Legal · Privacy Policy
Privacy Policy
Effective 2026-08-10 · Version 1.1 · AIO.GEO
This Privacy Policy explains how AIO.GEO ("AIO.GEO," "we," "us") collects, uses, discloses, and protects information when you use our websites, apps, APIs, CLI, MCP integrations, billing flows, and related services (the "Services"). It is designed to be transparent about categories and purposes while remaining flexible as our product and vendors evolve.
Who is the controller?
For personal data processed in connection with aio-geo.com, aio-geo.vercel.app, and the AIO.GEO Services, the operator reachable at aiogeoprotocol@gmail.com acts as controller (or equivalent) unless a written enterprise agreement names a different party. For Customer Content you process about your own end users or clients, you are typically the controller and we act as a processor/service provider.
What information do we collect?
We collect categories of information as needed to operate the Services:
Information you provide
- Account data: name, email, password or auth tokens, organization name, role, billing contact.
- Payment data: processed by payment providers (for example Stripe); we typically receive limited billing metadata, not full card numbers.
- Support and ops messages: emails, contact forms, tickets.
- Configuration: domains you audit, workspace settings, API keys and integration tokens you store.
Information collected automatically
- Usage and device data: IP address, approximate location from IP, browser/OS, referring URLs, pages viewed, feature usage, timestamps.
- Logs and security telemetry: authentication events, rate-limit hits, error traces, abuse signals, firewall events.
- Cookies and similar tech for session, CSRF, preferences, analytics, and fraud prevention.
Websites you ask us to analyze
- Public HTML, metadata, robots.txt, sitemaps, schema, headers, and related signals from domains you submit.
- Derived artifacts: scores, findings, fix packs, diffs, proof receipts, digests.
- Private systems only when you connect them with your credentials.
How do DOM parsing and math engines handle target site data?
Structural evaluation (DOM AST parsing, schema extraction, Sinkhorn-style transport scoring, and related readiness math) runs in isolated request-scoped serverless or server processes. We compute scores and fix packs from the crawl snapshot needed for that request. We do not operate a permanent archive of full third-party page source as a default product feature. Short-lived caches, logs, or customer-visible audit records (scores, findings, optional stored HTML excerpts for your workspace) may exist so you can re-open reports. Those workspace records follow retention rules below.
AI referral header decoding (bot family / intent classification) processes User-Agent and related purpose headers in memory for the request. It is not designed to build a marketing profile of individual end users browsing your site from AI products, and it does not store raw IP addresses as a product feature of that decoder.
How do cookies and sessions work?
Authenticated sessions use an HTTP cookie typically named aether_session (or equivalent). Production attributes: HttpOnly, Secure, SameSite=Lax, Path=/, and Max-Age approximately 2,592,000 seconds (30 days) unless shortened by logout or security events. Local development may relax Secure when not on HTTPS.
We also use short-lived CSRF or captcha tokens and optional preference storage. You can clear cookies in your browser; doing so ends the local session.
What database modes do we use?
Dual-mode data plane: (1) Local/sandbox mode uses PGLite (WebAssembly Postgres) or an in-memory SQL shim when DATABASE_URL is unset. Data may not survive cold starts or multi-instance hosts. (2) Production mode uses Neon Postgres (or compatible Postgres) when DATABASE_URL is configured with TLS. Account, session, agency roster, contact queue, and proof records intended for multi-user production require Postgres.
How do we use information?
- Provide, operate, secure, and improve the Services.
- Authenticate users, prevent fraud/abuse, enforce Terms.
- Communicate service and security messages; limited product messages as allowed.
- Comply with law and protect legal rights.
- Create aggregated or de-identified statistics that do not reasonably identify you.
Legal bases (EEA/UK where applicable)
Where GDPR/UK GDPR applies, we rely on contract, legitimate interests (security, product improvement, limited B2B communications), consent where required, and legal obligation.
How do we share information?
We do not sell personal information as "sell" is commonly understood in consumer retail. We may share information with service providers/processors, integrations you enable, professional advisors, authorities when required by law, and parties to a corporate transaction with appropriate safeguards.
International transfers
We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer mechanisms and vendor diligence.
Retention
We retain information as long as needed to provide the Services, comply with law, resolve disputes, and enforce agreements. When no longer needed, we delete or de-identify using reasonable commercial methods. Backups may persist for a limited rotation window.
Security
We implement administrative, technical, and organizational measures appropriate to our stage and risk (access controls, encryption in transit where configured, secret redaction, SSRF controls, rate limiting). No method of transmission or storage is 100% secure. You safeguard your own credentials.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent. California residents may have rights under the CCPA/CPRA. Contact us via the /contact form (or aiogeoprotocol@gmail.com for formal privacy requests) to exercise rights. You may lodge a complaint with a supervisory authority where applicable.
Children
The Services are directed to business users and are not intended for children under 16 (or higher age required locally). We do not knowingly collect personal data from children.
AI / automated processing
We use automated systems to crawl, score, classify findings, and generate fix suggestions. Outputs are assistive. Optional visibility probes may send limited prompts/domain context to third-party model providers when you enable and fund them.
Standing product refusal
We do not sell LLM rankings. Nobody can measure them honestly. We sell what can be measured: structure, accessibility, and receipts to prove it.
Changes and contact
We may update this Policy; the effective date will change. Privacy requests: aiogeoprotocol@gmail.com. Social: https://x.com/AIOGEO · https://instagram.com/aiogeoprotocol · https://www.youtube.com/@AIOGEO · https://www.linkedin.com/company/aio-geo-protocol.