Skip to content

Privacy

Last updated 20 September 2026.

AEOptimiz reads the search data you already own and tells you what to fix. To do that it has to hold some of your data. This page says exactly which, why, where it goes and how to get rid of it.

Who is responsible

AEOptimiz is the business behind this site, and is responsible for the data described here. For anything on this page, write to privacy@aeoptimiz.com, or use the contact page.

For your account and your billing we are the controller. For the Search Console, Analytics and website data you connect, we are a processor acting on your instructions: it is your data, we hold it so the product can work, and we delete it when you say so.

What we hold

Your account. The email address you sign in with, your name if you give one, which workspace you belong to, and the times you signed in. If you sign in with Google we receive your email address and name from Google, never your password.

The search data you connect. When you connect Search Console we copy your performance history (the queries and pages you appear for, with clicks, impressions and positions) and what Google says about each of your URLs when we ask it. If you connect Google Analytics we also copy organic sessions and revenue by landing page. This is mirrored into our database because the engine ranks fixes with SQL over months of it, and asking Google live on every question would be slower and would hit limits.

Your website's public pages. We fetch them the way a search engine does, and keep their text, titles, headings and links.

What you write here. Your questions, the answers, the documents drafted or reworked, and the notes attached to them.

Publishing credentials. If you connect WordPress, Shopify or your own endpoint, we store what is needed to publish: an application password, an access token or a client id and secret, or a signing secret. Each is encrypted with a key that is bound to its own row, and is decrypted only at the moment of publishing. Disconnecting deletes it.

Billing. Stripe holds your card details; we never see them. We store your Stripe customer and subscription identifiers, your plan, your credit balance and a ledger of what each message and each purchase cost.

The free tools. The address you enter, and a one-way hash of your IP address so the same visitor cannot run thousands of checks a day. We do not store the IP address itself. The free coverage report also stores the email address you give it, so the report can be sent to you.

Records. An audit log of significant actions (who connected or disconnected something, who deleted a conversation) and ordinary server logs.

Why, and on what basis

  • To provide the product you asked for, which is the contract between us: everything above except the items named below.
  • Because the service has to work and not be abused, which is our legitimate interest: rate limits, the IP hash behind the free tools, the audit log, and security logging.
  • Because the law requires it: invoices and tax records.
  • With your consent, where we ask for it: the weekly report email, which you can stop from Settings or from any report.

We do not sell your data, we do not share it with advertisers, and we do not use it to train anybody's model.

The AI providers

Your questions and the data needed to answer them are sent to Anthropic, which writes the answers and the articles. Once a month, for the AI-answer check, we ask ChatGPT, Perplexity and Gemini a set of buyer questions about your market to see whether they cite your site; those questions contain your site's name and topics, not your account data or your search history.

All of these are used through their business APIs, whose terms say the provider does not train its models on what is sent. They are listed below with everyone else who touches your data.

Who else touches it

WhoWhat forWhere
AnthropicThe assistant's answers, article writing, the monthly AI-answer checkUnited States
OpenAI, Perplexity, GoogleThe monthly AI-answer check, when configuredUnited States
DataForSEOKeyword and search-result data, when a question needs itUnited States, European Union
StripePayments and invoicesUnited States, Ireland
ResendSign-in links, the weekly report, the free reportUnited States
VercelHosting the site and the appGlobal edge, United States
GoogleSearch Console and Analytics, which is your own data returned to youGlobal

The site and its database run in Frankfurt, Germany. Several of the providers above are in the United States, so data moves between the two: those transfers rely on each provider's standard contractual clauses, or on its certification under the EU-US Data Privacy Framework.

How long we keep it

Your conversations, documents and connected data stay until you delete them or close the workspace. Close the workspace and everything belonging to it is deleted within 30 days, except records we must keep for tax and accounting, and the ledger rows that prove what was charged.

An answer you replaced by regenerating or by editing your question is kept but hidden from the conversation, because it was paid for and its cost has to stay on record. It goes with the conversation when you delete that.

Rate-limit hashes are kept for a rolling window of days, long enough to count a day's use. Server logs are kept for weeks, not years.

Your rights

Whoever and wherever you are, you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask for it in a portable form, object to what we do with it, and stop the emails. Write to privacy@aeoptimiz.com and we answer within 30 days. We do not charge for this and we do not treat you differently for asking.

Some of those rights are written into law where you live, and those laws name the details:

  • Europe and the United Kingdom. The GDPR and the UK GDPR give you the rights above, and the right to complain to your national data protection authority.
  • California. You may ask what categories of personal information we collect and why, ask for it to be deleted or corrected, and not be discriminated against for asking. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of.
  • Anywhere else. The same requests are honoured, in the same 30 days.

Much of this you can do yourself: delete a conversation or a document in the app, disconnect a CMS or an analytics property in Settings, and unsubscribe from the link in any report.

Cookies

Only what sign-in needs, and nothing for advertising or tracking. The cookie policy lists every one of them.

Children

AEOptimiz is a business tool and is not for anyone under 16.

Changes

If this page changes in a way that matters, we will say so in the product before it takes effect. The date at the top is the last change.