Kavanah Analytics / Security

Security and your data

If your team works somewhere that makes you careful about what leaves your building, this page is for you. Everything here is also in our privacy policy — this is the plain-English version.

Where your data lives

On servers in the United States. Encrypted in transit with TLS 1.2 or higher, and encrypted at rest. Access inside our team is least-privilege and audit-logged, and environments are kept separate from one another.

What we can see, and what we can't

When you connect Meta or Google, we request read-only access. We can read your page insights, ad performance, YouTube analytics, and GA4 metrics. We cannot post on your behalf, change your campaigns, reply to your messages, or touch anything in your account. Not “we choose not to” — the permissions we hold don't allow it.

What we never ask for

Your platform passwords. We connect through Meta's and Google's own authorization screens, so your credentials go to them, never to us. If anyone claiming to be from Kavanah asks you for a password, an API key, or account access, it isn't us — forward it to privacy@kavanahanalytics.com.

Who can see your numbers

Your organization's data is visible to the people in your organization, scoped by the role you give them. A team lead sees their team. A director sees the org. Nobody sees another organization's data.

Sign-ins support two-factor authentication, so a stolen password alone doesn't open an account.

How long we keep things

Your accountWhile it's active, then 90 days after deletion
Meta and Google access tokensWhile active; deleted within 30 days of being revoked
Cached Meta insights25 months by default, configurable
Cached Google analyticsA window you configure, then deleted or anonymized
Server and security logsUp to 13 months, then purged automatically

Getting your data out, or deleting it

Ask and we delete it — within 30 days, either way you prefer:

You can also request a portable copy of your data. Full detail: data deletion.

Who else touches your data

Amazon Web Services hosts the platform. Your data sits on AWS infrastructure in the United States, and AWS is the only outside company we hand your data to.

Separately — and this is a different thing — you choose which platforms to connect: Meta, Google, Chatwoot, Echo, Disciple.Tools. Those aren't companies we share your data with. They're your own accounts, which you authorize us to read from and can revoke at any time. Your data flows from them to you, through us. It doesn't flow the other way.

What we don't do

We don't sell your data. We don't use it for advertising. We don't share it with other organizations on the platform. And we don't use your data to train AI models — when you use our built-in AI features, your question is answered at query time and nothing about it is kept for training, by us or by the model provider. There is no version of our business that depends on doing any of that — see below.

Who you're actually trusting

Kavanah Analytics is built by Kavanah Media, a Tennessee nonprofit corporation and 501(c)(3) tax-exempt organization, based in Maryville, Tennessee.

That matters more than it sounds. We're not a venture-funded startup that needs to monetize your data later, and there's no acquisition on the horizon that quietly rewrites these terms. Where we handle data on behalf of your organization, we do it as your processor — you remain the controller of your own information.

And if we disappeared tomorrow

Kavanah Analytics is open source. You can read the code that handles your data, and you can run your own copy on your own servers. Your reporting isn't something we're able to lock you out of, whatever happens to us.

Questions your security review needs answered

Send them to privacy@kavanahanalytics.com. If your organization needs a call with someone technical before you connect anything, ask — we'd rather have that conversation than have you skip the platform.