Dekstr

Privacy Policy

17 August 2026

Dekstr ("Dekstr", "we") builds a growth analytics service that reads the marketing, analytics and revenue accounts you connect, and turns them into plain-language findings. This policy explains exactly what we collect, why, where it is stored and how to get it deleted.

What we collect

Waitlist: your email address, the language you used and which page you signed up from. Nothing else — no tracking pixels, no advertising cookies.

Account: when you sign in with Google we receive your name, email address and Google account identifier, and store them to identify your workspace.

Connected sources: read-only metrics from the accounts you explicitly authorize (for example campaign names, spend, clicks, sessions, subscription revenue). We never post, edit or delete anything in those accounts.

Google user data

With your consent we request read-only access to Google Ads (adwords), Google Analytics (analytics.readonly) and Search Console (webmasters.readonly). We use this data for one purpose only: to compute your metrics and produce the findings and weekly brief you see in the product.

Dekstr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not allow humans to read it except when you ask us for support, when required by law, or for security investigations.

You can revoke our access at any time from your Google Account permissions page, or by asking us to disconnect the source. Revoking access stops all future reads immediately.

How it is stored

Access and refresh tokens are encrypted with AES-256-GCM before they touch the database; plaintext tokens are never written to storage or logs. Application data lives in a managed database hosted in the European Union (Ireland), and the application runs on Vercel.

Who else processes it

We do not sell your data and we do not share it with advertisers. We use a small set of processors to run the service: Vercel (hosting), Turso (database), Google (sign-in and the APIs you connect) and Anthropic (AI interpretation of your metrics to generate findings). Each receives only what that function needs.

Retention and deletion

Waitlist entries are kept until launch or until you ask us to remove them. Account and metric data are kept while your workspace is active. Write to privacy@dekstr.co and we will delete your data, including stored tokens, within 30 days.

Your rights

Under KVKK (Turkey) and the GDPR you can ask what we hold about you, request a copy, ask for corrections, or ask for deletion. Write to privacy@dekstr.co; we answer within 30 days.