Effective date: August 1, 2026
Who we are
Stats Ninja is operated by Lince Media ("we", "us"). Contact: hello@stats.ninja. We are the data controller for the personal data described in this policy.
What we collect and why
- Google account basics — when you install the add-on we receive your Google account email address and user identifier, verified through Google's sign-in. We use them to create your workspace and to send you service emails (run failures, expiring connections, trial reminders). Legal basis: performance of contract.
- Meta OAuth tokens — when you connect a Meta account we store the
access token encrypted at rest (AES-256-GCM envelope encryption with
a separate data key for each token). We use it solely to fetch your ads data when your reports
run. We never post, modify or manage your ads — the token scope is read-only
(
ads_read). - Ad account metadata — account ids, names, currency and timezone, so the report builder can show you a picker. Not the ads data itself.
- Report configurations — the metrics, breakdowns, schedules and the id of the spreadsheet each report writes to.
- Usage logs — run timestamps, row counts, durations and error messages, used for quota enforcement, support and abuse prevention. Legal basis: legitimate interest.
- Billing data — handled by Stripe. We store your subscription tier and Stripe customer id; we never see or store card numbers.
- Waitlist — if you join the waitlist we store your email, language and the page you signed up from, to notify you about the launch. Legal basis: consent; unsubscribe with one email.
What we never store
Your ad performance data. When a report runs, our API retrieves the requested rows from Meta and returns them to the add-on so it can write your Google Sheet. The rows are processed transiently in memory; we do not persist impressions, spend, conversions or any other metric values.
Google API Services — Limited Use
Stats Ninja's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data to provide the features you see (writing your reports into your spreadsheets); we do not sell it, use it for advertising, or allow humans to read it except for support with your permission, security purposes, or as required by law.
Processors we rely on
- Neon — PostgreSQL database hosting (workspace metadata, encrypted tokens).
- Stripe — payments and subscription management.
- Brevo — transactional email delivery.
- Google — the Sheets add-on runs on Google Apps Script inside your Google account.
- Meta Platforms — source of your ads data, under your authorization.
- Cloudflare — website delivery and bot protection for the waitlist.
- Self-hosted infrastructure — our API runs on servers we operate in the EU.
Analytics
Our website uses self-hosted, cookie-less analytics (Umami). It does not track you across sites and stores no personal identifiers. The add-on itself contains no third-party trackers. Website fonts are served from our own domain; your browser does not contact Google Fonts.
Retention and deletion
We keep your data while your workspace is active. Disconnecting a Meta account attempts to revoke its Meta authorization and deletes the stored ciphertext. To delete your workspace and all associated data, email hello@stats.ninja from your account address — we complete deletion within 30 days. Usage logs are retained up to 12 months for abuse prevention, then deleted. Waitlist details are kept until launch communications finish or you withdraw consent, whichever comes first.
Your rights
Under the GDPR (and equivalent laws) you can request access, correction, deletion, portability, or restriction of your personal data, and object to processing based on legitimate interest. Write to hello@stats.ninja. You can also lodge a complaint with your local supervisory authority.
Changes
If we change this policy in a way that matters, we'll email active workspaces before it takes effect. The current version always lives at this URL.