Stats Compass logo
Home GitHub

Privacy Policy

Last updated: July 30, 2026

Who We Are

Stats Compass is operated by Inference Labs, based in the United Kingdom. For the purposes of UK GDPR, Inference Labs is the data controller for personal data processed through the hosted service. You can contact us at tunji@statscompass.io.

Overview

Stats Compass is available in three modes: local (installed on your own machine), self-hosted (run on your own server), and hosted (our cloud service at mcp.statscompass.io). This policy covers all three modes. The data we collect depends on which mode you use.

Local Mode

When you install Stats Compass via pip install stats-compass-mcp and run it locally, all data processing happens entirely on your machine. No data is sent to our servers. We have no access to your files or analysis results.

Self-Hosted Mode

When you run Stats Compass on your own server using stats-compass-mcp serve or Docker, you control where data is stored and processed. We have no access to your self-hosted instance.

Hosted Mode (mcp.statscompass.io)

When you use our hosted cloud service, we collect and process the following:

  • Email address — collected via OAuth sign-in (Google or email/password) and held by our authentication provider, Auth0. We use it to identify your account and to contact you about your subscription or service changes. It is not stored on the Stats Compass server, which identifies accounts by a salted, irreversible hash instead.
  • Usage counts — we count the number of tool calls you make per billing period to enforce free tier limits and bill paid subscribers. These are recorded against the hashed identifier, not your email.
  • Uploaded files and analysis results — files you upload and results generated during your session are stored temporarily on our server for the duration of your session. These are used solely to provide the service.

We do not collect or store the content of your conversations with your AI assistant, and we do not access your data for any purpose beyond providing the service.

Data Retention

  • Session data, uploaded files and exports — deleted when you call the delete_session tool, and automatically removed after 24 hours of inactivity.
  • Google Sheets access tokens — deleted when you disconnect, when you delete your account, or automatically after 90 days without use.
  • Usage counts — stored per calendar month against a pseudonymous account identifier, and deleted automatically 35 days after your first call in that month.
  • Server logs — automatically rotated, with the oldest entries overwritten once a fixed size is reached. Retention therefore varies with traffic. Logs record request paths and timestamps for security and debugging; they do not contain the contents of your files or spreadsheets.
  • Account data — retained for as long as your account is active. You can request deletion at any time by emailing us.

Your email address is held by our authentication provider (Auth0) and, if you subscribe, by Stripe. Stats Compass does not store your email address on its own servers — accounts are identified internally by a salted, irreversible hash.

Google Sheets Integration

Stats Compass can connect to your Google Sheets account to load spreadsheet data for analysis and save results back to Google Sheets. This integration is optional and requires your explicit consent via Google's OAuth flow.

Data accessed

When you connect Google Sheets, Stats Compass requests the spreadsheets scope, which allows it to read and write Google Sheets spreadsheets you direct it to. Stats Compass only accesses the specific spreadsheets you choose to load — it does not scan, index, or browse your Google account.

How your data is used

Spreadsheet data is loaded into memory for the sole purpose of performing the statistical analysis, visualisation, or transformation you request during your session. Results may be written back to a Google Sheet at your direction. Your Google Sheets data is not used for any other purpose.

Data storage and retention

Spreadsheet data loaded from Google Sheets is held in memory for the duration of your session and is not written to disk, unless you explicitly export it — for example by asking your assistant to save results as a CSV. Exported files are written to our server so you can download them, and are deleted along with the rest of your session data.

Session data and any exported files are deleted when you call delete_session, and are automatically removed after 24 hours of inactivity.

OAuth tokens granting access to your Google Sheets are stored in our Redis datastore, hosted on the same server, and are automatically deleted after 90 days without use. You can disconnect at any time in three ways: ask your AI assistant to disconnect Google Sheets, visit mcp.statscompass.io/google/disconnect, or revoke access from your Google Account connections. The first two revoke the grant with Google and delete our copy of the tokens. Deleting your Stats Compass account also revokes and deletes them.

Data transfer

Your Google Sheets data is not sold, shared with, or transferred to any third parties. Analysis results are returned to your AI assistant (e.g. Claude) as part of the normal conversation flow, subject to that platform's own privacy policy. No Google user data is transferred to advertising platforms, data brokers, or any other third parties.

Data protection

All connections to Google APIs are made over HTTPS. OAuth tokens are stored server-side and are never exposed to the client or the AI assistant. Spreadsheet data is processed in isolated, per-user sessions.

Google API Services Limited Use Disclosure

Stats Compass's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve, or train generalised AI/ML models.

Third-Party Services

We use the following third-party services in hosted mode:

  • Auth0 — handles authentication and sign-in. Your email address is shared with Auth0 for this purpose. See Auth0's Privacy Policy.
  • Stripe — handles payment processing for paid subscriptions. Payment information is processed directly by Stripe and is not stored on our servers. See Stripe's Privacy Policy.
  • Google — if you connect Google Sheets, OAuth tokens and API requests are processed by Google. Only the specific spreadsheets you choose to load are accessed. See Google's Privacy Policy.
  • Resend — delivers our account and product emails. Your email address and name are shared with Resend for this purpose. No file contents, spreadsheet data or analysis results are ever sent to Resend. See Resend's Privacy Policy.

Stats Compass does not sell your data or share it with any third parties beyond those listed above.

Stats Compass runs inside an AI assistant, so the results you ask for are returned to that assistant and handled under its own privacy policy. Depending on the platform and your settings there, general conversation content — excluding any content derived from Google Workspace data — may be used by that provider to improve their services.

Google Workspace data is excluded from all such use. Data retrieved from Google Sheets, and any results derived from it, is used solely to carry out the analysis you request. It is never used to develop, improve, or train any AI or machine-learning model, and is never transferred to any third party for that purpose.

The only transfer of Google Workspace data that occurs is returning the analysis you requested to the assistant you connected, so that it can be shown to you. That is the user-facing feature you invoked, and it happens only at your request. If you want to control how your assistant provider handles conversation content more generally, that setting lives with the provider — for example, Anthropic does not train models on business-tier or API traffic, and consumer accounts offer a training opt-out.

Your Controls

  • Delete session data — call the delete_session tool at any time to delete your session and all associated uploaded files from our servers.
  • Delete your account — email us at tunji@statscompass.io to request full account deletion.

Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Contract performance — processing your email, usage counts, and uploaded data is necessary to provide the Stats Compass hosted service and manage your subscription.
  • Legitimate interest — we use aggregated, non-identifying usage data to maintain and improve the service.

Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your personal data.
  • Portability — request your data in a machine-readable format.
  • Restriction — request that we limit how we process your data.
  • Objection — object to processing based on legitimate interest.

To exercise any of these rights, contact us at tunji@statscompass.io. We will respond within 30 days.

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk, or with your local supervisory authority if you are in the EEA.

Automated Decision-Making

Stats Compass does not carry out any automated decision-making or profiling that produces legal or similarly significant effects. Analysis results are produced only in response to your explicit requests, and are not used to make decisions about you.

Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office within 72 hours of becoming aware of it, and will inform affected users without undue delay where the risk is high.

Data Processing Locations

Your data may be processed in the following locations:

  • Stats Compass servers — hosted on DigitalOcean in London, United Kingdom.
  • Auth0 (Okta) — authentication services based in the United States. Auth0 maintains EU Standard Contractual Clauses for cross-border data transfers. See Auth0's Privacy Policy.
  • Stripe — payment processing based in the United States. Stripe maintains EU Standard Contractual Clauses for cross-border data transfers. See Stripe's Privacy Policy.
  • Resend — email delivery based in the United States. Resend maintains Standard Contractual Clauses for cross-border data transfers. See Resend's Privacy Policy.

Cookies

Stats Compass does not use cookies for analytics, advertising, or tracking. The only cookies used are those strictly necessary for authentication (session tokens set by Auth0 during sign-in).

Contact

For privacy-related questions, data protection requests, or account deletion:
tunji@statscompass.io

← Back to Home