Privacy Policy
Effective 20 May 2026.
Who we are
Halfborg is a sole-proprietor business based in Singapore, run by Alex ([email protected]). "Halfborg Levers" is the marketing-intelligence service this policy applies to.
What data we access
Halfborg Levers reads your marketing data using its own Google account, not by holding an OAuth refresh token issued from your account. To onboard, you add the Halfborg operator account to a small set of your dashboards as a viewer; we then read on a recurring schedule (weekly or monthly, per client) using that access. You can revoke any of these grants at any time by removing us from the relevant dashboard.
- Google Search Console — you add the Halfborg operator account email to your Search Console property as a Restricted user. We read query, page, click, impression, CTR and position metrics so we can spot SEO opportunities to recommend.
- Google Analytics 4 — you add the same Halfborg operator account email to your GA4 property as a Viewer. We read session, user, pageview, conversion, revenue and engagement metrics by landing page, source and medium, so we can identify which channels and pages deserve focus.
- Google Merchant Center — shopping performance per SKU (cost, clicks, conversions, ROAS) is read through the linked Google Ads account, so no direct grant on Merchant Center is needed today.
- Google Ads — you accept a manager-account link request from the Halfborg manager (MCC) account. Once linked, we read campaign- and ad-level performance metrics (cost, impressions, clicks, conversions, conversion-value, ROAS) via the Google Ads API. We do not send any change to your account; access is read-only.
No client GCP project is required, and Halfborg does not query any BigQuery dataset belonging to you. Outside Google, you provide us with a Meta Marketing system-user assignment (for ads-account read access) and WordPress application-password credentials (for blog-post inventory) at onboarding.
How we use the data
On a recurring schedule (weekly or monthly, per client), the Halfborg Levers service reads recent data from each connected source, runs analytic code plus an LLM (Claude, via OpenRouter) to summarise what changed, and produces a single recommendation, delivered as a short Telegram message and a private web page. You reach that page by signing in with your Google account through Cloudflare Access; only email addresses we explicitly authorise can open it. We do not run real-time access to your data, and we do not surface your data in any third-party product.
Where the data is stored
Snapshots of the data we read are stored in Halfborg's database, hosted by Neon (which runs on AWS infrastructure). Operational logs are stored on a private server in Singapore, which also runs the web app that renders your recommendation page. Both stores are encrypted at rest and in transit.
Prompts sent to the LLM (Claude via OpenRouter) include aggregated metrics from the snapshots above. We do not transmit raw user-level data, and OpenRouter and Anthropic apply their own data-handling policies to the requests. We do not opt your data into any model training.
Retention
Snapshots are retained for as long as the service relationship is active, so we can compute month-over- month deltas and track outcomes of past recommendations. On termination of service, all client-specific data is deleted within 30 days.
Sharing
We do not sell, share, or disclose your data to any third party. The only external services that ever receive a derivative of your data are: Neon (database storage), OpenRouter and Anthropic (LLM inference, on aggregated metrics only), Telegram (the short summary message we send you each cycle), and Cloudflare (which proxies the web app that serves your recommendation page and authenticates your sign-in).
How to revoke access
You can revoke Halfborg's access at any time, with no involvement from us:
- Search Console, GA4 — remove the Halfborg operator account email from the property's user list in the relevant dashboard.
- Google Ads — in your Ads account, go to Tools → Account access → Manager accounts, and unlink the Halfborg manager account.
- Meta Ads — in Business Manager, remove the Halfborg system user from your ad-account access.
- WordPress — revoke the application password under Users → Profile.
To request deletion of your stored data, email [email protected] — data is deleted within 30 days of the request.
Changes to this policy
Material changes to this policy will be communicated by email to active clients before they take effect. The effective date at the top of this page is updated when changes are made.
Contact
Privacy questions, deletion requests, or anything else: [email protected].