Privacy Policy
Last updated: September 7, 2026
Alleviate Lab ("we", "us", "our") operates Duct (getduct.ai), a cross-tool intelligence platform that connects your advertising, analytics, product and search tools, synthesises what changed across them, and — only when you approve a specific change — applies that change back to the connected tool. This Privacy Policy explains what we collect, why, who we share it with, how long we keep it, and how to delete it.
1. Google User Data We Access
Duct accesses Google user data only through official Google APIs, and only for the Google accounts and properties you explicitly connect. Nothing is accessed until you complete Google's consent screen, and every scope below is requested for the purpose stated beside it.
Sign-in
| Scope | What it accesses | Why Duct needs it |
|---|---|---|
openid | A stable Google account identifier | To recognise your account across sessions |
userinfo.email | Your email address | To identify your account, send report notifications, and match project invitations |
userinfo.profile | Your name and profile picture | To display who is signed in and who took an action in a shared project |
Connected data sources
Each connector below is optional and connected separately. You may connect none, some, or all of them, and disconnect any of them at any time.
| Scope | What it accesses | Why Duct needs it |
|---|---|---|
adwords | Google Ads campaigns, ad groups, search terms, and performance metrics (clicks, impressions, cost, conversions, ROAS), plus device and geographic segmentation | To report on paid performance and, where you approve it, to add negative keywords or pause a campaign |
analytics.readonly | Google Analytics 4 reporting data and property configuration | To report on traffic, conversion and retention alongside your other tools |
analytics.edit | Google Analytics 4 admin settings | To apply approved configuration changes, such as marking an event as a key event |
webmasters.readonly | Google Search Console queries, pages, impressions, clicks and positions | To report on organic search performance and surface ranking changes |
tagmanager.readonly | Google Tag Manager accounts, containers, tags and triggers | To audit your measurement setup and detect broken or missing tracking |
tagmanager.edit.containers | Google Tag Manager container contents | To prepare approved tracking fixes as a container change |
tagmanager.publish | Google Tag Manager container versions | To publish a container version after you approve it |
2. Changes Duct Makes on Your Behalf
Some of the scopes above allow writes. We want to be precise about this, because it is the part of Duct that touches your live accounts:
- Nothing is written automatically. Duct proposes a change set, shows you the exact before-and-after for every individual change, and applies nothing until you explicitly approve it in the app.
- Approval is per change set, not blanket. Approving one change does not authorise future ones.
- Changes are recorded and reversible where the underlying API allows it. Every applied change is written to an audit log against your project.
- Reporting works without write access. If you prefer read-only, connect the read-only scopes and decline the rest; Duct's reports still function.
3. How We Use Google User Data
- Authentication: To verify your identity and maintain your session
- Reports and insights: To fetch data from your connected properties and generate the briefs, alerts and audits you request
- Approved changes: To apply the specific changes you approve, to the connected account you selected
- Support: To diagnose a problem you report to us, using the minimum data needed
We use Google user data only to provide and improve these user-facing features. We do not use it for any other purpose.
4. Limited Use of Google User Data
Duct's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we do not:
- Use or transfer Google user data for serving advertising of any kind, including targeted, personalised, retargeted or interest-based advertising
- Sell, rent, or transfer Google user data to data brokers, information resellers, or any third party for their own purposes
- Use Google user data to determine credit-worthiness or for lending purposes
- Use Google user data to build or enrich independent databases or profiles
- Use Google user data to develop, improve, or train generalised or non-personalised AI or machine learning models
- Allow humans to read Google user data, except where you have given explicit consent for a specific issue, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised
5. Other Data Sources You Connect
Google is one of several sources Duct can connect. Each is optional, connected individually by you, and accessed through the provider's official API using credentials you authorise. Duct reads the metrics needed to build your reports, and writes only changes you have explicitly approved.
- Advertising: Meta Ads, Apple Search Ads, OpenAI Ads
- Product and behavioural analytics: Mixpanel, Microsoft Clarity
- Experimentation: GrowthBook
- Revenue and billing: Stripe, RevenueCat
- CRM: HubSpot
- Social publishing and analytics: PostBridge, which in turn connects the social accounts you authorise (TikTok, Instagram, YouTube, LinkedIn, X, Pinterest, Facebook, Google Business Profile)
The commitments in this policy — no sale of your data, no advertising use, no model training, deletion on request — apply to data from these sources exactly as they apply to Google user data.
6. Content Studio: Uploads and Publishing
If you use Duct's content features:
- Files you upload (images, video, brand assets) are stored so they can be attached to drafts and published posts.
- Generated media. Images and video created in Duct are produced by third-party generative AI services, which receive the prompt and any reference image you supply.
- Publishing. When you schedule or publish a post, its content and media are transmitted to PostBridge and on to the social platform you selected, under that platform's own terms and privacy policy.
- Public research data. Duct can retrieve publicly available content and metrics from social platforms to inform recommendations. This is public data, not data about you or your audience individually.
Do not upload material you lack the rights to use, or files containing other people's personal data beyond what your post requires.
7. The Duct Desktop App
The desktop app is a native window around the same Duct you would use in a browser. It is worth being precise about what that means, because "desktop app" sounds like "everything stays here" and that is not what we ship:
- The app we distribute talks to our servers. It does not carry its own copy of Duct's backend. Your projects, briefs, agent memories, activity log, uploads and connector authorisations are stored by us, exactly as they are when you use Duct in a browser — which is also what lets you sign in on a second computer and find your work there. Sections 12 to 14 cover how we store, share and delete it.
- Your AI provider keys stay on your machine. They live in your operating system's keychain, and are sent with a request only when a job needs to run. We never store them, and the option to save a key with us that the browser version offers is deliberately switched off in the desktop app.
- Sign-in and connector authorisation open your system browser rather than an embedded window, so you keep your browser's own protections, and no credential is ever carried in the link that returns you to the app.
- The desktop app sets no cookies, and is never going to ask you about them. It reports usage through the same Google Tag Manager container as the rest of Duct, but with storage switched off permanently: Google Analytics receives the event and writes nothing to your machine, so none of the cookies in section 11 exist there and there is nothing to consent to. A consent bar in front of an application you just opened is not a question worth interrupting anyone for.
- Crash reports and usage data are on by default in the app we distribute, and one switch in Preferences turns both off. Once you touch it your answer is kept and no default applies again. A crash report contains the error and the stack trace that caused it; usage data is which screens and features you open — never your provider API keys, your data, or anything you generate. If you build Duct yourself both are off by default instead, because then we are not the ones running it.
- Update checks contact our release host to ask whether a newer version exists. This request reveals your IP address and the version you are running.
- You can run the whole thing yourself instead. The source is public, and it can be built with the backend inside the app or hosted on your own server. Then we hold nothing and this policy has nothing to describe — see section 16.
8. Bring-Your-Own AI Provider Keys
You may supply your own API keys for AI providers instead of using Duct's:
- In the desktop app, keys are stored in your operating system's keychain. They are sent with a request so that the job you asked for can run, and we never store them; the option to save a key with us is switched off there.
- In the web app, a key you paste is held for that browser session and sent with each request. If you choose to save it so you do not have to paste it again, it is encrypted at rest, decrypted only to make a request on your behalf, never returned by our API, and never written to logs. You can delete it at any time.
- When you use your own key, your usage is billed by that provider under your account and is subject to that provider's terms and privacy policy.
- The provider's data settings are yours to configure. Whether a provider retains or trains on what it receives is governed by the policy on your account with that provider, not by us — see the note on routing in section 12.
9. Website Audits and Lead Reports
Our public SEO audit tool collects the email address and website URL you submit, retrieves pages from that website to analyse them, and emails you the resulting report. We store the submission and report so we can resend it and so we can contact you about Duct. Only submit a website you own or are authorised to audit. Ask us at hello@getduct.ai to delete a submission.
10. Team Projects
Duct projects can be shared. If you invite someone, we send an invitation to the email address you provide. Members of a project can see that project's connected sources, reports, insights and activity history, along with the name, email and profile picture of other members. Anyone with the right role can also see and approve changes proposed against connected accounts. Invite only people you intend to give that access.
11. Other Information We Collect
Usage data
We collect basic product analytics — pages visited, features used, general interaction patterns — to understand how Duct is used. This runs through Google Tag Manager, which loads Google Analytics 4. We do not record keystrokes or form contents.
Cookies and similar technologies
Analytics cookies are set only after you accept them. If you are in the EEA, the UK or Switzerland we ask before anything is set, and nothing but the strictly necessary entries below exists until you choose. Elsewhere analytics is on by default and you can turn it off at any time — the Cookie settings link in our footer, and in the account menu inside the app, reopens the choice on every page.
Declining means Google Tag Manager is never loaded at all, rather than loaded in a restricted mode. If you decline after previously accepting, we delete the cookies below and reload the page.
| Cookie | Set by | Purpose | Expires |
|---|---|---|---|
_ga | Google Analytics 4 | Distinguishes one visitor from another so a returning visit is not counted twice | 2 years |
_ga_SXH5LYVTJ8 | Google Analytics 4 | Holds the state of the current session for our specific property | 2 years |
_gcl_au | Google Tag Manager (Conversion Linker) | Attributes a signup to the ad or link that led to it | 90 days |
duct_consent | Duct | Remembers your choice, so you are not asked on every page. Set on getduct.ai and all its subdomains, so answering once in your browser also answers for the app. The desktop app never sets it, because it loads no analytics at all. Strictly necessary — it exists whether you accept or decline | 6 months, then we ask again |
duct_consent_region | Duct (session storage) | Caches the country your request arrived from, so we ask the right question without repeating the lookup. Strictly necessary | End of session |
The authentication token described under Locally stored data below is also strictly necessary: without it you cannot stay signed in.
Diagnostics
When something breaks, we collect error reports containing the technical context of the failure (stack trace, browser, the operation attempted). We configure our error monitoring to avoid capturing Google user data, but a report may incidentally contain an identifier such as a property ID.
Activity and agent memory
Duct records an activity log of significant actions in a project, and stores durable notes its agents derive from your data (for example, a recurring seasonal pattern) so reports improve over time. Both are scoped to your project, visible to you, and deleted with it.
Locally stored data
We store an authentication token in your browser's local storage to keep you signed in. It contains your name, email and profile picture, and expires after 7 days.
12. How We Share and Store Data
We do not sell your data. We share it only with the service providers below, only as needed to operate Duct, and only under terms that restrict them to that purpose:
| Provider | Purpose | Receives connected-source data? |
|---|---|---|
| Railway | Application hosting and the primary database | Yes — at rest, as stored data |
| Cloudflare | CDN, web application delivery, bot protection (Turnstile), email delivery | In transit |
| Anthropic, OpenAI, Google, OpenRouter | AI models that generate report narratives, recommendations and content drafts | Yes — the data needed for the output you requested |
| Generative media providers | Image and video generation in Content Studio | Prompts and reference media only |
| PostBridge | Publishing to, and reading analytics from, your social accounts | Social account data and post content only |
| Apify | Retrieving publicly available social content for research | No |
| Sentry | Error monitoring and crash reporting | Incidentally, in error context only |
| Resend | Transactional email (report delivery, project invitations) | No — email address and report content only |
Where connected-source data is sent to an AI model provider, it is sent solely to produce the output you asked for. We never use it to train models, and we never permit a provider to do so on our behalf. Anthropic, OpenAI and Google are used under API terms that exclude submitted data from training by default.
OpenRouter is a router, not a model provider, and it warrants a specific note. It forwards a request to whichever underlying provider the routing configuration selects, and those providers differ in whether they log or train on what they receive. Where you supply your own OpenRouter key, that routing configuration is yours: the retention and training behaviour of a request is governed by the data policy set on your OpenRouter account, and you should set it to match the commitments you need. We recommend enabling OpenRouter's zero-logging and no-training data policy before connecting a key. Duct does not use your data for training regardless of which route is taken.
We may also disclose data where required by law, and to a successor entity in the event of a merger or acquisition, in which case this policy continues to apply until you are notified otherwise.
13. Data Security
- OAuth tokens and saved provider keys are encrypted at rest using Fernet symmetric encryption, stored server-side per user, and never exposed to the browser
- All data in transit is encrypted via HTTPS/TLS
- Access to a project's data requires both authentication and verified membership of that project; a non-member cannot read another project's data
- We follow the principle of least privilege for internal data access
14. Data Retention and Deletion
| Data | Retention |
|---|---|
| OAuth refresh tokens and saved provider keys | Until you disconnect the source, delete the key, delete your account, or revoke access at the provider — whichever is first |
| Data fetched from connected sources | Retained as part of the reports, insights, agent memory and working artifacts it produced, for as long as your account is active |
| Generated reports, content drafts, uploads and audit logs | While your account is active |
| Authentication tokens (browser) | 7 days |
| Error diagnostics | 90 days |
| Audit tool submissions | Until you ask us to delete them |
| Backups | Deleted data may persist in encrypted backups for up to 30 days after deletion |
Deleting your data
- Disconnect one source: remove it on the Connections page in Duct. Its stored credentials are deleted at that point.
- Revoke Duct's access at Google: visit myaccount.google.com/permissions and remove Duct. This works whether or not you still have a Duct account.
- Desktop app: deleting the app's data directory removes the local database and its contents; provider keys are removed from your keychain when you delete them in the app.
- Delete your account and all associated data: email hello@getduct.ai. We action deletion requests within 30 days and confirm by email when complete.
15. Your Rights
We are based in Spain and process personal data under the EU GDPR. You have the right to access, correct, export, restrict the processing of, or delete your personal data, and to object to processing. Our legal basis is the performance of our contract with you for operating the product, and legitimate interest for security and diagnostics. Exercise any of these rights at hello@getduct.ai; you also have the right to lodge a complaint with your local supervisory authority (in Spain, the AEPD).
Data may be processed outside the EEA by the providers listed in section 12, under transfer mechanisms including the EU Standard Contractual Clauses.
16. Open Source and Self-Hosting
Duct's source code is published under the MIT licence. This policy covers the hosted service we operate at getduct.ai and app.getduct.ai, and the official desktop app we distribute.
It does not cover an instance of the software that someone else runs. If you use a Duct deployment operated by a third party, or one you run yourself, the operator of that deployment is the data controller and this policy does not apply to it. Publishing the code does not give us access to any data held in a deployment we do not operate.
17. Beta Status and Changes
Duct is currently in beta, and features and data handling practices may evolve. We will update this policy as needed, revise the date at the top, and notify users of material changes by email at the address on their account before the change takes effect.
18. Children's Privacy
Duct is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.
19. Contact
For privacy questions, data access or deletion requests:
- Email: hello@getduct.ai
- Data controller: Alleviate Lab
- Location: Spain
- Website: getduct.ai