Oracolo.ai Security

How we handle your data

Honest page. We explain what we do, what we don't do, and which architectural decisions we've made. No ISO 27001 to brandish: just the concrete choices that protect your data at this stage of the product.

Last updated 2026-05-17

1. How we access your Google data

Oracolo connects to Google only after you grant permission via OAuth 2.0. Every scope we request is read-only: we cannot modify your properties, your reports, or any data in your Google account.

2. What we store on our database

We only store what's needed to make the service work. Everything sits on a MySQL database hosted in the EU (Italy), protected by the hosting server credentials.

User profile
email, name, profile picture, language, country. All data you gave us or that came from your Google profile at sign-in.
OAuth tokens
Google access_token and refresh_token. Stored only in database (never in cookies or PHP session). Used to call APIs on your behalf without asking you to log in again. Encrypted at rest (AES-256-GCM, split-key across two locations).
GA4 data cache
results of queries to GA4, serialised as JSON in DB. Short TTL: 60 minutes for the dashboard, 2-4 hours for trends, 24 hours for forecasts. After expiry, regenerated. Encrypted at rest; expired rows are physically deleted daily.
AI reports
weekly/monthly analyses generated by Claude (Anthropic) on your aggregated GA4 data. Kept for historical reference. Encrypted at rest.
Forecaster plans
the manual targets you set in the Forecaster, the alternative plan versions you create, the cross-property aggregate.

What we don't store: personal data of visitors to your sites (Oracolo only reads GA4 aggregates, not individual user_ids). We don't install our own profiling cookies on your sites.

3. What you can delete anytime

The Account page gives you three concrete controls:

4. Limited Use of Google user data

Oracolo.ai's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In compliance with the Google API Services User Data Policy, we declare that our use of data obtained from users' Google accounts (Google Analytics, Search Console, AdSense) meets the Limited Use requirements:

5. Get in touch

If you want to report anything, write to info@oracolo.ai. A real person answers.