Legal

Privacy Policy

Last updated 2026-08-21

This policy describes how Natively (“Natively,” “we,” “us”) collects, uses, stores, and shares information when you use getnatively.ai and the Natively client portal (app.getnatively.ai), including information accessed through third-party accounts you connect, such as Google.

Information we collect

We collect information in three ways:

  • Account and contact information you provide directly: name, work email, company, and any information submitted through a form on this site.
  • Usage data: page views, referrers, device type, and, on select marketing pages, deeper behavioral analytics and session recording, see “Analytics and session recording” below.
  • Data from connected third-party accounts you explicitly authorize, see “Google user data” below.

Analytics and session recording

On some of our marketing pages, we use PostHog, a third-party analytics provider acting as our data processor and hosted in the United States, to understand how visitors use the site.

  • What we collect. Page views, referrers, and device type, plus behavioral events: scroll depth, which sections of a page you view, clicks, and how long you spend on a page. If you interact with a form, we also record which field you focused, which fields you completed, and which field you were on last before leaving.
  • Session recording. We record a replay of the page as you saw it, including mouse movement, scrolling, and clicks. Anything you type into a form field is masked and is never recorded. The page’s own text, which is our marketing copy, is not masked.
  • No cookies. This analytics tooling does not use cookies. Instead, an identifier is stored in your browser’s local storage.
  • Approximate location. We derive an approximate location (country and region) and network operator from your connection, server-side, to help distinguish real visitors from automated traffic.
  • Form submissions. If you submit our access-request form, that submission is linked to your analytics session using a salted one-way hash of your email address, so your email address itself is never sent to the analytics provider. The form’s actual contents (name, email, brand, and your answers) go to Brevo, our email and CRM provider, not to the analytics provider.

On getnatively.ai we also use Apollo’s website visitor tool, which matches visits to the companies they come from. It works at the company level and does not identify you as an individual.

Your choice. None of these analytics tools load until you accept them in the cookie banner. You can change your answer at any time with the Cookie settings link in the page footer. If your browser sends a Global Privacy Control signal, we treat it as a rejection and do not ask.

Google user data

If you connect a Google account to the Natively client portal, we request read-only access to two Google APIs, solely to power the analytics features you’ve asked for:

  • Google Search Console API (webmasters.readonly scope): organic search performance: clicks, impressions, click-through rate, and average position, broken down by query, page, country, and date, for the property you select.
  • Google Analytics Data API (analytics.readonly scope): sessions, conversions, engagement, and traffic-source data for the property you select.

How we use it. This data is used exclusively to render analytics dashboards inside your Natively client portal and, where you’ve enabled it, to inform the SEO and content use case’s opportunity scoring (e.g. identifying search queries where you rank on page two). We do not use Google user data for advertising, and we do not sell it.

How we store it. Search Console and Analytics data are stored in a Postgres database isolated to your organization’s own schema, never a shared table across customers. Your OAuth refresh token is encrypted at rest (AES-256-GCM) and used only to request short-lived access tokens for the scopes above.

How we share it. We do not share Google user data with any third party, except: (a) our infrastructure providers (Cloudflare, Neon) strictly as data processors to operate the service, under standard processing terms, and (b) if required by law.

Human access. Natively staff do not access your Google-sourced data except as needed to provide customer support you’ve requested, or to debug a reported issue.

Retention and revocation. You may disconnect your Google account at any time from Settings → Integrations. Disconnecting revokes our access token immediately and deletes the stored refresh token; previously synced Search Console / Analytics rows remain in your workspace (so historical charts don’t break) until you request deletion.

Compliance. Natively’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data from AI providers

Natively uses large-language-model providers (including Anthropic) to draft content and score opportunities. Prompts sent to these providers may include data from your connected accounts (e.g. a search query and its ranking) strictly to generate the specific output you requested. We do not permit these providers to use your data to train their models, per our agreements with them.

Your choices

  • Disconnect any connected account at any time from Settings → Integrations.
  • Request a copy or deletion of your data by contacting us (see below).
  • Every automated action Natively takes on your behalf routes through a human-review queue before it executes. Nothing publishes or sends without your approval.

Contact

Questions about this policy or your data: [email protected].

Changes to this policy

We’ll update the “Last updated” date above when this policy changes, and post material changes here before they take effect.