AEO Owl operates aeoowl.com and provides AI visibility auditing services. Contact us at admin@aeoowl.com.
We do not sell your data or use audit inputs for any purpose other than generating your reports. We do not use your data to train any AI model.
AEO Owl uses the following third-party services to deliver the platform. Each receives only the data described below.
| Service | Purpose | Data shared |
|---|---|---|
| Cloudflare | Hosting (Workers + Pages), CDN, DDoS protection, AI Gateway | All HTTP traffic by design (CDN edge) |
| Supabase | Postgres database and authentication | Account data, brand and audit configuration, audit history |
| Stripe | Payment processing and subscription management | Name (if provided), email, payment details |
| Resend | Transactional email delivery | Email address and message content (welcome, alerts, audit-complete, contact form replies) |
| OpenRouter | AI engine queries (ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek, Mistral) | Only the audit questions you configure — never your account info, audit history, or other brand data |
| SerpAPI | AI engine queries (Google AI Overviews) | Only the audit questions you configure — never your account info, audit history, or other brand data |
Each provider has its own data policies. We send each one only the data necessary for the specific purpose described. See our Security page for the full data-flow details.
We retain your account data and audit history for as long as your account is active — your reports stay with you forever for the life of the account. The Platform Preview at /app?demo=1 uses sample data and does not persist your inputs.
On account closure (you can close your account yourself any time from Profile → Delete account with a 30-day grace period, or request closure by emailing admin@aeoowl.com), personal data is deleted within 30 days except where legally required for tax or fraud-prevention purposes. Inactive accounts may be purged automatically after 15 months of no activity.
AEO Owl uses only essential cookies required for the platform to function — primarily a session cookie set by Supabase Auth so you stay signed in, and standard Cloudflare protection cookies. We do not use advertising, marketing, or third-party analytics cookies. Theme preference (light/dark) is stored in browser localStorage, not a cookie.
To exercise any right, email admin@aeoowl.com. We respond within 30 days.
All data is transmitted over HTTPS (TLS 1.3) and encrypted at rest (AES-256 via Supabase Pro). Passwords are hashed with bcrypt. Payment data is handled exclusively by Stripe-hosted Checkout — AEO Owl never touches card data. Every database table is gated by Row-Level Security so customers cannot see each other's data. See our Security page for the full posture details, including admin controls, monitoring, supply-chain protections, and vulnerability reporting.
AEO Owl is operated from the United States. Where data is transferred internationally, we ensure appropriate safeguards are in place in accordance with applicable law.
AEO Owl is not directed at children under 16. We do not knowingly collect personal data from anyone under 16.
We may update this policy periodically. Material changes will be notified to account holders by email.
This policy is a starting point and not legal advice. Consult a qualified legal professional to ensure compliance with applicable law.