Skip to content
esc close · switch
Legal · the data side

Privacy policy.

What we collect, why we collect it, where it lives, and the rights you keep over it. Written so a person can read it before clicking accept.

Effective Jan 12026
Last updated Apr 222026
Sections 11Numbered clauses
Reading time ~9 min2,400 words
Canonical version A canonical, legally-binding copy is maintained under our compliance program at iubenda.com. The text below mirrors that version in plain English.

Lyra ("we," "us," or "our") operates the Lyra platform at lyrappc.com, a Google Ads optimization and analytics service.

This Privacy Policy explains how we collect, use, store, and protect your personal information. By using Lyra, you agree to the collection and use of information as described here. If you do not agree, please do not use our services.

The short version · 01

We do not sell your personal information. We do not sell, rent, or trade your personal data or your Google Ads data to any third party — ever. We do not use your data to serve ads to you or anyone else.

§ 01

Information we collect.

Account information

When you create a Lyra account, we collect your name, email address, and organization name. If you sign up via Google OAuth, we receive your Google profile information (name, email, and profile picture) as authorized by your Google account settings.

Google Ads data

When you connect your Google Ads account to Lyra, we access and store Google Ads performance data, including but not limited to:

  • Campaign metrics, keyword data, and search term reports
  • Ad copy and asset performance data
  • Quality Score data and change history
  • Budget information and conversion data

This data is accessed through the Google Ads API under your authorization and is used solely to provide you with analytics and optimization recommendations.

Usage data

We automatically collect information about how you interact with Lyra, including pages visited, features used, timestamps, browser type, device information, IP address, and referring URLs. This data is collected through server logs and analytics tools.

Cookies and similar technologies

We use cookies and similar tracking technologies to maintain your session, remember your preferences, and understand how you use our platform. See § 06 for details.

Communication data

When you contact our support team or provide feedback, we collect the content of your messages along with your contact information.

§ 02

How we use your information.

We use the information we collect for the following purposes:

Providing services
Analyzing your Google Ads data, generating optimization recommendations, producing reports, and operating the Lyra platform.
AI-powered analysis
Processing your Google Ads data through our AI systems to generate insights, identify patterns, and provide optimization suggestions. AI-generated insights are based solely on your account data and aggregated, anonymized patterns.
Account management
Authenticating your identity, managing your subscription, processing payments, and providing customer support.
Platform improvement
Understanding usage patterns to improve features, fix bugs, and develop new functionality.
Communication
Sending service-related notifications, security alerts, and (with your consent) product updates and tips.
Security & compliance
Detecting and preventing fraud, abuse, and security incidents.

We do not use your Google Ads data for advertising purposes. We do not use your data to serve ads to you or anyone else.

§ 03

How we share your information.

Operator note · 02

We share information only in the limited circumstances below. Service providers we use are contractually bound to protect your data and access only what's needed to do their job.

Service providers

We use third-party services for:

  • Hosting — Railway
  • Payment processing — Stripe
  • AI processing — Anthropic, OpenAI
  • Email communication — transactional providers

These providers access only the data necessary to perform their services and are contractually bound to protect it.

Google API compliance

Our use of data obtained through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. We access Google Ads data only as necessary to provide our services to you.

Where you use our account-access provisioning flow, we access your Google Analytics, Google Tag Manager, and Google Merchant Center accounts solely to list them for your selection and to grant the agency the access you authorize. We do not read, store, or otherwise process the contents of those accounts.

Legal requirements

We may disclose information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you before your information becomes subject to a different privacy policy.

§ 04

Data retention.

We retain your information for as long as your account is active or as needed to provide you with our services. Specifically:

Account data
Retained until you delete your account or request deletion.
Google Ads data
Retained for the duration of your active subscription to provide historical analysis and trend reporting. Upon account deletion, purged within 30 days.
Usage data
Retained for up to 24 months for analytics and platform improvement purposes.
Payment records
Retained as required by applicable tax and financial regulations.

When you cancel your subscription or delete your account, we delete or anonymize your data within 30 days, except where retention is required by law.

§ 05

Data security.

We implement industry-standard security measures to protect your information:

Encryption in transit
All data between your browser and our servers is encrypted using TLS 1.2 or higher.
Encryption at rest
Sensitive data stored in our databases is encrypted.
Access controls
Access to production systems and customer data is restricted to authorized personnel on a need-to-know basis.
Authentication
OAuth 2.0 for Google account authentication, plus secure session management.
Infrastructure
Hosted on Railway with PostgreSQL databases that maintain SOC 2 compliance standards.
Monitoring
We monitor our systems for unauthorized access and security anomalies.

No system is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. If we become aware of a security breach affecting your data, we will notify you promptly as required by applicable law.

§ 06

Cookies.

We use the following types of cookies:

  • Essential cookies — Required for the platform to function, including session management and authentication. These cannot be disabled.
  • Functional cookies — Remember your preferences and settings to improve your experience.
  • Analytics cookies — Help us understand how users interact with our platform so we can improve it.

We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings. Disabling essential cookies will prevent you from using the platform.

§ 07

Your rights (GDPR and other regulations).

If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, you have the following rights:

Access
Request a copy of the personal data we hold about you.
Rectification
Request correction of inaccurate or incomplete data.
Erasure
Request deletion of your personal data (subject to legal retention requirements).
Restriction
Request that we restrict processing of your data in certain circumstances.
Portability
Request your data in a structured, machine-readable format.
Objection
Object to processing of your data for specific purposes.
Withdraw consent
Where processing is based on consent, withdraw that consent at any time.
How to exercise · 30-day SLA

To exercise any of these rights, email support@lyrappc.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.

§ 08

International data transfers.

Your data may be processed in countries outside your country of residence, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place, including standard contractual clauses approved by the European Commission where applicable.

§ 09

Children's privacy.

Lyra is a business tool not directed at children. We do not knowingly collect information from anyone under the age of 16. If we become aware that we have collected personal data from a child, we will delete it promptly.

§ 10

Changes to this policy.

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice on our platform. Your continued use of Lyra after changes take effect constitutes your acceptance of the updated policy.

§ 11

Contact us.

If you have questions about this Privacy Policy or our data practices, contact us at:

Platform
lyrappc.com
Canonical, legally-binding version. A signed, always-current copy of this Privacy Policy is maintained under our compliance program at iubenda.com/privacy-policy/39121924. In the event of any discrepancy, the canonical version controls.