Trust Center

Your social data, handled with care

Measure Studio reads the analytics you connect and nothing more. Access is read-only by default, encrypted throughout, and scoped to exactly what each person is allowed to see — including everywhere our AI touches your data.

Read-only OAuth · Encrypted in transit & at rest · SSO, MFA & role-based access

Security built into every account

  • Secure OAuth connections

    Accounts connect through each platform's OAuth. We never see or store your social login credentials.

  • Encrypted end to end

    Your data is encrypted in transit and at rest, on every hop and at every layer.

  • SSO & MFA

    Enterprise single sign-on and multi-factor authentication, enforceable across your entire team.

  • Granular permissions

    Role-based controls for account visibility, exporting, managing groups, editing teams, viewing revenue, and more.

  • Session visibility

    Session logs for every team member, plus email alerts when a new device or location signs in.

  • Trusted infrastructure

    Hosted in secure facilities, with all of your data backed up daily.

  • Independently tested

    Annual penetration testing by a third-party security firm.

  • GDPR-ready

    Built to support your GDPR obligations, backed by our data processing agreement.

Read-only by design

Measure Studio is built to observe, not to act on your behalf. We pull the analytics you connect and nothing more — so giving us access never means giving up control of your accounts.

  • Read-only wherever possible. We request the minimum scopes each platform allows — almost always read-only.
  • We never touch your content. Measure Studio can't publish, edit, or delete posts on your accounts.
  • No access to your audience. We can't see DMs or interact with the people who follow you.
  • Your logins stay yours. Connections run through OAuth, so we never see or store account passwords.

AI that works within your permissions

Our AI assistant reads your analytics through a set of permission-scoped tools — the same boundaries as your normal session. Here's how that data is handled.

  • Your permissions, exactly

    The assistant can only reach data you're already allowed to see — no more, no less. Every query runs through the same authorization layer as the rest of the app.

  • Never used for training

    Your conversations and analytics are not used to train models. Providers are explicitly configured to deny data collection.

  • You own your history

    Conversations are private to each user and can be permanently deleted at any time.

  • Your data stays on our servers

    When the assistant fetches analytics, that runs server-side within your permission scope. Model providers never touch your database or internal systems.

  • Read-focused, never destructive

    The vast majority of actions are read-only. The few writes — like building a report or creating a group — run only on your explicit request, and nothing can be deleted.

  • Isolated by workspace

    Access is scoped to your workspace. Cross-workspace and cross-organization access is not possible.

  • Encrypted on every hop

    Traffic is encrypted with TLS from your browser to our servers, and from our servers to any model provider.

Same permissions as the app — the assistant inherits the exact boundaries of your normal Measure Studio session.

The same principles govern Content Lens, our AI content classification: opt-in per account, public post content only, never used to train models, structured output only. How Content Lens handles data

Your data in your own AI tools

Our MCP server lets you connect your workspace to any compatible AI client. Measure Studio is the data source, not the model — nothing leaves our infrastructure to an AI provider unless you connect a client and it makes a request.

You choose the client and the model tier that handle the data it returns, so it meets your own data-residency and training requirements.

See what the Measure MCP can do
  • Opt-in per company

    Disabled by default. An admin enables it, then each user connects through a standard OAuth flow.

  • Modern authentication

    OAuth 2.1 with PKCE. Every token is bound server-side to a single user and a single workspace.

  • Scoped to you

    Clients see only what you'd see logged in — the same permissions and the same workspace isolation.

  • Reads and light writes only

    Tools cover reads and lightweight writes like tagging or building slides. No destructive, account-level actions are exposed.

  • Stateless by design

    No conversation transcripts are stored — only standard access-log metadata, under the same retention policy as the rest of the app.

  • Revoke anytime

    Disconnect a client at any moment to immediately invalidate every token it was issued.

Governance & compliance

  • GDPR & DPA. Built to support your GDPR obligations, with a data processing agreement available.
  • Data residency. Traffic terminates in the same infrastructure region as the rest of the platform.
  • Right to deletion. Removing a user or workspace cascades to the associated access, tokens, and data.
  • Minimal retention. Analytics fetched for AI features are used in real time and not persisted afterward.
  • Sub-processor transparency. Tools you run in your own AI client add no new sub-processor on our side — you configure that.
  • Monitored & isolated. Surfaces are covered by operational monitoring and isolated from core data sync.

Have a security question, need our DPA, or want to report a vulnerability?

Get in touch with our team

Analytics you can trust, on data you control.

Free trial · No credit card · Connect your accounts in minutes.

Control the cookies and tracking technologies used on this website. Opting out of advertising cookies is how you opt out of the "sale" or "sharing" of your personal information under U.S. state privacy laws. See our Privacy Policy for details.