Legal
Privacy
A privacy page is only worth reading if it is specific. This one names every third party that sees your data and every thing we deliberately do not do.
Last updated 20 August 2026
The short version
We store the business details you type in, the AI answers we collect on your behalf, and — if you give us one — an email address. Signing in is by emailed link, so there are no passwords; the only cookies this site sets are the first-party session cookies that keep you signed in. There are no tracking cookies, no analytics scripts, and no advertising pixels. We do not sell or share your data for anyone else's marketing.
What we collect
What you type into the audit form: brand name and aliases, your domains, the competitors you track — their names, domains and any aliases you list — your category, who your buyers are, and any seed questions. A run measures at most four competitors; brands you add beyond that are stored as watch-only and scored against answers we already hold, so the number you can store is not capped at four. This is business information, not personal information, with one exception below.
An email address, if you give one. It is optional on the setup form. If you buy a plan, Stripe passes us the email you used at checkout so we can send you the report and reach you about billing. Unless you switch on lead capture in our WordPress plugin, it is the only personal data we hold — see the section on connecting a CRM for what lead capture adds.
What the audit produces: the full text of every answer each AI engine returned, the URLs those answers cited, what our extraction step found in them, and the per-call API cost. These are what make the report auditable — every number on it traces back to a stored answer.
A Stripe subscription identifier, so we know whether your plan is active. We never see or store your card number, expiry, or CVC — those go straight to Stripe.
Tags and settings you put on your questions. On the Questions page you can tag a question or override its journey phase. Those tags are stored on the question itself — business configuration you wrote, shown back to you and included in your own CSV exports, never used for anything else.
A record of paid feature runs.Some paid features call an AI model when you click them (suggested questions, for example) and carry a daily allowance. Each click stores one ledger row — which account asked (your sign-in email), which property, and when — because that count is what enforces the allowance and what lets us show you “2 of 5 used today.” It records that the feature ran, never the content it produced for you beyond what the feature itself saves.
Health-check results for your own domain. The Sources page can probe your homepage, robots.txt, llms.txt and agents.md to check whether AI crawlers can reach and read your site. Each check you run stores one row — which property, which signed-in account ran it (your sign-in email), when it ran, whether it completed, and the pass/fail result per named check. The probes fetch only the domain already on your property; they store the verdicts, not copies of your pages.
Fix items and their history.The Fixes page turns findings your audit already stores — lost questions, diagnosed gaps, failed health checks, your action plan’s content briefs — into tracked work items. Each item stores its title, the evidence rows it came from, its priority and status; every status change stores one history row recording who changed it (your sign-in email, or our team) and when. When a fix ships, the item can carry the published page’s URL so we can measure whether AI engines start citing it. This is business configuration and work history on your own property, shown identically to you and to the team doing the work, never used for anything else.
Assistant chat transcripts.Messages you send to the in-product assistant, and its replies, are stored as a transcript on the property you asked about — that history is what lets you reopen a conversation. Each message is capped at 10,000 characters, and each conversation at 200 messages. Transcripts are stored exactly as written: we cannot detect a password or key you paste into chat, so treat the box like any other stored field. Our team can view a transcript for support. When the assistant proposes an action (like a re-run), the proposal stays stored with the transcript; it can no longer run 15 minutes after it was proposed. Each message you send — along with the conversation so far — goes to Anthropic (Claude) to generate the answer, the same processor listed under “Who else touches your data” below. Transcripts are kept while the property exists, deleted with it, and deletable earlier on request via the contact below. We do not use them to train any model, ours or anyone else’s.
API tokens you mint. Settings can mint a token so an AI assistant reads your reports directly, through our MCP endpoint. We store the first few characters of the token, a SHA-256 hash of the whole value, your sign-in email, when it was made, when it was last used, and, once you revoke it, when that happened. The token itself is never stored: it appears once, in the response to the click that made it, and if you lose it the only remedy is to revoke it and mint another. A token reads every property your email owns, revalidated on each call, and keeps working until you revoke it. Revoking keeps the row and ends the credential. Each call stores one ledger row — your sign-in email, which token asked, and when — because that count is what holds a token to 60 calls per clock hour. It names the token rather than a property, since one token reads them all.
Which plugin sent you here, if one did. Start an audit from the link in our WordPress plugin or Shopify app and we store one row recording that this audit came from that plugin. It describes the audit, not the visitor: a first-party database row that sets no cookie, runs no script, and follows nobody between pages or sites. It stores no name, email address, IP address, or device identifier — only which plugin, and the id of the audit it belongs to.
An email address, if you give one. It is optional on the setup form. If you buy a plan, Stripe passes us the email you used at checkout so we can send you the report and reach you about billing. Unless you switch on lead capture in our WordPress plugin, it is the only personal data we hold — see the section on connecting a CRM for what lead capture adds.
What the audit produces: the full text of every answer each AI engine returned, the URLs those answers cited, what our extraction step found in them, and the per-call API cost. These are what make the report auditable — every number on it traces back to a stored answer.
A Stripe subscription identifier, so we know whether your plan is active. We never see or store your card number, expiry, or CVC — those go straight to Stripe.
Tags and settings you put on your questions. On the Questions page you can tag a question or override its journey phase. Those tags are stored on the question itself — business configuration you wrote, shown back to you and included in your own CSV exports, never used for anything else.
A record of paid feature runs.Some paid features call an AI model when you click them (suggested questions, for example) and carry a daily allowance. Each click stores one ledger row — which account asked (your sign-in email), which property, and when — because that count is what enforces the allowance and what lets us show you “2 of 5 used today.” It records that the feature ran, never the content it produced for you beyond what the feature itself saves.
Health-check results for your own domain. The Sources page can probe your homepage, robots.txt, llms.txt and agents.md to check whether AI crawlers can reach and read your site. Each check you run stores one row — which property, which signed-in account ran it (your sign-in email), when it ran, whether it completed, and the pass/fail result per named check. The probes fetch only the domain already on your property; they store the verdicts, not copies of your pages.
Fix items and their history.The Fixes page turns findings your audit already stores — lost questions, diagnosed gaps, failed health checks, your action plan’s content briefs — into tracked work items. Each item stores its title, the evidence rows it came from, its priority and status; every status change stores one history row recording who changed it (your sign-in email, or our team) and when. When a fix ships, the item can carry the published page’s URL so we can measure whether AI engines start citing it. This is business configuration and work history on your own property, shown identically to you and to the team doing the work, never used for anything else.
Assistant chat transcripts.Messages you send to the in-product assistant, and its replies, are stored as a transcript on the property you asked about — that history is what lets you reopen a conversation. Each message is capped at 10,000 characters, and each conversation at 200 messages. Transcripts are stored exactly as written: we cannot detect a password or key you paste into chat, so treat the box like any other stored field. Our team can view a transcript for support. When the assistant proposes an action (like a re-run), the proposal stays stored with the transcript; it can no longer run 15 minutes after it was proposed. Each message you send — along with the conversation so far — goes to Anthropic (Claude) to generate the answer, the same processor listed under “Who else touches your data” below. Transcripts are kept while the property exists, deleted with it, and deletable earlier on request via the contact below. We do not use them to train any model, ours or anyone else’s.
API tokens you mint. Settings can mint a token so an AI assistant reads your reports directly, through our MCP endpoint. We store the first few characters of the token, a SHA-256 hash of the whole value, your sign-in email, when it was made, when it was last used, and, once you revoke it, when that happened. The token itself is never stored: it appears once, in the response to the click that made it, and if you lose it the only remedy is to revoke it and mint another. A token reads every property your email owns, revalidated on each call, and keeps working until you revoke it. Revoking keeps the row and ends the credential. Each call stores one ledger row — your sign-in email, which token asked, and when — because that count is what holds a token to 60 calls per clock hour. It names the token rather than a property, since one token reads them all.
Which plugin sent you here, if one did. Start an audit from the link in our WordPress plugin or Shopify app and we store one row recording that this audit came from that plugin. It describes the audit, not the visitor: a first-party database row that sets no cookie, runs no script, and follows nobody between pages or sites. It stores no name, email address, IP address, or device identifier — only which plugin, and the id of the audit it belongs to.
The agency waitlist
If you reserve a seat on the agencies page, we store what that form asks for: your email address, your agency name if you give one, a client-count band, and which tier you said you were interested in. We use it for exactly two things: following up on the offer, and counting demand before we build more. It is never shared or sold. To be removed, email the contact address at the bottom of this page and we will delete the row.
Signing in, and the cookies it sets
You can sign in with the email you used at checkout to see your reports in one place. We email you a one-time link; there is no password to create or leak. Sign-in is provided by Supabase Auth, the same provider that hosts our database, so your address is stored there as an auth user record.
Requesting a sign-in link sets one cookie immediately:
All of them are first-party and are set
Attaching a report to your account (“Add a report you already have”) writes your email address and a timestamp onto that audit's record — the same field the setup form or Stripe checkout would have filled.
Requesting a sign-in link sets one cookie immediately:
sb-*-auth-token-code-verifier, the random value that proves the link is being opened by the browser that asked for it. It is set when you submit the form and cleared when the link is used, or it expires unused. Completing sign-in sets the session cookies, sb-*-auth-token.All of them are first-party and are set
HttpOnly, Secure, SameSite=Lax, path /. They exist for one purpose — keeping you signed in. No script on the page can read them; they are never sent to any other site; they carry no tracking identifier and are used for no analytics. Signing out clears them. If you never use the sign-in form, this site sets no cookie at all.Attaching a report to your account (“Add a report you already have”) writes your email address and a timestamp onto that audit's record — the same field the setup form or Stripe checkout would have filled.
What we do not collect
No passwords — sign-in is by emailed link. No tracking cookies: the only cookies are the session cookies described above, set only once you sign in, which you can confirm in your browser's developer tools. No Google Analytics, no Plausible, no PostHog, no session recording, no advertising pixels, no cross-site tracking. We do not know how many pages you visited before this one. Two settings — your theme, and whether you have dismissed the dashboard tour — are remembered in your browser's own storage. Neither is a cookie, and neither is sent to us or to anyone else.
Who else sees your information
Running an audit means sending your brand name, competitor names and questions to other companies' AI systems. That is the product; it cannot be done privately. In full:
AI engines— OpenAI (ChatGPT), Anthropic (Claude), Perplexity, Google (Gemini) and xAI (Grok) receive your questions, which contain your brand and competitor names. Each engine runs a live web search to answer. We also send answers to Anthropic a second time to extract which brands were mentioned; to write your question set, gap diagnosis and action plan; to answer your assistant chat messages (which are sent with the conversation so far); and — on plans that include content drafting — to write the content drafts themselves from your audit's data.
Supabase hosts the database. Vercel hosts the site. Stripe processes payments and holds your card details. Resend delivers report-ready emails when email delivery is switched on. Nangobrokers the sign-in for Salesforce and Zoho CRM connections and holds those connections' access tokens; it never receives your audit data. If you connect a CRM, that CRM (or the webhook endpoint you name) also receives data — see the section on connecting a CRM below.
These providers process data in facilities they operate, including in the United States. If you are outside the United States, running an audit means your information is transferred there.
AI engines— OpenAI (ChatGPT), Anthropic (Claude), Perplexity, Google (Gemini) and xAI (Grok) receive your questions, which contain your brand and competitor names. Each engine runs a live web search to answer. We also send answers to Anthropic a second time to extract which brands were mentioned; to write your question set, gap diagnosis and action plan; to answer your assistant chat messages (which are sent with the conversation so far); and — on plans that include content drafting — to write the content drafts themselves from your audit's data.
Supabase hosts the database. Vercel hosts the site. Stripe processes payments and holds your card details. Resend delivers report-ready emails when email delivery is switched on. Nangobrokers the sign-in for Salesforce and Zoho CRM connections and holds those connections' access tokens; it never receives your audit data. If you connect a CRM, that CRM (or the webhook endpoint you name) also receives data — see the section on connecting a CRM below.
These providers process data in facilities they operate, including in the United States. If you are outside the United States, running an audit means your information is transferred there.
Pages we fetch on your behalf
Two steps on our side make outbound requests to websites. If you use pre-fill, we fetch your homepage once and ask a model to suggest your brand details — always shown to you as editable suggestions, never saved silently. During gap diagnosis we fetch the competitor pages the assistants actually cited, so we can say why that page won. Both respect robots.txt. We identify ourselves as a normal HTTP client and do not log in anywhere.
A third request is your browser's, not ours.Your dashboard shows each tracked brand's favicon, loaded by your own browser straight from that brand's website — never through us, and never through a favicon service, which would hand one company your whole competitor list. That website's server sees the request the way it sees any visitor: your IP address and browser, and no referrer telling it where you were. We receive nothing back from it.
A third request is your browser's, not ours.Your dashboard shows each tracked brand's favicon, loaded by your own browser straight from that brand's website — never through us, and never through a favicon service, which would hand one company your whole competitor list. That website's server sees the request the way it sees any visitor: your IP address and browser, and no referrer telling it where you were. We receive nothing back from it.
If you connect a CRM
Connecting a CRM is off by default and does nothing until you turn it on from your report's integrations page. Once connected, we send data out to a third party you chose:
Where it goes. To your CRM — HubSpot, Pipedrive, Salesforce or Zoho CRM — or, if you pick the generic webhook, to whatever HTTPS endpoint you name. That endpoint is yours to vet; we check only that it is a public HTTPS address, never a private or internal one.
What we send.For a completed audit: your brand name, your domain, the email address on the audit if there is one, the audit's numbers, and a link to the report. For a lead captured by our WordPress plugin: that person's email address, their name if the form collected one, the page URL they submitted from, and the form's id. Alongside those we send the audit's internal id and completion timestamp, so a repeat delivery can be recognised rather than duplicated. Nothing else, and no other customer's data ever goes to your CRM.
Leads are personal data about someone else. If you use lead capture, the person filling in your form is your contact, not ours — you are responsible for telling them and for having a lawful basis to pass their details on. We store and relay; we do not market to them.
Your CRM credentials. Stored encrypted (AES-256-GCM) with a key held in our deployment environment, never in the database. A HubSpot or Pipedrive token you paste in is never returned by any API, never written to a log, and never shown back to you — only the last four characters, masked. The one exception is the signing secret we generate for you when you choose the generic webhook: that one is displayed once, at the moment it is created, because you need it to verify our signature. After that screen it is masked like the rest and we cannot show it to you again. If we have no encryption key configured, the whole feature is switched off rather than storing anything in the clear.
Salesforce and Zoho sign-in uses an OAuth broker. Those two connect by signing in rather than by pasting a token, and the sign-in runs through Nango (Nango Inc.), a third-party service we use for exactly that. Nango holds the access and refresh tokens for those connections; we store only a reference to the connection and the name of the CRM, never a token of yours. Nango sees your CRM authorisation; it does not receive your audit data, which goes from us straight to your CRM.
If your agency connected the CRM. Some brands are audited under an agency arrangement, where the agency has connected its ownCRM and we have recorded, in a committed configuration file, which audits belong to it. When one of those audits completes, the same audit data described above — brand, domain, the audit's numbers, and a signed link to the white-label report, which opens that one report for that one agency and nothing else — is written to that agency's CRM as a deal with a note attached, or, if the agency connected a generic webhook rather than a CRM that has deals, posted to that endpoint instead. If the agency has turned on deal values for its connection, the deal also carries the published list price of your audit's plan, taken verbatim from our pricing page — never an estimate of what your business is worth. This happens only for audits explicitly listed on that agency's roster; membership is an exact id match, never inferred from your domain, plan or email address. An audit on no roster is sent to no agency.
Retention. Captured leads and CRM delivery records are deleted after 90 days. Disconnecting a CRM deletes the connection and its whole delivery history immediately. What already reached your CRM is in your CRM — deleting it there is up to you. An unfinished CRM sign-in stops working after thirty minutes and is deleted by our daily clean-up. It holds no personal data — only which CRM you picked, the id of the audit it belongs to, a random reference for the broker, and when it expires.
Where it goes. To your CRM — HubSpot, Pipedrive, Salesforce or Zoho CRM — or, if you pick the generic webhook, to whatever HTTPS endpoint you name. That endpoint is yours to vet; we check only that it is a public HTTPS address, never a private or internal one.
What we send.For a completed audit: your brand name, your domain, the email address on the audit if there is one, the audit's numbers, and a link to the report. For a lead captured by our WordPress plugin: that person's email address, their name if the form collected one, the page URL they submitted from, and the form's id. Alongside those we send the audit's internal id and completion timestamp, so a repeat delivery can be recognised rather than duplicated. Nothing else, and no other customer's data ever goes to your CRM.
Leads are personal data about someone else. If you use lead capture, the person filling in your form is your contact, not ours — you are responsible for telling them and for having a lawful basis to pass their details on. We store and relay; we do not market to them.
Your CRM credentials. Stored encrypted (AES-256-GCM) with a key held in our deployment environment, never in the database. A HubSpot or Pipedrive token you paste in is never returned by any API, never written to a log, and never shown back to you — only the last four characters, masked. The one exception is the signing secret we generate for you when you choose the generic webhook: that one is displayed once, at the moment it is created, because you need it to verify our signature. After that screen it is masked like the rest and we cannot show it to you again. If we have no encryption key configured, the whole feature is switched off rather than storing anything in the clear.
Salesforce and Zoho sign-in uses an OAuth broker. Those two connect by signing in rather than by pasting a token, and the sign-in runs through Nango (Nango Inc.), a third-party service we use for exactly that. Nango holds the access and refresh tokens for those connections; we store only a reference to the connection and the name of the CRM, never a token of yours. Nango sees your CRM authorisation; it does not receive your audit data, which goes from us straight to your CRM.
If your agency connected the CRM. Some brands are audited under an agency arrangement, where the agency has connected its ownCRM and we have recorded, in a committed configuration file, which audits belong to it. When one of those audits completes, the same audit data described above — brand, domain, the audit's numbers, and a signed link to the white-label report, which opens that one report for that one agency and nothing else — is written to that agency's CRM as a deal with a note attached, or, if the agency connected a generic webhook rather than a CRM that has deals, posted to that endpoint instead. If the agency has turned on deal values for its connection, the deal also carries the published list price of your audit's plan, taken verbatim from our pricing page — never an estimate of what your business is worth. This happens only for audits explicitly listed on that agency's roster; membership is an exact id match, never inferred from your domain, plan or email address. An audit on no roster is sent to no agency.
Retention. Captured leads and CRM delivery records are deleted after 90 days. Disconnecting a CRM deletes the connection and its whole delivery history immediately. What already reached your CRM is in your CRM — deleting it there is up to you. An unfinished CRM sign-in stops working after thirty minutes and is deleted by our daily clean-up. It holds no personal data — only which CRM you picked, the id of the audit it belongs to, a random reference for the broker, and when it expires.
If you connect a publishing venue
On plans that include content drafting, you can connect a venue — your WordPress site, your Shopify store, or an HTTPS webhook endpoint you name — so that a draft you approve is published to it. Like the CRM connection, this is off by default and does nothing until you add a connection from your dashboard.
What we send out.The content of the draft being published, to the venue you connected. Drafts are written from your own audit's data; nothing about any other customer is in them. Publishing to WordPress or Shopify records an undo token with the delivery, so a published item can be removed again; a webhook has no undo and the page that offers it says so.
Your venue credentials. Stored encrypted the same way as CRM credentials — AES-256-GCM, key held in our deployment environment, never in the database, never returned by any API or page after you save them. If no encryption key is configured on the deployment, publishing is switched off entirely rather than storing anything in the clear.
Revoking. Revoking a connection stops all publishing through it, including any standing permission you had recorded. What was already published to your venue is on your venue — removing it there is yours to do, or use the per-item undo where one exists.
What we send out.The content of the draft being published, to the venue you connected. Drafts are written from your own audit's data; nothing about any other customer is in them. Publishing to WordPress or Shopify records an undo token with the delivery, so a published item can be removed again; a webhook has no undo and the page that offers it says so.
Your venue credentials. Stored encrypted the same way as CRM credentials — AES-256-GCM, key held in our deployment environment, never in the database, never returned by any API or page after you save them. If no encryption key is configured on the deployment, publishing is switched off entirely rather than storing anything in the clear.
Revoking. Revoking a connection stops all publishing through it, including any standing permission you had recorded. What was already published to your venue is on your venue — removing it there is yours to do, or use the per-item undo where one exists.
Your report URL is the access control
Your report is protected by having an unguessable address and nothing else — signing in adds a dashboard that lists your reports, it does not lock the report links themselves. Anyone holding that URL can read the report. We chose that on purpose — the link is the delivery mechanism of record — but it means you control who sees your audit by controlling who has the link. The terms say the same thing in the same words.
How long we keep it
Indefinitely by default, because a report you paid for should still open in two years and a subscription's value is the comparison across months. Two things are the exception: captured leads and CRM delivery records are deleted automatically after ninety days. Ask us to delete an audit and we will delete the audit and everything attached to it — questions, answers, extractions, gaps and your email — within thirty days, and confirm when it is done. Deletion is permanent and the report link stops working. We keep the Stripe payment record, because tax law requires it.
Your rights
Email us to get a copy of everything we hold about you, correct it, or have it deleted. We do not charge for this and we do not require you to prove a legal basis. If you are in the EU, UK or California you have these rights by statute; we extend them to everyone because running two standards would be more work than honouring one.
Children
AEOSolved is a business tool and not intended for anyone under 18.
Changes
If we start collecting something new, or add an analytics tool or a cookie, this page changes in the same commit that adds it — and if it affects a paying subscriber we email the address on the audit first. The date below is when this page last changed.
Contact
paintedalways@gmail.com — for data access, deletion, or any question about this page. A person reads it.