← Attribura

Privacy Policy

Last updated: June 22, 2026

Attribura ("Attribura", "we", "our", "the service") is operated by Martin Condet, registered as an auto-entrepreneur in France. Attribura is a content attribution tool: it connects the organic content you publish to the installs and revenue it drives. This policy explains what data we process, why, and the rights you have over it.

1. Data controller

The data controller is Martin Condet, auto-entrepreneur (micro-entreprise) registered in France — SIREN 951 671 668, SIRET 951 671 668 00014. For any privacy request, contact privacy@uncondetional.com.

2. Who this policy covers

This policy applies to two groups:

  • Account holders — the operators (founders, creators, businesses) who create an Attribura account and connect their own platforms.
  • People who interact with an account holder's content — for example, someone who comments on a connected post, or whose purchase is reported to us. We process this data on behalf of the account holder to measure their content.

3. Data we collect

Account & sign-in. We use Sign in with Google. We receive your email address, name, profile picture, and a Google account identifier, used solely to create and authenticate your account. We store a session as an HttpOnly cookie (its token is kept hashed on our server). We never receive your Google password.

Connected platform data.Only when you explicitly connect an integration, and only through each platform's official API, we import:

  • YouTube (read-only): your own videos and their metadata, public per-video statistics (views, likes, comment counts), and public top-level comments (commenter display name, comment text).
  • Instagram (Meta): your own media and their public comments. For the optional comment-to-DM feature, when a commenter uses a keyword you configure, we send a single private reply on your behalf and store a record that the reply was sent (comment id, post id, keyword).
  • App Store Connect: aggregated daily analytics by campaign token (impressions, downloads, proceeds). This contains no individual end-user identities.
  • Revenue events (Superwall, Stripe, Shopify): purchase and subscription events you forward to us, which may include a transaction or order id, product, amount, currency, country, and — where your own systems include it — an email or app-user id. Used to attribute revenue to your content.

Integration credentials. The OAuth tokens and API keys you provide so we can run these syncs on your behalf.

Attribution & technical data. When someone taps an Attribura tracking link, we record the event (timestamp, coarse country derived from IP, referrer, device type) to attribute it. We do not use third-party advertising or analytics SDKs.

4. How we use your data

We use the data above solely to provide the service: authenticate you, run scheduled imports, attribute installs and revenue to the content that drove them, power your dashboard, and send the auto-replies you configure. We do not sell your data, and we do not use it for advertising.

5. Platform data (Meta & Google)

Our use of information received from the Meta / Instagram APIs and from Google / YouTube APIs adheres to the Meta Platform Terms and Developer Policies, and to the Google API Services User Data Policy, including its Limited Use requirements. Platform data is used only to provide the user-facing attribution and engagement features described here. It is not sold, not transferred to third parties except as needed to run the service, and not used for advertising or to train generalized AI models.

6. Sharing and sub-processors

We do not sell your data. We share it only with the providers that run the service: Google (sign-in), Meta, Apple, Superwall, Stripe, and Shopify (only the data you route through each), and Hetzner (hosting). Our servers and database are hosted in the European Union (Hetzner, Falkenstein, Germany).

7. Legal basis (GDPR / RGPD)

We process data on the basis of: performance of a contract (delivering the service you signed up for), our legitimate interest in providing attribution and analytics, and your consent where required (for example, when you authorize a platform connection).

8. Data retention

Account and imported data are retained while your account is active. When you disconnect an integration, we stop syncing it and revoke the stored token. When you delete your account, we delete your account data, connected-integration credentials, imported posts/comments/statistics, and conversion and revenue records. Aggregated, non-identifying analytics may be retained.

9. Your rights (GDPR / RGPD)

If you are in the European Economic Area, you have the right to access, rectify, erase, port, restrict, and object to the processing of your data. To exercise any of these, contact privacy@uncondetional.com — we respond within 30 days. You may also lodge a complaint with the French data protection authority, the CNIL. For deletion specifically, see our Data Deletion page.

10. Security

All traffic between your browser, our service, and connected platforms uses HTTPS/TLS. Session and integration credentials are held on access-controlled servers in the EU and are never exposed back to the browser. No method of transmission or storage is perfectly secure, but we work to protect your data using reasonable, industry-standard measures.

11. Children

Attribura is a business tool not directed at children under 16. We do not knowingly collect data from children.

12. Changes & contact

We may update this policy; the "Last updated" date reflects the latest revision. For any question or request, contact privacy@uncondetional.com.