Legal
Privacy Policy
Last updated: 29 April 2026
Overview
Measure Copilot ("we", "us", "our") operates the website measurecopilot.com and the Measure Copilot Evidence Collector Chrome extension (together, "the Service"). This policy explains what data we collect, how we use it, and your rights.
Web application — data we collect
Audit inputs: When you run an audit, we receive the website URL, business type, and any files you upload (GTM JSON, GA4 CSVs, extension evidence JSON). Files are processed in memory to generate your report and are not stored on our servers after the audit completes.
Audit results: Completed audit reports are stored for 7 days so you can share or revisit them via their unique URL, then automatically deleted.
Account data (signed-in users): If you create an account, we store your email address, plan status, and a monthly audit usage counter. This data is held in Supabase (EU region) and is used solely to enforce your plan limits and display your audit history.
Billing: Payments are processed by Stripe. We do not store card numbers or bank details. We receive a Stripe customer ID and subscription status.
Analytics: We use Google Tag Manager and GA4 to understand how the product is used (page views, audit starts, audit completions). No personally identifiable information is sent to GA4. Anonymous IP address truncation is enabled.
IP addresses: Anonymous users are rate-limited by IP address (3 audits per 24 hours). IP addresses are stored alongside audit records for up to 7 days and then deleted with the record.
Chrome extension — data we collect
The Measure Copilot Evidence Collector extension observes analytics signals on websites you choose to audit. Specifically, it reads:
window.dataLayerpush events (GA4 / GTM events fired on the page)- Consent Mode signal states (analytics_storage, ad_storage, etc.)
- GA4 measurement ID and GTM container ID detected on the page
- CMP (consent management platform) presence signals
Storage: All collected evidence is stored locally in Chrome extension storage (chrome.storage.local) on your device. It is never automatically transmitted to Measure Copilot or any third party.
Export: Evidence is exported only when you explicitly click "Export evidence" in the extension popup. The resulting JSON file is downloaded to your device. You then upload it to a Measure Copilot audit at your discretion.
What we do not collect: The extension does not collect passwords, payment details, form field values, cookies, browser history, bookmarks, or data from pages you do not actively visit with the extension installed and active.
Broad host permissions justification: The extension uses http://*/* and https://*/* host permissions because users need to audit any website — not a fixed set of domains. The content script runs passively on all pages and only begins collecting analytics evidence when the user opens the extension popup and the page is in scope for their audit.
Cookies
We use a single session cookie to maintain your signed-in state (Supabase Auth). We do not use advertising or cross-site tracking cookies. Third-party services we use (GA4, Stripe) may set their own cookies subject to their respective privacy policies.
Data sharing
We do not sell your personal data. We share data only with:
- Supabase — database and authentication hosting
- Stripe — payment processing
- Google (GA4 / GTM) — anonymised product analytics
- Law enforcement or regulators when required by applicable law
Data retention
Audit records (including IP address) are automatically deleted after 7 days. Account data is retained for as long as your account is active. You may request deletion at any time by emailing hi@measurecopilot.com.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise any of these rights, email hi@measurecopilot.com. We will respond within 30 days.
Children
The Service is not directed at children under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via the website or by email to registered users. Continued use after the effective date constitutes acceptance of the updated policy.
Contact
Questions about this policy: hi@measurecopilot.com