Skip to content
FixAEO

Subprocessors

To run FixAEO we rely on the third parties listed below. Each is here because it touches some user-attributable data at runtime. We don't add new subprocessors silently — material additions are reflected here before they go live.

Last updated: 2026-08-11

ProviderPurposeData sharedRegion
Lemon SqueezyMerchant of Record — payment processing, sales tax / VAT, and recurring billing for Lite subscriptionsEmail, billing name + address, card data (handled by Lemon Squeezy / Stripe — we never see card numbers)USA (Lemon Squeezy, a Stripe company)
CloudflareCDN, DNS, DDoS protection, edge caching for fixaeo.comIP address (hashed before logging), request headers, country (for geo-routing)Global edge network
PostHogProduct + site analytics — page views and named events (e.g. "started a scan"). No session recording, no autocapture, no advertising audiences.IP address (for coarse country/city only), page URL, named events, and — only if you accept the optional analytics cookie — a random first-party identifier. Signed-in events key on your FixAEO user id.USA (PostHog Cloud US)
AhrefsAhrefs Web Analytics — cookie-free page-view counting for the marketing sitePage URL, referrer, coarse device/country data. No cookies, no identifier stored on your device.EU / Singapore
Oracle Cloud InfrastructureApplication server + Postgres database hostingAuthenticated-user data, including encrypted Google OAuth tokens and imported Google integration metrics (encrypted disk + protected DB)India (Mumbai region)
AnthropicClaude API — produces some of the AI-engine responses we score in scansBrand prompts (the scan queries) only. No user identifiers attached.United States
OpenAIChatGPT API — same role as Anthropic for OpenAI's modelsBrand prompts only. No user identifiers attached.United States
Google (AI Studio + Gemini API)Gemini API — same role as Anthropic for Google's modelsBrand prompts only. No user identifiers attached.United States / Global
xAIGrok API — Grok model coverage for scansBrand prompts only. No user identifiers attached.United States
DeepSeekDeepSeek API — DeepSeek model coverage for scansBrand prompts only. No user identifiers attached.China
SerpAPIGoogle AI Overviews coverage (Google's AI Overview can't be queried directly; SerpAPI provides programmatic access)Brand prompts only. No user identifiers attached.United States
Google Workspace (Gmail SMTP)Transactional email delivery (magic-link sign-in)Email address + magic-link URL onlyGlobal (Google datacenters)
GitHubOAuth sign-in (only if you choose to sign in with GitHub)Your GitHub user ID, email, display name, avatar URL — only sent to us if you authorizeUnited States
Google OAuthOAuth sign-in (only if you choose to sign in with Google)Your Google sub (user ID), email, display name, avatar URL — only sent to us if you authorizeGlobal
Microsoft identity platformOAuth sign-in (only if you choose to sign in with Microsoft)Your Microsoft subject ID, email, and display name — only sent to us if you authorizeGlobal

How brand-prompt data flows to LLM providers

When we scan your brand we send each prompt to multiple AI engines as if a real user were asking them. The prompts themselves carry your brand context (e.g. “Best CRM for early-stage startups?”), but we strip user identifiers before the outbound call — the LLM provider sees only the prompt text and our API key. Provider terms differ in whether they retain prompts for training; we've linked each provider's privacy policy above for the authoritative detail.

Google integration data flow

Google Analytics 4 and Google Search Console data is processed on FixAEO's application and database infrastructure solely to provide the connected dashboard features. It is not sent to the AI providers, analytics providers, advertising platforms, or data brokers listed above. Search Console prompt suggestions are generated locally inside FixAEO. Disconnecting an integration deletes its token and imported or derived Google data from the live database; encrypted disaster-recovery backups expire within 30 days.

Changes to this list

We publish a dated change-log line above. If we add a new subprocessor, this page goes live before the production change. If you object to a specific subprocessor and that subprocessor is essential to the service, your only recourse is to delete your account — see Privacy Policy for the right-to-erasure path.

Questions?

Email hello@fixaeo.com — we reply within 24 hours on business days.