Privacy Policy
Last updated 23 September 2026
Pretty Metrics turns the revenue data in your payment provider into good-looking charts and share cards. To do that we need to hold some information about you, your products and the payment accounts you connect. This policy explains what we collect, why, who else is involved and the choices you have.
In this policy, “Pretty Metrics”, “we”, “us” and “our” mean Maximilian Winter-Leinweber, who runs the service from England, United Kingdom, and is the controller of your personal data. “You” means the person using the service. If anything here is unclear, email us at maxwinterleinweber@gmail.com.
The short version
- We collect your email address and password to run your account, and the product details and API keys you give us.
- Payment provider API keys are encrypted before they are stored and are never shown back to you in full.
- Your revenue data is read from your payment provider when you ask for a chart. We do not copy it into our database.
- Images you export are made in your browser. We do not receive or keep them.
- We do not sell your data, show ads or use tracking or analytics cookies.
- You can delete your account, and everything in it, from your dashboard at any time.
Information we collect
Your account
When you sign up we collect your email address and a password. We use the part of your email address before the “@” as your display name. To confirm that the address is yours we email you a one-time verification code. Passwords are handled by our authentication provider and are stored only in hashed form, so nobody at Pretty Metrics can read them. We also record basic account details such as when your account was created and whether your email address has been verified.
Your products
For each product you add we store its name, website address, logo (either the address of an image on your website or a small image you upload) and brand colours, together with the background designs we generate from those colours.
When you enter a website address, our servers visit that public website to suggest the product’s name, logo and colours. We read only what the site publishes about itself, such as its title, icons, web app manifest and stylesheets, and we keep only the suggestions you choose to save.
Payment provider API keys
To read your metrics you give us an API key for each payment provider your product uses (for example Stripe, Paddle, Lemon Squeezy, Polar, RevenueCat, Square or Creem). We ask for keys with read-only access wherever the provider supports it, and for Stripe we only accept restricted keys. Keys are encrypted with AES-256-GCM before they reach our database, using an encryption key that is kept separately from the database. After you save a key we only ever display its last four characters.
Data read from your payment providers
When you open the studio or build a chart, our servers use your key to read the records needed to calculate your metrics, such as subscriptions, payments, products and prices. From these we work out figures like monthly recurring revenue, revenue, subscribers, churn and cancellation reasons.
These records can include information about your customers, such as customer identifiers, billing country and, depending on the provider, names or email addresses. We use only the fields needed for the calculations (identifiers, dates, amounts, currencies, plans, billing intervals, countries and cancellation reasons). The results are held briefly in server memory, for about five minutes, so that switching between charts is fast, and are then discarded. We do not write this data to our database.
Images you create
Share cards and charts are drawn and exported entirely in your browser. When you download, copy or share an image, it goes straight from your device to wherever you send it. We do not receive or store a copy.
Messages you send us
If you email us, for example to suggest a feature, we keep your message and email address so we can reply and follow up.
Technical information
Like most websites, our hosting provider automatically records technical information when you use the service, such as your IP address, browser type, the pages requested and the time of each request. This is used to keep the service running, secure and free of abuse. We also log errors on our servers to fix problems; we take care that these logs never contain your API keys.
How we use your information
We use the information above only to:
- create and secure your account and sign you in;
- show your products and build the charts, metrics and share cards you ask for;
- provide support, investigate problems and fix bugs, including checking what the service shows for your account when you report an issue;
- send you messages about the service, such as verification codes or important changes to these documents;
- protect the service and its users from fraud, abuse and security threats; and
- meet our legal obligations.
We do not use your data, or your customers’ data, for advertising, and we do not sell it or share it with data brokers.
Legal bases for processing
We handle personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 and, for users in the European Economic Area, the EU General Data Protection Regulation. We rely on the following legal bases:
- Performance of a contract: to provide the service you signed up for, including your account, products, keys and charts.
- Legitimate interests: to keep the service secure, prevent abuse, fix problems and improve the product, in ways you would reasonably expect.
- Legal obligation: where the law requires us to keep or disclose information.
- Consent: where we ask for it. You can withdraw consent at any time.
Your customers’ data
When our servers read your payment accounts on your behalf, we process your customers’ information only on your instructions and only to produce your metrics. For that processing, you are the controller and we act as your processor. You are responsible for having a lawful basis to share that data with a service like ours and for telling your customers about it where the law requires, for example in your own privacy policy.
Who we share information with
We share information only with service providers that help us run Pretty Metrics, and only as far as they need it:
- Neon, which hosts our database and runs our account system, including sending verification emails.
- Vercel, which hosts the website and servers that run the service.
- The payment providers you connect. We send each one your API key to read your data, as you ask us to. Their own terms and privacy policies apply to the data they hold.
- The websites you enter. When we visit a product’s website to suggest its details, that website sees a request from our servers, not from you.
We may also disclose information if the law requires it, to protect the rights, safety or property of our users, the public or Pretty Metrics, or as part of a merger, acquisition or sale of the service, in which case this policy will continue to apply to your data or you will be told about any change.
International transfers
Our service providers may store or process information outside the United Kingdom, including in the United States. Where data leaves the United Kingdom or the European Economic Area, we rely on appropriate safeguards, such as UK adequacy regulations (including the UK-US data bridge), the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, or the Standard Contractual Clauses themselves.
How long we keep information
- Account details are kept for as long as your account exists.
- Products and API keys are kept until you remove the product or delete your account. Removing a product deletes it and all of its keys straight away.
- Data read from payment providers is held in server memory for about five minutes and is never written to our database.
- Emails you send us are kept for as long as needed to deal with them.
- Server and error logs are kept for a limited period set by our hosting provider and then deleted.
You can delete your account at any time from the account menu in the bottom corner of your dashboard. This immediately and permanently deletes your account, email address, password, products and API keys, and signs you out. If you can’t sign in, email us from the address you signed up with and we will delete it for you within 30 days. Copies in our providers’ backups are overwritten on their normal schedule, usually within a few weeks.
How we protect information
We take reasonable technical and organisational measures to protect your information. Traffic is encrypted in transit with HTTPS. API keys are encrypted at rest and each encrypted key is tied to the account that owns it, so it cannot be moved to another account and decrypted. Your products, keys and metrics can only be reached by your own signed-in account, and sessions are kept in signed cookies. Access to our systems is limited to the people who run the service.
No system is perfectly secure. Using read-only keys, as we ask, limits what anyone could do with a key even in the unlikely event it were exposed. If you think your account or a key has been compromised, revoke the key with your payment provider and contact us straight away.
Cookies and local storage
We use a small number of cookies that are strictly necessary for the service to work, mainly to keep you signed in. We also store your light or dark theme choice in your browser’s local storage. We do not use analytics, advertising or third-party tracking cookies, so we do not ask for cookie consent.
Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- correct information that is wrong or incomplete;
- have your data deleted;
- restrict or object to how we use it;
- receive your data in a portable format or have it sent to another service; and
- withdraw any consent you have given.
You can edit your products, remove products and keys, and delete your account yourself from your dashboard at any time. For anything else, email us at maxwinterleinweber@gmail.com. We will respond within one month and may need to confirm your identity first. We will not treat you differently for exercising your rights.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk. If you live in the European Economic Area, you can complain to your local data protection authority instead. We would appreciate the chance to address your concerns first.
If you are a California resident, you have the rights described above under the California Consumer Privacy Act. We do not sell or share personal information for cross-context behavioural advertising.
Children
Pretty Metrics is a tool for businesses and is not meant for anyone under 16. We do not knowingly collect personal data from children. If you think a child has given us their information, contact us and we will delete it.
Changes to this policy
We may update this policy as the service changes. We will change the date at the top when we do, and if the changes are significant we will tell you by email or in the app before they take effect.
Contact us
Questions, requests or complaints about privacy can be sent to maxwinterleinweber@gmail.com. See also our Terms of Service.