SibylMaking Science
Back to Sibyl

Privacy policy

Effective July 14, 2026 · Updated July 22, 2026

Sibyl helps organizations deploy predictive GA4 audiences in their own Google Cloud environment. This policy explains how the hosted deployment portal and a self-deployed Sibyl application handle information.

Google data used by the deployment portal

When you sign in, the portal requests your basic Google identity, the IDs and names of Google Cloud projects visible to you, and read-only access to your Google Analytics account and property metadata. It uses this information only to let you select a Cloud project and GA4 property, confirm that you can deploy into the selected project, identify that property's BigQuery export project, and generate the correct installation command. The portal cannot read data from other Google Cloud services.

The hosted portal does not train models, read GA4 event rows, create audiences, or modify your Google Cloud or Google Analytics resources. Its Google access token is kept server-side for the short portal session and is not used by the installed application.

Information used to install and update Sibyl

The portal records the signed-in email address, selected deployment project, a one-time install token, and installation status. A self-deployed instance sends that token, its project ID, and its current Sibyl version to the release service to validate the install and check for product updates. These requests do not include GA4 events, BigQuery rows, model outputs, audiences, or reports.

Data in your cloud

The installed application runs as a dedicated service account in the Google Cloud project you choose. It reads the selected GA4 BigQuery export, including when that export is in another project, and writes models, scores, pipeline state, and reports to your deployment project. It uses GA4 Editor access to manage the measurement and audience resources you explicitly deploy. Your GA4 event data and model outputs are not sent to the Sibyl release service.

Browser storage and product analytics

Sibyl uses secure cookies for the hosted sign-in session and the self-deployed access gate. The installed app stores selected setup details in your browser so you can resume the workflow.

With your consent, the hosted portal and self-deployed app load Google Analytics and Google Tag Manager to record page views and a small, fixed set of product-usage events, such as beginning a deploy or opening a pipeline. Events identify the product surface and use a pseudonymous installation identifier; they do not include customer property IDs, target event names, GA4 event rows, BigQuery data, model outputs, SQL, audiences, scores, or reports.

Browser analytics is off by default. Google tags do not load and no browser analytics request is sent until you accept the banner. Sibyl uses these cookies only for product analytics, never advertising or ad personalization. You can accept, reject, or withdraw your choice at any time; withdrawal removes Sibyl's Google Analytics cookies from this site and stops future browser events.

Separately, a self-deployed instance sends a limited set of operational lifecycle events to the Sibyl release service so we can measure installation success, reliability, activation, version adoption, and product health. These server events use pseudonymous installation and model identifiers, contain none of the customer data listed above, and are retained for up to 400 days. This operational telemetry does not use browser cookies and is not changed by the browser analytics choice.

Sharing, sale, and advertising

Sibyl does not sell Google user data. Google user data is not shared with third parties for advertising. Access is limited to operating, securing, supporting, and improving the product as described here. Sibyl's use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Control and deletion

You can revoke Sibyl's Google authorization from your Google Account permissions at any time. You can remove the Sibyl runtime service account from GA4 or Google Cloud IAM, or delete the deployed Cloud Run services and BigQuery artifacts in your project. To request deletion of portal installation records, contact us at the address below.

Review or change your analytics-cookie choice at any time:

Contact

Questions or privacy requests can be sent to info@makingscience.com.