Security & data

Your data stays under your control.

Read-only analytical access. You stay in control of every connection.

How access works

Four principles.

OAuth 2.0 connections

Every source is authorized through the provider's own login. Insigra receives a scoped token; the provider controls it, and you can revoke it there at any time.

Zero password storage

Insigra never sees, asks for, or stores a password for any connected system.

Read-only scopes

Insigra requests read access to performance data only. It cannot create, change or delete a campaign, budget, bid, order or record.

Clear data-handling policies

What is read, how long it is kept, and how to remove it are written plainly below and in the privacy policy.

Data handling

What is read, kept, and removed.

What Insigra reads

Aggregated performance data: spend, impressions, clicks, sessions, leads, orders, revenue and the campaign, channel and date they belong to. Insigra does not read customer PII from advertising platforms, and it does not read message content from email or CRM tools.

Where it is stored

Synced data is stored in Insigra's database so the weekly brief can compare periods. It is used to produce your briefs and for nothing else. It is never sold or shared.

How to remove it

Disconnect a source and its data is removed from your workspace. Close your account and all workspace data is deleted. You can also revoke Insigra's access directly from the provider (Google, Meta, Shopify, HubSpot) — the sync stops immediately.

What we don't claim

Insigra does not currently hold SOC 2, ISO 27001 or similar certifications, and we won't say otherwise until we do. If a certification matters to your evaluation, tell us.

Read-only access. Every connection in your control.

Connect a source in two minutes and revoke it in one.