Privacy Policy

Last updated: September 7, 2026

Alleviate Lab ("we", "us", "our") operates Duct (getduct.ai), a cross-tool intelligence platform that connects your advertising, analytics, product and search tools, synthesises what changed across them, and — only when you approve a specific change — applies that change back to the connected tool. This Privacy Policy explains what we collect, why, who we share it with, how long we keep it, and how to delete it.

1. Google User Data We Access

Duct accesses Google user data only through official Google APIs, and only for the Google accounts and properties you explicitly connect. Nothing is accessed until you complete Google's consent screen, and every scope below is requested for the purpose stated beside it.

Sign-in

ScopeWhat it accessesWhy Duct needs it
openidA stable Google account identifierTo recognise your account across sessions
userinfo.emailYour email addressTo identify your account, send report notifications, and match project invitations
userinfo.profileYour name and profile pictureTo display who is signed in and who took an action in a shared project

Connected data sources

Each connector below is optional and connected separately. You may connect none, some, or all of them, and disconnect any of them at any time.

ScopeWhat it accessesWhy Duct needs it
adwordsGoogle Ads campaigns, ad groups, search terms, and performance metrics (clicks, impressions, cost, conversions, ROAS), plus device and geographic segmentationTo report on paid performance and, where you approve it, to add negative keywords or pause a campaign
analytics.readonlyGoogle Analytics 4 reporting data and property configurationTo report on traffic, conversion and retention alongside your other tools
analytics.editGoogle Analytics 4 admin settingsTo apply approved configuration changes, such as marking an event as a key event
webmasters.readonlyGoogle Search Console queries, pages, impressions, clicks and positionsTo report on organic search performance and surface ranking changes
tagmanager.readonlyGoogle Tag Manager accounts, containers, tags and triggersTo audit your measurement setup and detect broken or missing tracking
tagmanager.edit.containersGoogle Tag Manager container contentsTo prepare approved tracking fixes as a container change
tagmanager.publishGoogle Tag Manager container versionsTo publish a container version after you approve it

2. Changes Duct Makes on Your Behalf

Some of the scopes above allow writes. We want to be precise about this, because it is the part of Duct that touches your live accounts:

  • Nothing is written automatically. Duct proposes a change set, shows you the exact before-and-after for every individual change, and applies nothing until you explicitly approve it in the app.
  • Approval is per change set, not blanket. Approving one change does not authorise future ones.
  • Changes are recorded and reversible where the underlying API allows it. Every applied change is written to an audit log against your project.
  • Reporting works without write access. If you prefer read-only, connect the read-only scopes and decline the rest; Duct's reports still function.

3. How We Use Google User Data

  • Authentication: To verify your identity and maintain your session
  • Reports and insights: To fetch data from your connected properties and generate the briefs, alerts and audits you request
  • Approved changes: To apply the specific changes you approve, to the connected account you selected
  • Support: To diagnose a problem you report to us, using the minimum data needed

We use Google user data only to provide and improve these user-facing features. We do not use it for any other purpose.

4. Limited Use of Google User Data

Duct's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not:

  • Use or transfer Google user data for serving advertising of any kind, including targeted, personalised, retargeted or interest-based advertising
  • Sell, rent, or transfer Google user data to data brokers, information resellers, or any third party for their own purposes
  • Use Google user data to determine credit-worthiness or for lending purposes
  • Use Google user data to build or enrich independent databases or profiles
  • Use Google user data to develop, improve, or train generalised or non-personalised AI or machine learning models
  • Allow humans to read Google user data, except where you have given explicit consent for a specific issue, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised

5. Other Data Sources You Connect

Google is one of several sources Duct can connect. Each is optional, connected individually by you, and accessed through the provider's official API using credentials you authorise. Duct reads the metrics needed to build your reports, and writes only changes you have explicitly approved.

  • Advertising: Meta Ads, Apple Search Ads, OpenAI Ads
  • Product and behavioural analytics: Mixpanel, Microsoft Clarity
  • Experimentation: GrowthBook
  • Revenue and billing: Stripe, RevenueCat
  • CRM: HubSpot
  • Social publishing and analytics: PostBridge, which in turn connects the social accounts you authorise (TikTok, Instagram, YouTube, LinkedIn, X, Pinterest, Facebook, Google Business Profile)

The commitments in this policy — no sale of your data, no advertising use, no model training, deletion on request — apply to data from these sources exactly as they apply to Google user data.

6. Content Studio: Uploads and Publishing

If you use Duct's content features:

  • Files you upload (images, video, brand assets) are stored so they can be attached to drafts and published posts.
  • Generated media. Images and video created in Duct are produced by third-party generative AI services, which receive the prompt and any reference image you supply.
  • Publishing. When you schedule or publish a post, its content and media are transmitted to PostBridge and on to the social platform you selected, under that platform's own terms and privacy policy.
  • Public research data. Duct can retrieve publicly available content and metrics from social platforms to inform recommendations. This is public data, not data about you or your audience individually.

Do not upload material you lack the rights to use, or files containing other people's personal data beyond what your post requires.

7. The Duct Desktop App

The desktop app is a native window around the same Duct you would use in a browser. It is worth being precise about what that means, because "desktop app" sounds like "everything stays here" and that is not what we ship:

  • The app we distribute talks to our servers. It does not carry its own copy of Duct's backend. Your projects, briefs, agent memories, activity log, uploads and connector authorisations are stored by us, exactly as they are when you use Duct in a browser — which is also what lets you sign in on a second computer and find your work there. Sections 12 to 14 cover how we store, share and delete it.
  • Your AI provider keys stay on your machine. They live in your operating system's keychain, and are sent with a request only when a job needs to run. We never store them, and the option to save a key with us that the browser version offers is deliberately switched off in the desktop app.
  • Sign-in and connector authorisation open your system browser rather than an embedded window, so you keep your browser's own protections, and no credential is ever carried in the link that returns you to the app.
  • The desktop app sets no cookies, and is never going to ask you about them. It reports usage through the same Google Tag Manager container as the rest of Duct, but with storage switched off permanently: Google Analytics receives the event and writes nothing to your machine, so none of the cookies in section 11 exist there and there is nothing to consent to. A consent bar in front of an application you just opened is not a question worth interrupting anyone for.
  • Crash reports and usage data are on by default in the app we distribute, and one switch in Preferences turns both off. Once you touch it your answer is kept and no default applies again. A crash report contains the error and the stack trace that caused it; usage data is which screens and features you open — never your provider API keys, your data, or anything you generate. If you build Duct yourself both are off by default instead, because then we are not the ones running it.
  • Update checks contact our release host to ask whether a newer version exists. This request reveals your IP address and the version you are running.
  • You can run the whole thing yourself instead. The source is public, and it can be built with the backend inside the app or hosted on your own server. Then we hold nothing and this policy has nothing to describe — see section 16.

8. Bring-Your-Own AI Provider Keys

You may supply your own API keys for AI providers instead of using Duct's:

  • In the desktop app, keys are stored in your operating system's keychain. They are sent with a request so that the job you asked for can run, and we never store them; the option to save a key with us is switched off there.
  • In the web app, a key you paste is held for that browser session and sent with each request. If you choose to save it so you do not have to paste it again, it is encrypted at rest, decrypted only to make a request on your behalf, never returned by our API, and never written to logs. You can delete it at any time.
  • When you use your own key, your usage is billed by that provider under your account and is subject to that provider's terms and privacy policy.
  • The provider's data settings are yours to configure. Whether a provider retains or trains on what it receives is governed by the policy on your account with that provider, not by us — see the note on routing in section 12.

9. Website Audits and Lead Reports

Our public SEO audit tool collects the email address and website URL you submit, retrieves pages from that website to analyse them, and emails you the resulting report. We store the submission and report so we can resend it and so we can contact you about Duct. Only submit a website you own or are authorised to audit. Ask us at [email protected] to delete a submission.

10. Team Projects

Duct projects can be shared. If you invite someone, we send an invitation to the email address you provide. Members of a project can see that project's connected sources, reports, insights and activity history, along with the name, email and profile picture of other members. Anyone with the right role can also see and approve changes proposed against connected accounts. Invite only people you intend to give that access.

11. Other Information We Collect

Usage data

We collect basic product analytics — pages visited, features used, general interaction patterns — to understand how Duct is used. This runs through Google Tag Manager, which loads Google Analytics 4. We do not record keystrokes or form contents.

Cookies and similar technologies

Analytics cookies are set only after you accept them. If you are in the EEA, the UK or Switzerland we ask before anything is set, and nothing but the strictly necessary entries below exists until you choose. Elsewhere analytics is on by default and you can turn it off at any time — the Cookie settings link in our footer, and in the account menu inside the app, reopens the choice on every page.

Declining means Google Tag Manager is never loaded at all, rather than loaded in a restricted mode. If you decline after previously accepting, we delete the cookies below and reload the page.

CookieSet byPurposeExpires
_gaGoogle Analytics 4Distinguishes one visitor from another so a returning visit is not counted twice2 years
_ga_SXH5LYVTJ8Google Analytics 4Holds the state of the current session for our specific property2 years
_gcl_auGoogle Tag Manager (Conversion Linker)Attributes a signup to the ad or link that led to it90 days
duct_consentDuctRemembers your choice, so you are not asked on every page. Set on getduct.ai and all its subdomains, so answering once in your browser also answers for the app. The desktop app never sets it, because it loads no analytics at all. Strictly necessary — it exists whether you accept or decline6 months, then we ask again
duct_consent_regionDuct (session storage)Caches the country your request arrived from, so we ask the right question without repeating the lookup. Strictly necessaryEnd of session

The authentication token described under Locally stored data below is also strictly necessary: without it you cannot stay signed in.

Diagnostics

When something breaks, we collect error reports containing the technical context of the failure (stack trace, browser, the operation attempted). We configure our error monitoring to avoid capturing Google user data, but a report may incidentally contain an identifier such as a property ID.

Activity and agent memory

Duct records an activity log of significant actions in a project, and stores durable notes its agents derive from your data (for example, a recurring seasonal pattern) so reports improve over time. Both are scoped to your project, visible to you, and deleted with it.

Locally stored data

We store an authentication token in your browser's local storage to keep you signed in. It contains your name, email and profile picture, and expires after 7 days.

12. How We Share and Store Data

We do not sell your data. We share it only with the service providers below, only as needed to operate Duct, and only under terms that restrict them to that purpose:

ProviderPurposeReceives connected-source data?
RailwayApplication hosting and the primary databaseYes — at rest, as stored data
CloudflareCDN, web application delivery, bot protection (Turnstile), email deliveryIn transit
Anthropic, OpenAI, Google, OpenRouterAI models that generate report narratives, recommendations and content draftsYes — the data needed for the output you requested
Generative media providersImage and video generation in Content StudioPrompts and reference media only
PostBridgePublishing to, and reading analytics from, your social accountsSocial account data and post content only
ApifyRetrieving publicly available social content for researchNo
SentryError monitoring and crash reportingIncidentally, in error context only
ResendTransactional email (report delivery, project invitations)No — email address and report content only

Where connected-source data is sent to an AI model provider, it is sent solely to produce the output you asked for. We never use it to train models, and we never permit a provider to do so on our behalf. Anthropic, OpenAI and Google are used under API terms that exclude submitted data from training by default.

OpenRouter is a router, not a model provider, and it warrants a specific note. It forwards a request to whichever underlying provider the routing configuration selects, and those providers differ in whether they log or train on what they receive. Where you supply your own OpenRouter key, that routing configuration is yours: the retention and training behaviour of a request is governed by the data policy set on your OpenRouter account, and you should set it to match the commitments you need. We recommend enabling OpenRouter's zero-logging and no-training data policy before connecting a key. Duct does not use your data for training regardless of which route is taken.

We may also disclose data where required by law, and to a successor entity in the event of a merger or acquisition, in which case this policy continues to apply until you are notified otherwise.

13. Data Security

  • OAuth tokens and saved provider keys are encrypted at rest using Fernet symmetric encryption, stored server-side per user, and never exposed to the browser
  • All data in transit is encrypted via HTTPS/TLS
  • Access to a project's data requires both authentication and verified membership of that project; a non-member cannot read another project's data
  • We follow the principle of least privilege for internal data access

14. Data Retention and Deletion

DataRetention
OAuth refresh tokens and saved provider keysUntil you disconnect the source, delete the key, delete your account, or revoke access at the provider — whichever is first
Data fetched from connected sourcesRetained as part of the reports, insights, agent memory and working artifacts it produced, for as long as your account is active
Generated reports, content drafts, uploads and audit logsWhile your account is active
Authentication tokens (browser)7 days
Error diagnostics90 days
Audit tool submissionsUntil you ask us to delete them
BackupsDeleted data may persist in encrypted backups for up to 30 days after deletion

Deleting your data

  • Disconnect one source: remove it on the Connections page in Duct. Its stored credentials are deleted at that point.
  • Revoke Duct's access at Google: visit myaccount.google.com/permissions and remove Duct. This works whether or not you still have a Duct account.
  • Desktop app: deleting the app's data directory removes the local database and its contents; provider keys are removed from your keychain when you delete them in the app.
  • Delete your account and all associated data: email [email protected]. We action deletion requests within 30 days and confirm by email when complete.

15. Your Rights

We are based in Spain and process personal data under the EU GDPR. You have the right to access, correct, export, restrict the processing of, or delete your personal data, and to object to processing. Our legal basis is the performance of our contract with you for operating the product, and legitimate interest for security and diagnostics. Exercise any of these rights at [email protected]; you also have the right to lodge a complaint with your local supervisory authority (in Spain, the AEPD).

Data may be processed outside the EEA by the providers listed in section 12, under transfer mechanisms including the EU Standard Contractual Clauses.

16. Open Source and Self-Hosting

Duct's source code is published under the MIT licence. This policy covers the hosted service we operate at getduct.ai and app.getduct.ai, and the official desktop app we distribute.

It does not cover an instance of the software that someone else runs. If you use a Duct deployment operated by a third party, or one you run yourself, the operator of that deployment is the data controller and this policy does not apply to it. Publishing the code does not give us access to any data held in a deployment we do not operate.

17. Beta Status and Changes

Duct is currently in beta, and features and data handling practices may evolve. We will update this policy as needed, revise the date at the top, and notify users of material changes by email at the address on their account before the change takes effect.

18. Children's Privacy

Duct is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.

19. Contact

For privacy questions, data access or deletion requests:

  • Email: [email protected]
  • Data controller: Alleviate Lab
  • Location: Spain
  • Website: getduct.ai
DuctAboutPrivacy PolicyTerms of Service