SushiLab AI Marketing — Privacy Policy

Updated: 4 October 2026

Operator and contact
Sushi Lab AS operates this internal analytics pilot. Questions about access, use or deletion of application data can be sent to sushilabnarvik@gmail.com.

Google Analytics access
The owner authorizes Google Analytics access through Google's OAuth consent process. The application uses the analytics.readonly permission to retrieve aggregate reports from the designated GA4 property. This permission can allow access to other Analytics resources available to the authorizing account; the pilot workflow is configured to request only the designated SushiLab property.

Data accessed and stored
The current report contains the date, sessions, total users and event counts for each day. The application also records the GA4 property identifier, reporting dates, reporting timezone, retrieval time and available data-quality indicators. Daily user counts are not added together as a count of unique users across a longer period.

The current GA4 report does not request visitor-level identifiers, names, email addresses, phone numbers, IP addresses or individual customer records. It does not request purchase or revenue metrics.

OAuth credentials needed to retrieve reports are held in the automation platform's credential storage and are not included in the aggregate report database. A read-only permission does not make credentials public.

Purpose
Data is used to provide the owner with internal website activity reports, verify that the integration works and support review of marketing performance. The current pilot does not automatically take advertising or customer actions.

Processing services and access
Google provides the source reports. n8n Cloud executes the report retrieval and storage workflow. Supabase stores the aggregate observations. Authorized technical work and review may use ChatGPT/OpenAI, where selected aggregate reports and diagnostics can be shared at the owner's direction. These services process information according to their applicable service terms, settings and agreements.

Access to stored observations is restricted to the application's backend and authorized administrators. Reports are not published for public access. The pilot does not sell Google API data, use it for data brokerage, transfer it to advertising platforms for audience targeting, or use it to build its own general-purpose machine-learning model.

Google API data use
SushiLab AI Marketing's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Policy: https://developers.google.com/terms/api-services-user-data-policy

Retention and deletion
Aggregate reports are retained while needed for the pilot's reporting and investigation of its operation. No automatic deletion period has been configured yet. The owner may request deletion of retained application reports and disconnection of the integration by emailing sushilabnarvik@gmail.com. Deletion of data from the original Google Analytics property is a separate action managed in Google Analytics. Any retained copies in service-provider backups remain subject to the relevant provider's backup and deletion processes.

Revoking access
The owner can revoke access through Google Account's third-party connections settings:
https://myaccount.google.com/connections
Revocation stops future authorized retrieval once access is invalidated; it does not itself remove reports already stored by the application. Contact the operator separately to request their deletion.

Changes
The operator will update these disclosures before introducing materially different access or uses of Google data. Additional authorization will be requested where required. Connecting other clients or adding new data categories is outside the scope of the current pilot.