Effective date: 4 October 2026 (website analytics added the same day)
Marketing Kit (marketing-kit.app, the website, server, Claude Desktop extension and skill together — “the Service”) lets you read your own advertising and analytics data from Google Analytics 4, Google Ads, Google Search Console, Meta (Facebook / Instagram) ads, TikTok Ads, AppsFlyer, RevenueCat, App Store Connect and the Apple App Store inside Claude. This policy explains what we process, why, and how you control it.
Data controller:
VALAS OÜ – PODRUŽNICA V SLOVENIJI
Mlinska ulica 22, 2000 Maribor, Slovenia
VAT ID: SI57438285
Website: valas.team
Contact for privacy questions: [email protected]
| Data | Source | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Name, e-mail address, account identifier of the Google or Meta account you sign in with | Google or Meta, when you sign in | Creating and identifying your account on the Service | Contract (Art. 6(1)(b)) |
| OAuth access and refresh tokens for Google (GA4, Google Ads, Search Console) and Meta, the scopes you granted, the account name and token expiry | Google or Meta, when you press “Authorize” on the Connections page | Reading your data from these services when you ask Claude for it | Contract; your consent given on the provider’s consent screen |
| Tokens issued to your Claude Desktop extension | The Service | Letting your extension call the server on your behalf | Contract |
| Request log: time, source and mode requested, request parameters without secrets, number of rows returned, duration | The Service | Security, abuse prevention, troubleshooting | Legitimate interest (Art. 6(1)(f)) |
| Technical data: IP address, browser type, in web server logs | Your browser | Operating and protecting the website | Legitimate interest |
Keys you enter by hand. You can paste your AppsFlyer API token, OneLink API token, RevenueCat secret API key (V2, read-only is enough) and (optionally, under Advanced) a Google Ads login customer ID on the Connections page. Marketing Kit detects your Google Ads manager accounts by itself through the Google Ads API; the account IDs and names it finds are kept in server memory for up to an hour and are not stored. The Service stores them encrypted (AES-256-GCM) until you remove them or delete your account; they are never written to logs, returned to the browser in full (only the last characters are shown) or included in answers. Alternatively you can enter the same keys in the settings of the Claude Desktop extension on your own computer: the extension sends them with each request, the server uses them for that request only and does not store them; a key entered in the extension takes priority over a saved one. The Service only reads RevenueCat data (subscription metrics, charts, products, offerings, and — when you ask about one customer — that customer’s subscriptions; customer attributes such as email are not returned unless you explicitly ask for them).
App Store Connect API. If you connect App Store Connect, the Service reads from Apple, on your behalf, your apps, sales and subscription reports, analytics reports, customer reviews and app versions (including Product Page Optimization experiments). To do so you save a team API key — its Issuer ID, Key ID and private key (.p8) — and, for sales and subscription reports, your vendor number on the Connections page. They are stored encrypted (AES-256-GCM) and used only to sign short-lived requests to Apple on your behalf; they are never shown back, shared, written to logs or included in answers, and are deleted when you press “Remove” or delete your account (you should also revoke the key in App Store Connect when you stop using the Service). The only write the Service makes is creating an Analytics Reports request for an app, and only when you confirm it.
Download files. When a result is too large to show in the chat, the Service saves it as a file that is kept for up to 24 hours and can be downloaded only by the same signed-in user; afterwards it is deleted.
Remote connector (claude.ai). If you add the Marketing Kit connector in claude.ai, requests are sent from Anthropic’s servers to marketing-kit.app (/mcp) on your behalf, after you sign in and allow access; the Service answers them with the same data and limits as for the extension.
ChatGPT (OpenAI). If you add the Marketing Kit connector in ChatGPT (Developer mode or, once published, the ChatGPT plugin directory) or use the Marketing Kit GPT, requests are sent from OpenAI’s servers to marketing-kit.app (/mcp or /api/v1) on your behalf, after you sign in and allow access. The Service answers with the same data as for Claude; through the GPT it only reads (no changes to AppsFlyer), and large tables come back as a summary with download links. The access can be revoked on the Account page at any time.
Your advertising and analytics data (spend, impressions, events, app reviews and the like) is fetched from the provider only when you ask for it, is passed to your Claude client, and is not stored by the Service beyond a short-lived in-memory cache (about 15 minutes, separate for each user) that avoids repeating identical requests. Device identifiers, IP addresses and customer user IDs contained in source data are removed by default before the data leaves the server.
We use the data only to provide the Service to you. We do not sell it, do not use it for advertising, do not build profiles, and do not use it to train AI models.
Marketing Kit’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Scopes requested: openid, email, profile (sign-in), analytics.readonly (read Google Analytics 4) and adwords (read Google Ads reports; the Service does not change your campaigns) and webmasters.readonly (read Google Search Console: your properties, search performance — clicks, impressions, CTR and position by query, page, country, device and date — sitemaps and URL index status; the Service does not add, remove or change properties or sitemaps). Google user data is used only to show you your own data in Claude or ChatGPT, is not transferred to third parties except as necessary to provide the Service or required by law, is not used for advertising, and is not read by humans except with your explicit consent, for security purposes, or as required by law.
With Facebook Login for Business the Service requests public_profile, email and ads_read (read-only access to the ad accounts you choose). Meta data is used only to show you your own advertising data in Claude, in line with the Meta Platform Terms.
Transfers outside the EU (Cloudflare, Google, Meta, Anthropic, OpenAI) rely on the EU–US Data Privacy Framework or Standard Contractual Clauses offered by those providers.
Provider tokens are encrypted at rest with AES-256-GCM. Tokens are never written to logs or returned to the browser or to Claude. All traffic uses HTTPS. Access to the server is limited to the operator’s administrators.
Step-by-step instructions: marketing-kit.app/data-deletion.html.
Under the GDPR you have the right to access, rectify, erase, restrict and port your data and to object to processing. You may also lodge a complaint with the Slovenian supervisory authority, the Information Commissioner (ip-rs.si).
The website uses one strictly necessary session cookie to keep you signed in, and Google Analytics cookies (_ga, _ga_*) to measure how the website itself is used: which pages are opened, from which country and on which kind of device. Google Analytics sees only visits to marketing-kit.app pages — never your connected accounts, keys, marketing data or what you ask your assistant. No advertising cookies. You can block analytics cookies in your browser or with Google's opt-out add-on; the Service works the same without them.
The Service is intended for business users and is not directed to children under 16.
We will publish changes on this page and update the effective date. Material changes will be announced on the website before they take effect.
See also the Terms of Service.
© 2026 Valas Team