Privacy
DataLens AI is in beta. This page describes what the product collects today.
What we never collect
Your questions, the SQL DataLens writes, the rows any query returns, your column and table names, your ad account names, your uploaded files, and your API keys are never sent to our analytics provider. They are not part of any usage measurement, and no third party receives them.
Credentials you give DataLens — API keys, ad-platform tokens, warehouse connection details — are encrypted at rest with AES-256-GCM and are only decrypted server-side to run the query you asked for.
What the AI provider sees
Answering a question means sending it, your schema, and the query results to the model provider you selected — that is what produces the answer. DataLens is not a party to that provider’s retention or training terms, so rather than ask you to take those terms on trust, there is a switch that removes the question: Settings → Privacy → “Hide identifying values from the model”.
With it on, every identifying value — customer names, emails, account and order IDs, campaign names — is replaced with a stable placeholder like DLX_A_7K2M9QRTVX on our server, in the moment before the request leaves for the provider, and restored the moment the answer comes back. The provider never receives the real value. You keep seeing real names on screen, in charts, and in CSV and Excel exports.
Because each value always maps to the same placeholder, the model can still group, rank, join and filter on it — this is reversible pseudonymization, not encryption, which is what lets the analysis keep working. Numbers, dates and fixed platform vocabulary (campaign status, country, device and the like) are sent unchanged, so every figure stays exact. It applies to values, not to column or table names.
The switch is off by default and takes effect from the moment you turn it on; it does not reach back into conversations you have already had. You can also override any individual column to always hide or always send plainly. Two further options put the choice of provider in your hands entirely: bring your own API key, or point DataLens at an OpenAI-compatible endpoint running on your own hardware.
Product analytics
We use Google Analytics 4 to understand which parts of DataLens get used — for example, that a chart was exported, that a data source was connected, or that a scheduled report was created. Events carry the type of thing that happened, never its content.
Google Analytics sets cookies named _ga and _ga_<id> to tell visits and sessions apart. If you are signed in, we also attach your account’s internal identifier so usage can be counted per person rather than per browser. Your email address, display name, and profile photo are never sent.
Analytics cookies are set on every visit. To stop the collection, block Google Analytics in your browser — via its tracking protection, a content blocker, or Google’s own opt-out add-on. The product works exactly the same either way.
Advertising
We advertise DataLens on Meta’s platforms, and our site carries the Meta pixel so we can tell which ads lead to someone actually signing up. It reports three things to Meta: that a page was viewed, that the contact form on our home page was submitted, and that an account was created. Nothing about what you do inside the product is sent — not your questions, your data, your connected sources, or your usage.
The pixel sets a cookie named _fbp on this site, and Meta can match the visit against its own cookies if you are a Facebook or Instagram user. We do not send your email address, phone number, or name to Meta — Meta’s “advanced matching” feature is switched off deliberately, including its hashed form.
To stop it, block the pixel with a content blocker or your browser’s tracking protection, and use Meta’s ad preferences to control how activity off their platforms is used. As with analytics, the product works exactly the same either way.
Your account and your work
Signing in uses Firebase Authentication, which stores your email address and, for Google sign-in, your name and profile photo.
Your conversations are stored so you can come back to them: the questions you asked, the answers DataLens gave, and up to 50 rows per message of the data behind them. We also keep a usage ledger of token counts and query costs so the Usage page can show you what you have spent. Deleting a conversation removes it.
Creating a share link publishes a read-only copy of that one conversation to an unlisted URL. Anyone holding the link can read it.
Third parties
Google (Firebase Authentication, Cloud Firestore, Google Analytics) hosts your account and your saved conversations. Vercel hosts and serves the application. Formspree receives the contact form on our home page. Meta receives the advertising measurements described above. The AI provider you select receives the messages in the turn you send — that is what generates the answer — and DataLens does not choose that provider for you. What that provider does and does not receive is covered under “What the AI provider sees” above.
Contact
Questions, or a request to delete your account and its data: contact.datalensai@gmail.com.