Privacy Policy
Last updated:
Summary
FixAEO is an Answer Engine Optimization (AEO) and Generative Engine Optimization (GEO) platform. To run your account, scans, subscription, and optional integrations we collect the personal data described below. We collect only what we need, we do not sell personal data, and we do not run third-party advertising trackers. This policy covers both the public site and the authenticated app at fixaeo.com and api.fixaeo.com.
Who we are (data controller)
FixAEO is the data controller for the personal data described here. The operating legal entity and registered address are listed in our Imprint. For any privacy question or to exercise your rights, contact hello@fixaeo.com.
What we collect
- Account data — your email address (used for passwordless magic-link sign-in) and, if you sign in with Google, GitHub, or Microsoft, the profile your provider returns (a provider user id, email, name, and, where available, an avatar). You may set a display name.
- Billing data — your subscription status, plan, amount, and the identifiers our payment provider returns. Payments are processed by Lemon Squeezy (our Merchant of Record), which collects your billing name, address, and card details and handles tax/VAT — we never see or store full card numbers. (Some legacy subscriptions were processed via Razorpay.)
- Product data you create — the brands, domains, tracked prompts, competitors, and the scan results, snapshots, and recommendations we generate for you.
- URLs and public website data you submit for scanning — HTML, robots.txt, llms.txt, sitemap.xml. We never request authenticated endpoints on the sites you scan.
- Google Analytics tokens (optional) — if you connect Google Analytics, we store a read-only OAuth token, encrypted at rest, used solely to read your own analytics for AI-traffic attribution. We also store the property you select and the synchronized metrics described below while the integration is connected. Disconnecting deletes the token, connection metadata, and imported GA4 metrics for that brand.
- Google Search Console data (optional) — if you connect Google Search Console, we store a read-only OAuth token, encrypted at rest, plus the verified site you select and its synchronized search-performance metrics. We use this data solely to show your organic-search performance, create prompt suggestions locally, and compare it with your AI visibility. Disconnecting deletes the token, connection metadata, imported metrics, and derived prompt suggestions for that brand.
- Analytics-tag data (optional) — if you install our JavaScript tag on your own website, we receive visit events (a hashed/salted IP, user agent, referrer, path) to classify AI-bot and AI-referred traffic for you. We process this on your behalf as a processor; we hash IPs and do not use them to identify individuals.
- Technical data — your IP address, hashed and salted, used for short-term rate limiting and abuse prevention, plus standard request logs.
- Product and site analytics via PostHog (our processor) and Ahrefs Web Analytics. Page views and a short list of named events like "started a scan". No screen recording, no automatic click capture, no advertising audiences. Analytics runs without storing anything on your device unless you accept the optional analytics cookie — see the Cookie Policy.
Google user data & Limited Use
When you connect Google Analytics, FixAEO accesses your Google Analytics 4 data through the read-only analytics.readonly scope — solely to read the property you select and attribute which AI engines drive sessions, conversions, revenue, landing-page engagement, and country/device totals on your own site. We store an encrypted, read-only OAuth token, the selected property metadata, and the imported daily metrics; we never request write access. You can revoke access at any time in Settings or from your Google Account.
When you connect Google Search Console, FixAEO uses the read-only webmasters.readonly scope to list the verified sites your Google account can access and read search-performance data for the site you choose. This includes clicks, impressions, click-through rate, average position, queries, pages, and countries. FixAEO uses the data to show your organic-search performance, generate relevant prompts locally inside FixAEO, and identify queries where you rank in Google but are not cited by AI engines. We never modify your Search Console sites or data. Search Console queries and metrics are not sent to an AI provider or used to train a generalized AI or machine-learning model. The OAuth token is encrypted at rest, and you can revoke access at any time in Settings or from your Google Account.
FixAEO's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. These commitments cover raw Google data and any data FixAEO aggregates or derives from it. We do not sell Google user data; use it for advertising, credit, insurance, or other unrelated purposes; use it to train generalized AI models; or allow humans to read it except when the user gives affirmative permission for support, when required for security or legal compliance, or where the data has been aggregated and anonymized for internal operations. We transfer Google user data only to infrastructure processors strictly necessary to provide the user-facing integration, to address security or legal duties, or as part of a merger or acquisition after obtaining explicit prior user consent. We do not transfer Google user data to AI providers, advertising platforms, or data brokers.
How we protect sensitive data
We apply technical and organizational safeguards to Google user data and other sensitive personal data throughout its lifecycle:
- Encryption in transit — FixAEO, Google APIs, and our application server communicate over HTTPS using TLS.
- Encryption at rest — Google OAuth tokens are encrypted before storage. Imported raw, aggregated, and derived Google metrics are stored on protected authenticated infrastructure. OAuth client secrets and encryption keys remain server-side and are not exposed to the browser.
- Least-privilege access — we request only the read-only Google scopes described above. Access to production systems and sensitive data is restricted to the services and authorized personnel who need it to operate, secure, or support FixAEO. Authorized personnel are subject to confidentiality obligations.
- User control and deletion — you can disconnect either Google integration in FixAEO Settings or revoke FixAEO from your Google Account at any time. Disconnecting in FixAEO permanently deletes the integration token, selected property/site metadata, imported metrics, and derived prompt suggestions for that brand. Revoking only from your Google Account stops future access; use FixAEO's Disconnect control or delete the FixAEO account to remove data already imported. You can also delete your FixAEO account from Settings. We then remove the associated personal data except records we must keep for legal reasons and encrypted disaster-recovery backups that expire within 30 days.
- Service protection — we use access controls, least-privilege admin gating, rate limits, request monitoring, and CDN/network protections to reduce unauthorized access and abuse. If a personal-data breach occurs, we investigate, contain, and provide legally required notifications.
How we use it and our legal basis
For users in the EEA/UK, we rely on the following legal bases under Article 6(1) GDPR:
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, delivering scans and measurements, and managing your subscription.
- Legitimate interests (Art. 6(1)(f)) — securing the service, preventing abuse (rate-limiting via hashed IPs), and storage-free product/site analytics. You may object at any time.
- Consent (Art. 6(1)(a), and Art. 5(3) ePrivacy) — the optional analytics cookie, which is set only if you accept it. You can withdraw at any time via Cookie settings in the footer, with no effect on anything else.
- Legal obligation (Art. 6(1)(c)) — keeping billing/tax records required by law (handled largely by our Merchant of Record).
- Consent (Art. 6(1)(a)) — where we ask for it (e.g. optional product emails). You can withdraw consent at any time.
AI providers and the scan pipeline
To measure how AI engines recognize a brand, we send the brand name, the prompt text, and the brand's public self-description to AI providers and, for some engines, drive logged-in browser sessions. Providers include Google (Gemini), OpenAI (ChatGPT), Anthropic (Claude), Microsoft (Copilot), xAI (Grok), DeepSeek, and Google AI Overviews (via SerpAPI). We send the minimum needed for the query and never share your IP address, Google Analytics data, Search Console data, or data derived from either Google integration with them. Each provider processes data under its own privacy policy.
Who we share data with
We share data only with the subprocessors needed to run the service — payments, hosting/CDN, email delivery, analytics providers, and the AI providers above. We do not sell personal data. The current list, with what each receives and where, is on our Subprocessors page.
International transfers
Some providers (including our payment, hosting, and AI providers) are located in the United States. Where we transfer personal data outside the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and providers' approved data-transfer frameworks.
Data retention
We retain Google OAuth tokens, selected property/site metadata, imported Google metrics, and derived Google-integration data only while that integration remains connected. Using Disconnect in FixAEO deletes that integration data immediately from the live database for the selected brand. Deleting the FixAEO account also deletes it. Encrypted disaster-recovery backups expire within 30 days and are used only to restore the service after a failure, not to continue ordinary processing of disconnected data. FixAEO does not retain Google data for advertising or generalized AI-model training. We keep other account, product, and billing data for as long as your account is active. When you delete your account (see below), we remove your personal data, except records we must retain for legal or tax reasons (e.g. invoices) and encrypted backups that expire within 30 days. Hashed IPs used for rate limiting are short-lived.
Your rights
Subject to applicable law (including the GDPR and UK GDPR), you can access, rectify, erase, restrict, or object to the processing of your personal data, and request portability. Two of these are self-serve in Settings:
- Download my data — export a copy of your data (portability, Art. 20).
- Delete my account — permanently erase your account and personal data (erasure, Art. 17).
For anything else, email hello@fixaeo.com. You also have the right to lodge a complaint with your local data-protection authority.
California residents have the right to know what personal information we collect, to request deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. Exercise these rights via the same controls above or by emailing us.
Cookies
Essential cookies keep you signed in (fixaeo_session), protect sign-in against forgery, and remember your cookie choice (fixaeo_consent). None of them are used for tracking or advertising.
One cookie is optional: a first-party PostHog analytics cookie that lets us count returning visitors. It is off until you accept it, and you can withdraw at any time from Cookie settings in the footer. If your browser sends a Global Privacy Control or Do Not Track signal we treat that as a refusal automatically. Every cookie, with lifetimes, is listed in our Cookie Policy.
Children
FixAEO is a business tool not directed to children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We'll update this page when our practices change and revise the “Last updated” date above. Material changes will be communicated in-app or by email where appropriate.
Contact
Questions about this policy or your data: hello@fixaeo.com.