Howzi Privacy Policy
At Howzi, we believe understanding your data should be easy – and understanding how we handle it should be just as straightforward. This Privacy Policy explains what information Howzi processes when you use our website, application and supported connections to AI assistants or other applications.
1. Who is responsible
Howzi is provided by velyoo AG, a company based in Switzerland.
Registered business address: velyoo AG, Eblinweg 2, 7000 Chur, Switzerland
Privacy contact: our support team
Website: https://howzi.ai
velyoo AG is responsible for personal data processed to operate Howzi, subject to applicable law and any separate responsibilities of integrated service providers.
2. Categories of information
Depending on your interaction with Howzi, we process:
- Identity and account data: account identifiers, federated sign-in identifiers and profile information needed for authentication and account management.
- Data-source connections: authorized Google Analytics property identifiers and metadata, Google OAuth access/refresh tokens and their validity information.
- Dashboard configurations: dashboard names, selected KPIs, comparison periods, event bindings and other preferences.
- Temporary report data: analytics metrics and dimensions fetched to answer a request or render a dashboard; these report values are processed in memory and returned to the requesting application, but are not stored as durable report results in Howzi.
- Limited request-derived operational metadata: operation type, time/period and dashboard/property references, hashed fingerprints and retry counters, subject to limited retention. This is not the same as a stored chat conversation or report response.
- Authentication, session and security data: active sessions, authorization grants, temporary OAuth transaction state, security events and account-level allowance counters.
- Website analytics data: with the relevant consent, website pages visited, approximate location, browser/device characteristics, referral information and online identifiers collected through Google Analytics 4 and tags managed by Google Tag Manager.
- Pro launch-interest information: email address, signup time, selected language and separate optional marketing preference, only if you submit the Pro notification form.
- Support correspondence: information you send to our support team.
3. Google Analytics connections
When you connect a GA4 property, Howzi uses Google's OAuth 2.0 authorization process. The application requests the scope https://www.googleapis.com/auth/analytics.readonly to retrieve analytics information without modifying your property. Google identity sign-in may separately request openid, email and profile to identify the signing-in user; these identity scopes are distinct from access to analytics reports.
You choose which accessible Analytics property to authorize. Howzi uses these permissions to retrieve the measurements relevant to your requests and configured KPIs. It does not sell your connected Analytics data or use that data for advertising.
You may revoke Howzi's Google access through your Google Account settings at https://myaccount.google.com/permissions. Disconnecting a property removes the currently stored Google connection credentials from the active Howzi account profile; the application attempts Google token revocation. Saved dashboard configuration/metadata is not currently deleted automatically on disconnect.
4. Connected AI assistants and other applications
Howzi offers its tools and analytics results to authorized clients through the Model Context Protocol (MCP) and related integrations. ChatGPT is the currently supported conversational assistant. Further clients may be supported in the future.
When a client invokes a Howzi tool, Howzi temporarily processes the tool arguments, retrieves relevant authorized Google Analytics data and returns results to that client. Howzi does not store chat transcripts, the raw incoming conversational request body or the returned analytics report values as persistent report data.
To operate the service, Howzi does retain limited configuration, usage, security and request-derived metadata, such as 24-hour operation receipts and hashed fingerprints. Details appear in Section 7. The statements above therefore do not mean that Howzi stores no request-related information whatsoever.
Howzi does not make independent calls to language models or AI processing services in this request flow. When analytics information is returned to a connected assistant such as ChatGPT, that assistant may interpret, display or otherwise process the information under its own applicable policies, terms and settings. You should consider the data-handling practices of the assistant you choose.
5. Cookies and analytics on the Howzi website
We use Google Analytics 4 to understand visits to howzi.ai and Google Tag Manager to manage the deployment of website tags. Website traffic tracking is separate from the GA4 property you connect to your Howzi account to ask questions.
Subject to your analytics consent, website measurement may collect visited pages, interactions, referral sources, device and browser characteristics, approximate location, and online identifiers. Google may process relevant technical information, including IP addresses, in operating its services.
Typical Google Analytics cookies (actual cookies depend on the deployed tag setup and browser):
| Name | Purpose | Typical default lifespan |
|---|---|---|
_ga | Distinguishes visitors | Up to 2 years |
_ga_<measurement-container-id> | Persists session-related state | Up to 2 years |
Google Tag Manager itself manages tags; the cookies that may be set depend on the tags actually configured. Howzi also uses essential authentication/session cookies within its application. Examples include login state cookies (approximately 5 minutes), onboarding state (approximately 15 minutes) and an authenticated session cookie (normally 24 hours). Essential cookies are required for secure logins and connections.
Your choices: We ask whether you agree to optional website analytics before loading Google measurement tags. You can Accept analytics, Reject analytics or change your decision later using Cookie settings in the footer. Essential security/authentication cookies do not require optional analytics consent. No advertising or personalization tags are planned for the launch version.
Read about Google's processing at https://policies.google.com/technologies/partner-sites.
6. How and why we use information
We use personal information where necessary to provide and secure accounts and connections, retrieve requested reports, display saved KPIs, administer usage limits, answer support requests, operate the site, and comply with applicable obligations. With your choice to allow analytics tracking, we use website measurement to improve our public website. If you register for Pro updates, we use your email to notify you when Pro becomes available; additional product marketing requires a separate opt-in.
7. Storage and retention
Howzi's primary application data is hosted in Microsoft Azure West Europe (Netherlands, European Union). The current production application stores encrypted account and operational records in Azure Table Storage, with secrets referenced from Azure Key Vault. The application has not implemented a PostgreSQL database for this service.
The supplied technical audit found the following retention behavior:
| Category | Observed retention / implementation |
|---|---|
| Chat transcripts, raw MCP request bodies and retrieved report values | Not persistently stored as chat/report records by Howzi; handled during request or page lifetime |
| Operation/usage receipts (metadata, not results) | 24 hours |
| Daily usage counters | 62 days |
| Short-term rate-limiting counters | Approximately 120 seconds |
| Security events (event type, pseudonymous account identifier, time) | 30 days |
| Temporary configuration/discovery cache | Approximately 30 minutes |
| Login/onboarding transaction state | Typically 5–15 minutes |
| Browser authenticated session | Default 24 hours; may be renewed |
| Authorization grants | Up to 90 days; invalid after 30 days of inactivity, subject to token/grant implementation |
| Identity profiles, Google connection credentials and saved dashboard settings | Currently no automatic account-level expiry; remain until an applicable action/process removes them |
| Website GA4 data | |
| Operator-selected diagnostic captures and Azure/provider logs | |
| Pro waitlist email data |
Expired operational records are rejected after their expiry and cleaned by a scheduled maintenance job. Physical deletion can lag the expiry time. Current Google property disconnect does not automatically remove saved dashboards. A self-service account deletion workflow is not yet implemented. To request account/data deletion, please contact our support team; requests will be assessed and handled according to applicable rights and technical capabilities. We do not promise an automated or fixed 24-hour deletion period.
8. Third parties and international processing
Relevant recipients and service providers include Microsoft Azure and Microsoft Entra (infrastructure, identity), Google (Google sign-in, Google Analytics APIs, and public website measurement), and OpenAI/ChatGPT when you choose to invoke Howzi in ChatGPT. Other connected client applications may receive tool outputs only when authorized and supported.
Although primary Howzi application storage is in Azure West Europe, Google, OpenAI and authentication providers may process information in additional locations. An EU infrastructure region for Howzi does not guarantee that all third-party processing remains inside the EU.
9. Your choices and rights
Depending on applicable law, you may request information about personal data, correction, deletion or other applicable rights. You can withdraw optional website analytics consent via the footer's Cookie settings control. You can revoke Google's access using Google Account permissions. You can request removal from the Pro notification list through our support team; the form must also disclose how to withdraw.
Contact: our support team.
Our business is based in Switzerland and the Swiss Federal Act on Data Protection (FADP) applies. Other mandatory laws, including GDPR where its territorial requirements are met, may also apply regardless of our Swiss establishment.
10. Updates and contact
We may update this policy as Howzi evolves. The effective date and current version are available at https://howzi.ai/privacy. If a material change legally requires notice or renewed consent, we will provide it.
velyoo AG
velyoo AG, Eblinweg 2, 7000 Chur, Switzerland
Switzerland
our support team