Privacy policy
This policy describes how AE Labs Inc (“AE Labs”, “we”, “us”) collects, uses, and shares information when you use FunnelKeeper — the website at funnelkeeper.com, the dashboard at app.funnelkeeper.com, the fk CLI, the MCP server, and the API (together, the “Service”).
If you have questions, email funnelkeeper@aelabs.ai.
Who we are
AE Labs Inc is a corporation registered in the State of Delaware, United States. FunnelKeeper is a product of AE Labs Inc.
What we collect
Account data. Your email address and a hash of your password. If you use Login with Google we also store your Google subject identifier and the name Google provides, so we can sign you back in without a password. Team invites store the invitee’s email until they accept or the invite expires.
Product data you connect. Traffic aggregates from Google Analytics 4; tag configuration from Google Tag Manager (read-only); advertising spend from Google Ads and, when you connect them, Meta Ads; SEO metrics from SEMrush (using a key you supply); revenue and funnel events from sources you wire up, including a MySQL view we may configure with you. This data is collected solely to compute the funnel, CAC, LTV, and payback reporting you see in your account, and to generate Keeper proposals for you to approve or reject.
Credentials. OAuth refresh tokens and API keys you provide are stored encrypted (AES-256-GCM) and used only to fetch the data above. Revoking access in your Google account or deleting the connection stops all collection immediately.
Landing-page analysis. If you ask FunnelKeeper to score a landing page, we fetch the page and send its text to our language-model provider so it can return a quality score against our rubric. That analysis is on-demand only — never a scheduled job.
Audit records. Actions taken in your account (approvals, rejections, connections, team changes) are logged with the acting user’s email for accountability.
Support and site use. Messages you send us, and standard server logs (IP address, user-agent, timestamps) needed to operate and secure the Service. The marketing site loads webfonts from Google Fonts. The marketing site and dashboard load Google Tag Manager, Google Analytics 4, Microsoft Clarity, and Plausible so we can see how people find FunnelKeeper and whether they finish signup — including session recordings of those pages. They also load the Opinly analytics pixel so we can attribute visits and sign-ups back to the campaign or post that earned them. Opinly stores an anonymous ID in local storage on that domain. When enabled, Meta Pixel measures visits and signup-CTA clicks from our Meta advertising; after an account is created, the API sends Meta the same registration event through Conversions API with a one-time deduplication id and a SHA-256 hashed, normalised email. We do not send Meta your password or connected product data. A hashed email is linked in Opinly only after you identify yourself (for example by creating an account). GA4 and Clarity receive an account id after you sign in, not your email.
How we use information
We use the information above to:
- provide, secure, and improve the Service
- authenticate you and enforce account-scoped access
- compute the reporting and Keeper proposals you see
- send transactional email (verification, password reset, invites)
- comply with law and enforce our terms of service
We do not use connected advertising, analytics, or revenue data to train general-purpose models, to advertise to you, or to build products for other customers.
Google API Services — Limited Use disclosure
FunnelKeeper’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data obtained via Google APIs (Analytics, Tag Manager, Google Ads) is used only to provide the reporting features you see in your FunnelKeeper account; it is never sold, never used for advertising, and never transferred except as necessary to provide the service, to comply with law, or as part of a merger with notice to you. Humans do not read this data except with your consent, for security purposes, or to comply with law.
How we share information
We share information only as needed to run the Service:
| Recipient | Why |
|---|---|
| Infrastructure hosts (currently Fly.io and Netlify) | Run the API, jobs, dashboard, and marketing site |
| Database host (currently Supabase) | Store account, event, and transaction data |
| Sign-in and the GA4 / Tag Manager / Ads connections you authorise | |
| Meta | The Ads connection you authorise, if you connect it; and Pixel / Conversions API measurement for FunnelKeeper’s own advertising |
| SEMrush | Weekly SEO snapshots, using the key you supply |
| Language-model provider (currently OpenRouter) | On-demand landing-page scoring you request |
| Email provider (Resend, once configured) | Verification, resets, and invites |
| Google Analytics and Tag Manager | First-party analytics on the marketing site and dashboard (visits, signup, onboarding) |
| Microsoft Clarity | Session recordings and interaction signals on the marketing site and dashboard |
| Plausible | Privacy-friendly visit and event counts on the marketing site and dashboard (no cookies, no personal identifiers) |
| Opinly | Marketing-site and dashboard analytics, and the blog content we publish from their CMS |
We may also share information if required by law, to protect the Service or our users, or as part of a merger, acquisition, or asset sale — in which case we will notify you.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
What we do not do
- No sale of data, to anyone, ever.
- No advertising or profiling use of connected data.
- No cross-account aggregation of your data into benchmarks without explicit opt-in.
Cookies and similar technology
The dashboard keeps your session token in browser storage so you stay signed in; it is not an advertising cookie. Google Analytics 4 and Tag Manager set first-party cookies (_ga, _gid, and related) so we can measure visits and signup. Microsoft Clarity sets first-party cookies (_clck, _clsk) and records a session replay of the page. Plausible does not set cookies and does not collect personal identifiers. When the Opinly pixel is enabled it stores an anonymous visitor ID in local storage (not a cookie) so a later conversion can be tied to the visit that started it. When Meta Pixel is enabled, Meta may set _fbp; a visit from a Meta ad may also set _fbc from its click identifier. Those values are sent with the matching server event when available so browser and server measurements deduplicate. We use this data to measure and improve FunnelKeeper’s acquisition, not to build advertising profiles from customer product data. Third parties we load (Google Fonts, Google Analytics / Tag Manager, Microsoft Clarity, Plausible, Opinly, Meta Pixel, and Google or Meta if you start an OAuth flow) may set their own cookies on their domains under their policies.
Retention and deletion
Connected analytics data is retained while the connection is active. Email support to delete an account; deletion removes credentials immediately and all account data within 30 days, except audit records we are legally required to keep.
You can disconnect a source at any time. Disconnecting deletes the stored credentials for that source and stops further collection. For a Google OAuth connection we also revoke the grant with Google. For a service-account connection we delete our service account; you should also remove that email from your GA4 property / GTM container.
Security
Credentials are encrypted at rest with AES-256-GCM, bound per row, with key rotation. Access to tenant data is account-scoped in the API. No one at AE Labs reads connected Google, Meta, or revenue data in the ordinary course of providing the Service. We may access an account with your consent, to diagnose a security issue, or to comply with law.
International transfers
AE Labs Inc is based in the United States. Service infrastructure currently runs in the United States (database) and Australia (API). If you access the Service from elsewhere, your information is processed in those locations. We take steps appropriate to the transfer, including contractual terms with our processors.
Your rights
Depending on where you live (including California and Australia), you may have the right to request access to, correction of, or deletion of personal information we hold about you, to opt out of any sale or sharing (we do neither), and to appeal a refusal. Email funnelkeeper@aelabs.ai. We will not discriminate against you for exercising these rights.
If you are acting for a business that has connected data about its own customers, that business is responsible for its own privacy obligations to those people. FunnelKeeper processes that data to provide the Service to the business.
Children
The Service is for businesses. It is not directed at children under 18, and we do not knowingly collect personal information from them.
Changes
We will post updates on this page and change the effective date. If a change materially affects how we use personal information, we will also notify account holders by email.
Contact
AE Labs Inc A Delaware corporation funnelkeeper@aelabs.ai
See also our terms of service.