Privacy Policy
Last updated: 2026-07-20
This Privacy Policy describes how AEO Audit ("we", "us") collects, uses and shares information when you use our service to audit how Large Language Models reference your brand.
1. Data we collect
- Account email — submitted when you request a free audit, register for a paid account, or subscribe to weekly tracking. Required to deliver the requested report.
- Brand domains and prompts — the domain you submit and any prompts generated for the audit run. Stored to render the report and to compute week-over-week deltas for tracking subscriptions.
- Source IP address — collected for free-audit and authentication rate limiting (1 free audit per IP per day, login/register throttling). Stored only in transient counters and masked in logs.
- Billing information — payments are handled by Paddle, our Merchant of Record; we never see or store full card numbers. We retain only the Paddle customer and subscription/transaction identifiers Paddle returns to us.
- LLM responses — raw and analysed responses returned by Anthropic, OpenAI, Perplexity, and — where configured — Google (Gemini), DeepSeek, Zhipu AI (GLM) and Moonshot AI (Kimi) for your audits. Stored to render reports and PDF exports.
- Brand name — used, for authenticated users viewing their brand dashboard, to query Google Trends for public search-interest data. No account or audit data is sent alongside it.
2. How we use the data
- To run audits and deliver visibility / sentiment / gap reports to you.
- To send weekly tracking reports by email if you have an active subscription.
- To enforce abuse limits on the free tier and authentication endpoints.
- To bill recurring or one-time charges via Paddle, our Merchant of Record.
3. Third-party processors
- Anthropic, OpenAI, Perplexity, Google (Gemini), DeepSeek, Zhipu AI (GLM), Moonshot AI (Kimi) — receive the audit prompts to generate model responses (Gemini, DeepSeek, GLM and Kimi only when configured on your plan). For deep and weekly audits, Anthropic also receives your website's sitemap URL paths and page content to detect service and city names (Site Structure Audit) and to score content quality (EPOS Content Audit). They do not receive your email.
- Google Trends — receives your brand name as a search query to return public search-interest data shown on your dashboard. No other account data is sent.
- Paddle — our Merchant of Record. Paddle is the reseller of record for all purchases: it processes payments, stores card data on our behalf, and handles sales tax / VAT. We never receive full card numbers.
- Resend — delivers transactional emails (free-audit results, deep audit ready, weekly reports).
- Supabase — managed Postgres and authentication. All user data is protected by Row Level Security.
- Cloudflare Turnstile — anti-abuse challenge on the free-audit form.
- Dokploy (self-hosted) — hosting and runtime for the application.
4. Cookies
We use a single session cookie issued by Supabase Auth to keep you signed in. We do not use marketing or third-party analytics cookies.
5. Data retention
- Free audits and their reports are retained indefinitely under your access link.
- Authenticated audits remain available while your account exists.
- Rate-limit counters are pruned on a rolling 15-minute / 24-hour window basis.
6. Your rights
You may request export or deletion of your data, or correction of inaccurate data, by contacting us at the address below. We will respond within 30 days.
7. Security
Data is transmitted over TLS, stored in encrypted Supabase Postgres, and segregated per user via Row Level Security policies. Service-role access is restricted to Paddle webhook handlers and Vercel Cron jobs only.
8. Changes to this policy
We may update this Privacy Policy. The "Last updated" date at the top will reflect the revision date. Material changes will be communicated to active subscribers by email.
9. Contact
Questions or data requests: ruslan.griban@gmail.com.
10. Personal data processing under Federal Law 152-FZ (Russian Federation)
For users in the Russian Federation, we act as the data operator (оператор персональных данных) for personal data processed through AEO Audit and process it in accordance with Federal Law No. 152-FZ "On Personal Data".
- Legal basis — processing relies on the data subject's consent, given when you submit an audit request, register an account, or subscribe to tracking. Consent is limited to the purposes described in Section 2.
- Categories processed — account email, source IP address, billing identifiers, and brand/audit content you submit — see Section 1 for the full list.
- Cross-border transfer — audit prompts and LLM responses are sent to the third-party AI providers listed in Section 3, some of which are located outside the Russian Federation. This transfer is necessary to provide the service you requested; by submitting an audit you consent to it.
- Data subject rights — you may request access, correction, blocking, or destruction of your personal data at any time by contacting us at the address in Section 9. We respond within the timeframes established by Federal Law 152-FZ.
- Storage location — account and audit data is stored in our Supabase Postgres instance; see Section 3 for the hosting provider.