Privacy Policy
Last updated: September 17, 2026
1. Introduction & Scope
At Clarika ("we", "our", or "the Platform"), we are committed to safeguarding the privacy and security of data belonging to our users, marketing agencies, and their clients. This Privacy Policy describes how we collect, use, store, process, and protect information across our marketing reporting and analytics intelligence platform at app.clarika.app.
2. Data Controller
The data controller responsible for the processing of personal data and OAuth credentials collected through the platform is Clarika. For any questions regarding this policy or the exercise of data privacy rights, you can reach us at privacy@clarika.app.
3. Information We Collect
Clarika only collects information strictly necessary to provide marketing performance reporting and analytics automation services:
User Account Information: Full name, business email address, locale/language preferences, and billing information processed securely via our certified Merchant of Record payment processor.
Google Ads API Data: Through the OAuth 2.0 protocol and the advertising read scope ('adwords'), we retrieve performance metrics from linked Google Ads accounts (impressions, clicks, cost, conversions, conversion value, and campaign metadata). We do not request or access personal data belonging to your end clients, nor direct Google account passwords.
Meta Marketing API & Graph API Data: Through Meta's authorized OAuth flow with specific permissions ('ads_read', 'pages_read_engagement', 'instagram_basic'), we retrieve aggregated ad campaign metrics (spend, impressions, clicks, ROAS, CPA), Facebook Page reach and engagement, and organic growth metrics from linked Instagram business profiles.
Technical and Log Data: Anonymized IP addresses, browser user agent, session audit logs, and technical cookies essential for authenticated session management.
4. Purpose of Data Processing
Collected information is processed solely for the purposes of: (a) Consolidating, computing, and visualizing multi-channel advertising KPIs (ROAS, CPA, ad spend, conversions) within interactive agency dashboards; (b) Generating customized, white-labeled client-facing web reports and exportable PDF summaries; (c) Alerting agencies regarding credential expirations or critical campaign anomalies.
5. Compliance with Google API Services User Data Policy
Clarika's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. Clarika does not use data retrieved from Google APIs to train generalized artificial intelligence or machine learning models, nor does Clarika sell or transfer this data to third parties.
6. Meta Platform Terms & Data Protection Compliance
Clarika strictly adheres to the Meta Platform Terms and Developer Policies. Ad and social data retrieved from Meta APIs are processed strictly on behalf of the authorized agency and are never shared, sold, or re-marketed to external entities.
7. Data Deletion Instructions & Permission Revocation
Users and agencies may revoke Clarika's access to their Google or Meta accounts at any time through the 'Connections' tab within the Clarika dashboard, or directly from their third-party security management dashboards (Google: myaccount.google.com/permissions; Meta: Settings & Privacy > Apps and Websites). Furthermore, to request complete and permanent deletion of any associated account records, cached reports, or tokens, you may submit a formal request to privacy@clarika.app or support@clarika.app. Deletion requests are fulfilled within 48 business hours.
8. Cryptographic Security & Storage
Credential security is paramount. All OAuth access tokens and refresh tokens are encrypted at rest using industry-standard AES-256-GCM authenticated encryption with isolated master keys. All data in transit is protected via modern TLS 1.3 encryption. At the database layer, PostgreSQL Row Level Security (RLS) guarantees complete cryptographic isolation between agency tenants.
9. Data Retention & Cache Expiration (TTL)
Clarika does not perform permanent unnecessary hoarding of external advertising logs. Aggregated report data is cached temporarily with a strict 6-hour Time-to-Live (TTL) to deliver instantaneous dashboard responsiveness and protect third-party API rate quotas. Once the TTL elapses, cache entries are recalculated or evicted.
10. User Rights
In accordance with applicable privacy regulations (including GDPR and CCPA where applicable), you retain the right to access, rectify, export, restrict processing, and request the permanent erasure of your personal and operational data at any time.
11. Contact & Inquiries
For any questions, legal inquiries, or concerns regarding our Privacy Policy or data processing practices, please contact: