Back to home
Legal

Privacy Policy

Last updated: July 2026

Plain English summary: AEO Owl collects only what it needs to provide the service. We do not sell your data or share it with advertisers. You can request deletion at any time by emailing admin@aeoowl.com.

1. Who we are

AEO Owl operates aeoowl.com and provides AI visibility auditing services. Contact us at admin@aeoowl.com.

2. Data we collect

  • Account information — email (provided at Stripe Checkout when you purchase), name (cardholder name from Stripe, if provided), and any details you add later in your Profile.
  • Brand & audit inputs — brand name, domain, a one-line description of who you serve, competitor brands or domains (up to 5), and the audit questions you configure (up to 10 per brand). Used solely to run your audits and compute your reports.
  • Payment information — handled entirely by Stripe (PCI-DSS Level 1). We never store, log, process, or transmit card numbers, CVVs, or expiration dates.
  • Communications — the content of any messages you send via the Contact form on our About page or to admin@aeoowl.com.
  • Operational logs — Cloudflare edge logs (IP, user-agent, URL) and Worker request logs for security and uptime. We do not run Google Analytics, Mixpanel, Hotjar, Facebook Pixel, or any other third-party tracking or analytics services.

3. How we use your data

  • To provide and improve the AEO Owl service
  • To run AI visibility audits against the AI engines on the brands you configure
  • To process payments and manage your account via Stripe
  • To send transactional email (welcome, audit-complete notifications, alerts) via Resend; authentication emails such as password reset and magic links are sent via Supabase Auth
  • To respond to support enquiries
  • To comply with legal obligations

We do not sell your data or use audit inputs for any purpose other than generating your reports. We do not use your data to train any AI model.

4. Third-party services

AEO Owl uses the following third-party services to deliver the platform. Each receives only the data described below.

ServicePurposeData shared
CloudflareHosting (Workers + Pages), CDN, DDoS protection, AI GatewayAll HTTP traffic by design (CDN edge)
SupabasePostgres database and authenticationAccount data, brand and audit configuration, audit history
StripePayment processing and subscription managementName (if provided), email, payment details
ResendTransactional email deliveryEmail address and message content (welcome, alerts, audit-complete, contact form replies)
OpenRouterAI engine queries (ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek, Mistral)Only the audit questions you configure — never your account info, audit history, or other brand data
SerpAPIAI engine queries (Google AI Overviews)Only the audit questions you configure — never your account info, audit history, or other brand data

Each provider has its own data policies. We send each one only the data necessary for the specific purpose described. See our Security page for the full data-flow details.

5. Data retention

We retain your account data and audit history for as long as your account is active — your reports stay with you forever for the life of the account. The Platform Preview at /app?demo=1 uses sample data and does not persist your inputs.

On account closure (you can close your account yourself any time from Profile → Delete account with a 30-day grace period, or request closure by emailing admin@aeoowl.com), personal data is deleted within 30 days except where legally required for tax or fraud-prevention purposes. Inactive accounts may be purged automatically after 15 months of no activity.

6. Cookies

AEO Owl uses only essential cookies required for the platform to function — primarily a session cookie set by Supabase Auth so you stay signed in, and standard Cloudflare protection cookies. We do not use advertising, marketing, or third-party analytics cookies. Theme preference (light/dark) is stored in browser localStorage, not a cookie.

7. Your rights

  • Access — request a copy of data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of your data (right to be forgotten)
  • Portability — receive your data in a structured format

To exercise any right, email admin@aeoowl.com. We respond within 30 days.

8. Security

All data is transmitted over HTTPS (TLS 1.3) and encrypted at rest (AES-256 via Supabase Pro). Passwords are hashed with bcrypt. Payment data is handled exclusively by Stripe-hosted Checkout — AEO Owl never touches card data. Every database table is gated by Row-Level Security so customers cannot see each other's data. See our Security page for the full posture details, including admin controls, monitoring, supply-chain protections, and vulnerability reporting.

9. International transfers

AEO Owl is operated from the United States. Where data is transferred internationally, we ensure appropriate safeguards are in place in accordance with applicable law.

10. Children

AEO Owl is not directed at children under 16. We do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

We may update this policy periodically. Material changes will be notified to account holders by email.

12. Contact

AEO Owl — Privacy
aeoowl.com

This policy is a starting point and not legal advice. Consult a qualified legal professional to ensure compliance with applicable law.