SECURITY / DATA
Your events stay in your project. We keep the totals.
Measurement substrate is the client BigQuery export. Pulsar stores aggregated model outputs, tenant context, and the audit log. A DPA is part of the pilot SOW.
IAM we ask for
| Role | Scope | Why |
|---|---|---|
| BigQuery Data Viewer | GA4 export dataset only | Read events and sessions. Nothing else in the project. |
| BigQuery Job User | The same project | Run the journey SQL. We cap bytes scanned per run. |
| Analytics Viewer | Optional, GA4 property | Admin / Data API QA: key events, ads links, schema drift. |
Prefer a service account in your project. We will not take Owner, never store key JSON in git, and isolate credentials per tenant in a secrets manager.
What leaves your GCP
- Channel shares, credited conversions, intervals.
- Run metadata: lookback, conversion definition, bytes billed.
- Anomaly flags and the approved PDF.
What does not
- user_pseudo_id paths, hit-level events, PII.
- Your Ads account. We do not bid.
- GTM container writes. Tag Health is read-only.
Subprocessors
- Amazon Web ServicesJob runners, secrets, object storage
- Google CloudYour BigQuery — in your project
- Neon / RDS PostgresTenants, runs, aggregated results
- ResendReport delivery
- Anthropic / GoogleDraft commentary only. Cannot change shares.