Privacy policy
Effective July 14, 2026 · Updated September 3, 2026
Sibyl helps organizations deploy predictive GA4 audiences in their own Google Cloud environment. This policy explains how the hosted deployment portal and a self-deployed Sibyl application handle information, and what Making Science does with the personal data it holds.
Who is the data controller?
For the processing activities for which it determines the purposes and means, the data controller is Making Science Group, S.A. ("Making Science"), with registered office at C/ López de Hoyos, 135, 4th floor, 28002 Madrid, Spain, and Tax ID A82861428.
This policy governs the processing of personal data in connection with the Sibyl deployment portal at sibylpredicts.com (the "portal") and the use of the Sibyl predictive-audience software ("Sibyl").
Sibyl is designed to be deployed within the Google Cloud environment selected by the customer. The customer remains the data controller in respect of the GA4 end-user data processed within its own Google Cloud project and determines the purposes and means of that processing. Making Science does not receive or centrally host the customer's GA4 event-level data, model outputs, or audience scores as part of the normal operation of Sibyl. The one flow in which Making Science handles information that originates in an installed instance — the optional failure-alert relay — is described below.
Privacy enquiries and requests relating to processing carried out by Making Science may be sent to sibyl@group.makingscience.com. For data protection matters you may also contact Making Science's Data Protection Officer at dataprivacy@makingscience.com.
Personal data Making Science collects through the portal
For the proper functioning of the portal, Making Science may process the following personal data provided or generated in connection with you:
- your name and surname, as shown on the Google Account you sign in with;
- your email address, and whether Google reports it as verified;
- the record of the choices you made at sign-in — your acceptance of this policy and the terms of service, your decision on marketing contact, the version of the wording you were shown, and when — so that a refusal is a stored fact rather than an absence;
- the installation record described below: the Google Cloud project you selected, the one-time install token, and the installation's status.
Google Cloud also keeps standard request logs for the portal and the release service (IP address, request path, and time); those logs are retained for 30 days.
Google data used by the deployment portal
When you sign in, the portal requests your basic Google identity, the IDs and names of Google Cloud projects visible to you, and read-only access to your Google Analytics account and property metadata. It uses this information only to let you select a Cloud project and GA4 property, confirm that you can deploy into the selected project, identify that property's BigQuery export project, and generate the correct installation command. The portal cannot read data from other Google Cloud services.
The hosted portal does not train models, read GA4 event rows, create audiences, or modify your Google Cloud or Google Analytics resources. Its Google access token is kept server-side for the short portal session and is not used by the installed application.
Information used to install and update Sibyl
The portal records the signed-in email address, selected deployment project, a one-time install token, and installation status — including, when an install does not complete, the setup phase it stopped at (never the error message). A self-deployed instance sends that token, its project ID, and its current Sibyl version to the release service to validate the install and check for product updates. These requests do not include GA4 events, BigQuery rows, model outputs, audiences, or reports.
Your contact details
When you sign in with Google or request access to Sibyl, Making Science collects your name and email address in order to manage your access to the Sibyl deployment portal, facilitate the installation process, and follow up on your request for access to or evaluation of Sibyl.
Your contact details are used to send marketing communications only where you have separately opted in to receive them. Marketing consent is optional and is not required in order to sign in with Google or to proceed with the Sibyl deployment; if you leave the box unticked, that refusal is recorded against your details and you are excluded from marketing contact. Making Science does not sell your contact details, and this use does not involve your GA4 data, your Google Cloud data, or information processed by the installed application within your project.
You may withdraw your consent to receive marketing communications at any time by emailing sibyl@group.makingscience.com or using the unsubscribe link included in any marketing email. Withdrawal does not affect the lawfulness of processing carried out before it, and it does not affect your install.
Data in your cloud
The installed application runs as a dedicated service account in the Google Cloud project you choose. It reads the selected GA4 BigQuery export, including when that export is in another project, and writes models, scores, pipeline state, and reports to your deployment project. It uses GA4 Editor access to manage the measurement and audience resources you explicitly deploy, and it delivers score bands back to your GA4 property through the Measurement Protocol using your property's own credentials. It can connect additional GA4 properties only when you grant its service account access to them. Because everything runs in your project, the BigQuery and Cloud Run usage it generates is billed to that project like any other workload you run there. Your GA4 event data and model outputs are not sent to the Sibyl release service.
Two advisory features can use Google Vertex AI (Gemini 2.5 Flash) in your own project, where the Vertex AI API is enabled there and the service account is allowed to use it: one maps the goal you type into an objective, the other explains a trained model's results in plain language. They send only that typed goal and aggregate model statistics — never event rows or user identifiers — and Sibyl falls back to a built-in rule whenever Vertex AI is unavailable. If you connect an AI agent to your instance's agent endpoint, what that agent's provider receives is governed by your agreement with that provider.
The customer is responsible for determining the purposes and legal basis for the processing of its GA4 end-user data, and for providing any privacy information or obtaining any consent required from its own users under applicable law.
Browser storage and product analytics
Sibyl uses secure cookies for the hosted sign-in session and the self-deployed access gate. The installed app stores selected setup details in your browser so you can resume the workflow.
With your consent, the hosted portal and self-deployed app load Google Analytics to record page views and a small, fixed set of product-usage events, such as beginning a deploy or opening a pipeline. Events identify the product surface and use a pseudonymous installation identifier; they do not include customer property IDs, target event names, GA4 event rows, BigQuery data, model outputs, SQL, audiences, scores, or reports.
Browser analytics is off by default. Google tags do not load and no browser analytics request is sent until you accept the banner. Sibyl uses these cookies only for product analytics, never advertising or ad personalization. You can accept, reject, or withdraw your choice at any time; withdrawal removes Sibyl's Google Analytics cookies from this site and stops future browser events.
Review or change your analytics-cookie choice at any time:
Operational telemetry from an installed instance
Separately from browser analytics, a self-deployed instance sends a limited set of operational lifecycle events to the Sibyl release service so we can measure installation success, reliability, activation, version adoption, and product health. These server events use pseudonymous installation and model identifiers, contain none of the customer data listed above, and are retained for up to 400 days. This operational telemetry does not use browser cookies and is not changed by the browser analytics choice. Because it comes from the deployed application rather than a browser, the person who administers the instance controls it: it can be switched off in the instance's Settings screen at any time, or disabled from the moment of install with SIBYL_TELEMETRY=off. With it off, the instance still checks its licence and available updates, and nothing about those checks is recorded.
Failure alerts
An instance can also email its administrator when its unattended pipeline has stopped working. This is off unless someone enters an address under Settings → Failure alerts, and it is a separate choice from the operational telemetry above. Because the instance runs inside your own Google Cloud and has no mail transport of its own, the message is relayed through Making Science in order to be delivered. What crosses is the address that was entered, the name of the affected model, and the error Google returned trimmed to a short summary — never your GA4 event data or model outputs. Making Science handles that address solely to deliver the alerts your administrator asked for, never for marketing, and clearing it stops them immediately.
The relay keeps a delivery record in its service logs for 30 days, in which the address appears only as a one-way hash and its domain. Because each alert is sent from a Making Science mailbox on Google Workspace, a copy of the sent message also remains in that mailbox.
Legal bases for processing
The legal basis applicable to each processing activity depends on its specific purpose, as set out below.
| Purpose | Legal basis |
|---|---|
| Managing access to the Sibyl deployment portal, Google sign-in, verifying the permissions required for deployment, and facilitating the installation and use of Sibyl. | Making Science's legitimate interest in providing, managing, and securing access to Sibyl and facilitating its use by customers and their authorised representatives (Article 6(1)(f) GDPR). |
| Managing installation records, licence validation, product updates, technical support, and the security and proper operation of Sibyl. | Making Science's legitimate interest in operating, maintaining, securing, and supporting Sibyl (Article 6(1)(f) GDPR). |
| Sending sales and marketing communications about Making Science products and services. | Your consent (Article 6(1)(a) GDPR). Consent is optional and may be withdrawn at any time. |
| Using Google Analytics for browser-based product analytics. | Your consent (Article 6(1)(a) GDPR). Google Analytics stays disabled until consent is given, and consent may be withdrawn at any time. |
| Processing limited operational telemetry to measure installation success, reliability, activation, version adoption, and product health. | Making Science's legitimate interest in monitoring, securing, and improving the reliability and performance of Sibyl (Article 6(1)(f) GDPR). The instance's administrator can switch it off at any time. |
| Sending optional failure alerts to the administrator of a Sibyl instance. | Making Science's legitimate interest in providing the operational functionality requested by the customer or its authorised administrator and supporting the proper functioning of Sibyl (Article 6(1)(f) GDPR). |
| Responding to data protection requests and complying with applicable legal and regulatory obligations. | Compliance with a legal obligation (Article 6(1)(c) GDPR). |
Sharing, sale, and advertising
Sibyl does not sell Google user data. Google user data is not shared with third parties for advertising. Aside from the contact details described above, access to information received from Google APIs is limited to operating, securing, supporting, and improving the product as described here — your Google Analytics and Google Cloud data are never used for sales or marketing. Sibyl's use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
How we protect this data
All data moves over encrypted connections (HTTPS/TLS). The portal keeps your Google access token server-side for a short sign-in session only; it is never stored long-term, never written to the installed application, and never shared. The installed application authenticates as a dedicated service account with permissions managed through Google Cloud IAM in your own project, where Google Cloud encrypts data at rest by default; your GA4 event-level data and BigQuery model artifacts are not sent to Making Science, and derived score bands may be sent back to your GA4 property as described above. Access to portal installation records and contact details is restricted to Making Science staff who operate and support Sibyl.
Personal data is retained only for as long as necessary for the purposes for which it was collected and, thereafter, where necessary to comply with legal obligations or to establish, exercise, or defend legal claims.
Operational telemetry uses pseudonymous identifiers and is retained for up to 400 days. Your contact details and consent record are retained for up to 24 months, and install tokens for up to 12 months, after which they are deleted automatically; you can ask us to delete them sooner at any time. Data is deleted or, where applicable, blocked when it is no longer required for the relevant purpose.
Recipients and international data transfers
Making Science may engage third-party service providers to support the hosting, operation, security, analytics, and communication functionalities of Sibyl. Such providers may process personal data only to the extent necessary to provide the relevant services and subject to appropriate contractual and confidentiality obligations.
In practice there is one such provider. The hosted portal, the release service, and the records described above are hosted on Google Cloud in the United States; browser analytics is processed by Google Analytics; and alert mail and support correspondence pass through Google Workspace. Making Science staff who operate and support Sibyl, including personnel located in the United States, may access this data.
Where personal data is transferred to recipients located outside the European Economic Area, Making Science ensures that an appropriate transfer mechanism is in place in accordance with Chapter V of the GDPR — including, where applicable, an adequacy decision adopted by the European Commission or the European Commission's Standard Contractual Clauses, together with any supplementary safeguards required in the circumstances. Google LLC participates in the EU-U.S. Data Privacy Framework, and Google Cloud's data processing terms incorporate the Standard Contractual Clauses.
Your data protection rights
Subject to applicable data protection law, you may request access to, rectification or erasure of your personal data, restriction of processing, object to processing — including processing based on legitimate interests — and, where applicable, request data portability. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
You may exercise these rights by contacting sibyl@group.makingscience.com or Making Science's Data Protection Officer at dataprivacy@makingscience.com. You also have the right to lodge a complaint with the competent data protection supervisory authority — in Spain, the Agencia Española de Protección de Datos.
Control and deletion
You can revoke Sibyl's Google authorization from your Google Account permissions at any time. You can remove the Sibyl runtime service account from GA4 or Google Cloud IAM, use the instance's self-destruct, or delete the deployed Cloud Run services and BigQuery artifacts in your project yourself. To request deletion of portal installation records or your contact details, or to opt out of sales and marketing contact, reach us at the address below.
Contact
Questions or privacy requests can be sent to sibyl@group.makingscience.com. Data protection matters can also be raised with Making Science's Data Protection Officer at dataprivacy@makingscience.com.