HOWZI · SWITZERLAND

Howzi Privacy Policy

At Howzi, we believe understanding your data should be easy – and understanding how we handle it should be just as straightforward. This Privacy Policy explains what information Howzi processes when you use our website, application and supported connections to AI assistants or other applications.

1. Who is responsible

Howzi is provided by velyoo AG, a company based in Switzerland.

Registered business address: velyoo AG, Eblinweg 2, 7000 Chur, Switzerland
Privacy contact: our support team
Website: https://howzi.ai

velyoo AG is responsible for personal data processed to operate Howzi, subject to applicable law and any separate responsibilities of integrated service providers.

2. Categories of information

Depending on your interaction with Howzi, we process:

3. Google Analytics connections

When you connect a GA4 property, Howzi uses Google's OAuth 2.0 authorization process. The application requests the scope https://www.googleapis.com/auth/analytics.readonly to retrieve analytics information without modifying your property. Google identity sign-in may separately request openid, email and profile to identify the signing-in user; these identity scopes are distinct from access to analytics reports.

You choose which accessible Analytics property to authorize. Howzi uses these permissions to retrieve the measurements relevant to your requests and configured KPIs. It does not sell your connected Analytics data or use that data for advertising.

You may revoke Howzi's Google access through your Google Account settings at https://myaccount.google.com/permissions. Disconnecting a property removes the currently stored Google connection credentials from the active Howzi account profile; the application attempts Google token revocation. Saved dashboard configuration/metadata is not currently deleted automatically on disconnect.

4. Connected AI assistants and other applications

Howzi offers its tools and analytics results to authorized clients through the Model Context Protocol (MCP) and related integrations. ChatGPT is the currently supported conversational assistant. Further clients may be supported in the future.

When a client invokes a Howzi tool, Howzi temporarily processes the tool arguments, retrieves relevant authorized Google Analytics data and returns results to that client. Howzi does not store chat transcripts, the raw incoming conversational request body or the returned analytics report values as persistent report data.

To operate the service, Howzi does retain limited configuration, usage, security and request-derived metadata, such as 24-hour operation receipts and hashed fingerprints. Details appear in Section 7. The statements above therefore do not mean that Howzi stores no request-related information whatsoever.

Howzi does not make independent calls to language models or AI processing services in this request flow. When analytics information is returned to a connected assistant such as ChatGPT, that assistant may interpret, display or otherwise process the information under its own applicable policies, terms and settings. You should consider the data-handling practices of the assistant you choose.

5. Cookies and analytics on the Howzi website

We use Google Analytics 4 to understand visits to howzi.ai and Google Tag Manager to manage the deployment of website tags. Website traffic tracking is separate from the GA4 property you connect to your Howzi account to ask questions.

Subject to your analytics consent, website measurement may collect visited pages, interactions, referral sources, device and browser characteristics, approximate location, and online identifiers. Google may process relevant technical information, including IP addresses, in operating its services.

Typical Google Analytics cookies (actual cookies depend on the deployed tag setup and browser):

NamePurposeTypical default lifespan
_gaDistinguishes visitorsUp to 2 years
_ga_<measurement-container-id>Persists session-related stateUp to 2 years

Google Tag Manager itself manages tags; the cookies that may be set depend on the tags actually configured. Howzi also uses essential authentication/session cookies within its application. Examples include login state cookies (approximately 5 minutes), onboarding state (approximately 15 minutes) and an authenticated session cookie (normally 24 hours). Essential cookies are required for secure logins and connections.

Your choices: We ask whether you agree to optional website analytics before loading Google measurement tags. You can Accept analytics, Reject analytics or change your decision later using Cookie settings in the footer. Essential security/authentication cookies do not require optional analytics consent. No advertising or personalization tags are planned for the launch version.

Read about Google's processing at https://policies.google.com/technologies/partner-sites.

6. How and why we use information

We use personal information where necessary to provide and secure accounts and connections, retrieve requested reports, display saved KPIs, administer usage limits, answer support requests, operate the site, and comply with applicable obligations. With your choice to allow analytics tracking, we use website measurement to improve our public website. If you register for Pro updates, we use your email to notify you when Pro becomes available; additional product marketing requires a separate opt-in.

7. Storage and retention

Howzi's primary application data is hosted in Microsoft Azure West Europe (Netherlands, European Union). The current production application stores encrypted account and operational records in Azure Table Storage, with secrets referenced from Azure Key Vault. The application has not implemented a PostgreSQL database for this service.

The supplied technical audit found the following retention behavior:

CategoryObserved retention / implementation
Chat transcripts, raw MCP request bodies and retrieved report valuesNot persistently stored as chat/report records by Howzi; handled during request or page lifetime
Operation/usage receipts (metadata, not results)24 hours
Daily usage counters62 days
Short-term rate-limiting countersApproximately 120 seconds
Security events (event type, pseudonymous account identifier, time)30 days
Temporary configuration/discovery cacheApproximately 30 minutes
Login/onboarding transaction stateTypically 5–15 minutes
Browser authenticated sessionDefault 24 hours; may be renewed
Authorization grantsUp to 90 days; invalid after 30 days of inactivity, subject to token/grant implementation
Identity profiles, Google connection credentials and saved dashboard settingsCurrently no automatic account-level expiry; remain until an applicable action/process removes them
Website GA4 data
Operator-selected diagnostic captures and Azure/provider logs
Pro waitlist email data

Expired operational records are rejected after their expiry and cleaned by a scheduled maintenance job. Physical deletion can lag the expiry time. Current Google property disconnect does not automatically remove saved dashboards. A self-service account deletion workflow is not yet implemented. To request account/data deletion, please contact our support team; requests will be assessed and handled according to applicable rights and technical capabilities. We do not promise an automated or fixed 24-hour deletion period.

8. Third parties and international processing

Relevant recipients and service providers include Microsoft Azure and Microsoft Entra (infrastructure, identity), Google (Google sign-in, Google Analytics APIs, and public website measurement), and OpenAI/ChatGPT when you choose to invoke Howzi in ChatGPT. Other connected client applications may receive tool outputs only when authorized and supported.

Although primary Howzi application storage is in Azure West Europe, Google, OpenAI and authentication providers may process information in additional locations. An EU infrastructure region for Howzi does not guarantee that all third-party processing remains inside the EU.

9. Your choices and rights

Depending on applicable law, you may request information about personal data, correction, deletion or other applicable rights. You can withdraw optional website analytics consent via the footer's Cookie settings control. You can revoke Google's access using Google Account permissions. You can request removal from the Pro notification list through our support team; the form must also disclose how to withdraw.

Contact: our support team.

Our business is based in Switzerland and the Swiss Federal Act on Data Protection (FADP) applies. Other mandatory laws, including GDPR where its territorial requirements are met, may also apply regardless of our Swiss establishment.

10. Updates and contact

We may update this policy as Howzi evolves. The effective date and current version are available at https://howzi.ai/privacy. If a material change legally requires notice or renewed consent, we will provide it.

velyoo AG
velyoo AG, Eblinweg 2, 7000 Chur, Switzerland
Switzerland
our support team