The app runs entirely on your device. We operate no server that receives, stores or processes your data. We cannot see your metrics, your API keys, or your identity. Every Google scope the app requests is read-only, and every API call goes straight from your phone to Google.
The app only ever reads data from the Google accounts and properties you own and explicitly connect. Each source is optional: a scope is requested only when you add that source, through Google's own consent screen.
| Scope requested | Google user data accessed (read-only) |
|---|---|
analytics.readonly | Your Google Analytics 4 metrics for the properties you select: sessions, active users, page views, and traffic-source breakdowns. |
webmasters.readonly | Your Search Console metrics for the sites you select: clicks, impressions, CTR, average position, top queries and pages. |
adsense.readonly | Your own AdSense reporting: estimated earnings, page views, RPM. |
admob.readonly | Your own AdMob reporting: estimated ad earnings, impressions, eCPM, per app. |
devstorage.read_only | Read-only access to your own Google Cloud Storage bucket into which Google Play Console exports your reports (sales, earnings and installs CSV files). |
youtube.readonly | Your own channel list and basic channel statistics (subscribers, total views). |
yt-analytics.readonly | Your own channel's YouTube Analytics: views, watch time, subscriber changes. |
yt-analytics-monetary.readonly | Your own channel's estimated ad revenue. |
| Sign-in (email, profile) | The email address of the Google account you sign in with, so the app can display it in Settings and bind each connected source to the right account. |
The app requests no write, no delete and no send permission of any kind, and no Restricted scopes (no Gmail, Drive, Calendar, Contacts, Photos or Fitness data).
Google user data — raw or aggregated — is used for exactly one purpose: to render your own KPI dashboards inside the app, on your device (dashboard tiles, breakdowns, history charts, home-screen widgets and the optional local daily digest notification). Numbers from several sources may be aggregated into a per-project or portfolio total, which is again only displayed to you, on your device.
Google user data is never used for advertising or ad targeting, for lending or credit decisions, for building user profiles, for resale, for market research, for any purpose unrelated to the dashboard features above, and it is never used to develop, improve or train any AI/ML model. No AI/ML model is used in this app at all.
Google user data is transferred to nobody. It travels only between your device and Google's own API endpoints, over HTTPS. It is not sent to us (we run no server that could receive it), not sent to any third party, not sold, not shared with data brokers, advertisers, analytics vendors or AI/ML services. Neither we nor any subcontractor can read it — there is no copy of it anywhere outside your device. The app contains no analytics SDK, no crash reporter and no advertising SDK.
Cockpit Analytics' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google APIs will adhere to the Google User Data Policy, including the Limited Use requirements, and such data will not be used to develop, improve or train generalized AI and/or ML models.
The YouTube source uses the YouTube API Services. By connecting it you agree to the YouTube Terms of Service; Google's own handling of your data is described in the Google Privacy Policy. Cockpit Analytics reads your own channel's statistics, analytics and estimated revenue solely to display them to you in the app, and stores them only as described in sections 4 and 5. You can revoke the app's access to your YouTube data at security.google.com/settings/security/permissions.
API keys and tokens you provide for other services (Stripe restricted key, PayPal REST credentials, Umami/Plausible/Matomo/GitHub/Gumroad/Lemon Squeezy/RevenueCat/Buy Me a Coffee tokens) are stored in the Android Keystore and used exclusively to call that provider's API directly from your phone. They are never transmitted to us.
None. The app requires no account of ours and contains no tracking of any kind. Network requests go exclusively to the API providers you connect (Google, Stripe, PayPal, your self-hosted instances…), plus the European Central Bank reference-rates API (frankfurter.app) for currency conversion — that request contains no personal data.
The Pro unlock is a one-time purchase processed by Google Play. We receive no payment information; entitlement is verified through Google Play on your device.
If you join the waitlist on this website, we store your email address on our own server, solely to send launch information. No third-party marketing tools. It is never combined with any Google user data (which we never receive). Removal on request.
Since the app sends us no data, there is nothing for us to access, rectify or delete — uninstalling the app removes everything, and revoking access at myaccount.google.com/permissions cuts it off at the source. For the website waitlist or any question: contact@paint-vault.com.
Material changes to this policy will be posted on this page with a new effective date.