Skip to content

Security & Compliance

Your data is safe with Nook

Read-only API access. Three cookies total. Encrypted at rest. Here is exactly what we access, store, and why.

Read-only access

We can see your data. We can't touch it.

Nook requests two read-only Google API scopes: analytics.readonly (GA4) and webmasters.readonly (Search Console). We can read your analytics data but cannot modify your Google account, create properties, change settings, or access any other Google services.

GA4

analytics.readonly

Search Console

webmasters.readonly

Google API Permissions
Read GA4 sessions & pageviews
Read Search Console queries
Read traffic sources & devices
Modify GA4 configuration
Create or delete properties
Access other Google services

How we handle your data

What we store

We store aggregated analytics metrics: sessions, pageviews, bounce rates, traffic sources, search queries, impressions, and clicks. We do not store personal visitor data. We do not store PII. We do not store raw GA4 event streams.

Cookies

Nook uses exactly three cookies: a session authentication cookie, an organization preference cookie, and a consent tracking cookie. That's it. No tracking cookies, no third-party cookies, no advertising cookies.

Encryption

All data in transit is encrypted via HTTPS (TLS 1.2+). All data at rest is encrypted in our PostgreSQL database. OAuth tokens are stored securely and never exposed in logs or client-side code.

Compliance
PIPEDACanadian privacy law
GDPREU data protection
Google API User Data PolicyLimited Use requirements
Minimum scopesOnly what we need, nothing more
No third-party sharingYour data stays between you and Google

Compliance & deletion

Your data, your rules

Nook Analytics complies with PIPEDA (Canada), GDPR (EU), and the Google API Services User Data Policy including Limited Use requirements. We only request the minimum scopes needed and never share your data with third parties.

You can delete your account at any time from your settings page. Self-service account deletion permanently removes all stored analytics data, organization settings, and account information. You can also disconnect individual properties without deleting your account.

Frequently asked questions

No. We request analytics.readonly and webmasters.readonly scopes only. These are read-only permissions. Nook cannot create, edit, or delete anything in your Google account.

No. Nook does not install any tracking code on your website. We read aggregated metrics from the GA4 and Search Console APIs. We never see or store individual visitor data, IP addresses, or personally identifiable information.

You can delete your account at any time from your settings. When you do, we permanently delete all stored analytics data, organization settings, and account information. Nothing is retained. If you cancel your subscription without deleting your account, your data remains accessible in a read-only state for 30 days.

Yes. We only store aggregated analytics metrics (sessions, pageviews, search queries). We do not process personal data of your website visitors. We comply with GDPR (EU), PIPEDA (Canada), and the Google API Services User Data Policy.

Nook's use of Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the minimum scopes needed and never share your data with third parties.