Last Updated
September 11, 2026
AEO Goal Inc. (“AEO Goal,” “we,” “us,” or “our”) provides AI citation tracking, answer engine optimization analytics, content optimization, reporting, and related software services. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our websites, create an account, use the platform, connect third-party integrations, or contact us.
Information We Collect
Account and organization data
- Name, work email, password credentials, verification status, and support contact details.
- Company name, website, role, team membership, organization settings, and plan information.
- Security settings such as MFA status, active sessions, API key metadata, and audit events.
Customer content and analytics data
- Brands, competitors, prompts, keywords, tracked domains, markets, personas, and content briefs.
- AI search results, citations, rankings, backlink metrics, site-crawl findings, reports, and tasks.
- Generated drafts, uploaded brand-voice documents, publishing settings, and user instructions.
Connected services
If you connect Google Search Console, Google Analytics, Google Drive, GitHub, Notion, Bing Webmaster Tools, an MCP client, or another integration, we collect the account identifiers, OAuth tokens, scopes, files, metrics, and events needed to provide that integration. You can disconnect supported integrations in the product settings.
Billing, usage, and device data
- Billing contact, plan, invoices, and payment status. Card details are handled by Stripe.
- Usage counts, feature interactions, error logs, security signals, IP address, browser type, and device information.
- Support messages, demo requests, survey responses, and sales communications.
How We Use Information
- Provide, secure, monitor, and improve the AEO Goal platform.
- Run AI citation checks, SEO audits, reports, alerts, exports, publishing workflows, and integrations.
- Authenticate users, enforce tenant isolation, prevent abuse, investigate incidents, and audit security events.
- Process subscriptions, trials, invoices, payments, taxes, and account administration.
- Respond to support requests and send service, security, billing, and product notices.
- Analyze aggregate usage and product performance without identifying individual customers where practical.
- Comply with legal obligations, enforce agreements, and protect AEO Goal, customers, and the public.
Legal Bases for EU, EEA, and UK Processing
Where GDPR or UK GDPR applies, we process personal information based on contract necessity, legitimate interests in operating and securing a B2B SaaS product, consent where required, and legal obligations. Customers act as controllers for personal information they submit about their users, employees, customers, or prospects, and AEO Goal acts as processor for that Customer Personal Data under our Data Processing Addendum.
How We Share Information
We do not sell personal information. We may disclose information to service providers and subprocessors that host, secure, monitor, email, bill, store, or process platform data; third-party integrations you authorize or configure; professional advisers, auditors, insurers, and legal authorities where required or appropriate; and successors in a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate safeguards.
We do not use Customer Content to train general-purpose foundation models unless a customer has separately agreed to that use in writing.
Google User Data and API Services
AEO Goal offers optional Google integrations. AEO Goal only requests Google OAuth access after you explicitly authorize it, and only for the specific, least-privilege scopes each integration needs. This section explains, in line with the Google API Services User Data Policy and its Limited Use requirements, exactly how AEO Goal accesses, uses, shares, protects, retains, and deletes Google user data.
What Google user data we access
We request read-only scopes for the reporting integrations and per-file access for Drive. We never request broad, account-wide access:
- Google Analytics (
analytics.readonly): read-only access to your Google Analytics account and property identifiers and your traffic, engagement, content, and conversion metrics, used to display those metrics inside AEO Goal. - Google Search Console (
webmasters.readonly): read-only access to your search-performance data (queries, pages, clicks, impressions, and average position), your indexing and coverage status, and your list of verified sites, used to display search visibility inside AEO Goal. - Google Drive (
drive.file, per-file access): access limited to the specific files you select through the Google Picker and to files AEO Goal itself creates. We use this to import the brand-voice or content documents you choose, and to write reports back to your Drive when you use “Save to Drive.” AEO Goal cannot see, list, or access any other file in your Drive. - Basic profile (
openid,userinfo.email): your email address and Google account identifier, used only to label the connected account and match it to your AEO Goal user.
How we use Google user data
We use Google user data solely to operate the specific integration you connected: to display your analytics, search, and Drive content inside AEO Goal, to power the reports and workflows you request, and to keep the connection working. We do not use Google user data for any purpose you have not enabled.
How we share Google user data
We do not sell or rent Google user data, and we do not share it with third parties for their own purposes. We disclose Google user data only to the infrastructure subprocessors that host and secure AEO Goal on our behalf (for example, our cloud hosting and database providers), strictly to run the integration you enabled, or where we are legally required to. We do not transfer Google user data to data brokers or advertising networks.
How we protect Google user data
Google OAuth tokens are encrypted at rest (AES via Fernet) and scoped to the least privilege each integration needs. Google user data is encrypted in transit (TLS), protected by access controls, tenant isolation, and audit logging, is accessible only to the systems and authorized personnel required to run the integration, and is never exposed to other customers.
How we retain and delete Google user data
We retain Google user data only while the integration is connected and needed to provide the service. You can disconnect any Google integration at any time in the product settings. Disconnecting immediately revokes AEO Goal’s stored access and triggers deletion of the associated OAuth tokens and cached Google data, normally within 30 days. You may also revoke access directly from your Google Account permissions page, or email privacy@aeogoal.com to request deletion. We delete Google user data on request except where limited retention is required by law.
Limited Use commitment
AEO Goal’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, AEO Goal does not:
- sell Google user data;
- use or transfer Google user data for serving advertising, including personalized, targeted, or interest-based advertising;
- use Google user data to train, develop, or improve generalized or non-personalized AI or ML models;
- transfer Google user data to data brokers, use it for credit, lending, or other creditworthiness decisions, or use it to build commercial databases;
- transfer Google user data to any other party except as necessary to provide or improve the integration you enabled, to comply with applicable law, or with your explicit direction; or
- allow humans to read Google user data, except with your affirmative agreement for specific data, where security or abuse prevention requires it, to comply with applicable law, or where the data is aggregated and anonymized for internal operations consistent with the Limited Use requirements.
Cookies and Similar Technologies
We use essential cookies and local storage for authentication, security, session continuity, preferences, and product operation.
Our public marketing website also uses Google Tag Manager to load measurement tags, and Google Analytics 4 to measure how visitors find and use the site. Google Tag Manager sets no cookies of its own; every tag it loads is subject to the same consent choice described below. Google Analytics sets cookies that identify a returning browser and reports aggregated usage to us; Google acts as our processor for this data. We operate it under Google Consent Mode v2: in the EEA, the United Kingdom, and Switzerland, analytics and advertising storage are denied by default, and no analytics cookie is set until you accept through the consent banner. You can change or withdraw your choice at any time using the “Cookie settings” link in the site footer, which reopens the banner. Declining analytics does not affect access to any part of the site.
Google Analytics runs on the public marketing site only. The signed-in application at app.aeogoal.com ships no analytics or advertising tags, and private report pages – free audit results and shared client reports – are excluded from analytics entirely, so a domain you scan or a report you share is never sent to Google.
Security
We use administrative, technical, and organizational safeguards designed for a multi-tenant SaaS product, including encryption in transit, access controls, audit logging, scoped credentials, secure authentication, monitoring, and vendor due diligence. No internet service can be guaranteed completely secure, but we work to reduce risk and investigate suspected security incidents promptly.
Retention
We retain personal information for as long as needed to provide the services, comply with legal and accounting obligations, resolve disputes, preserve security records, and enforce agreements. Customers may export or request deletion of account data from the product where available. Some logs, backups, invoices, fraud-prevention records, and audit events may be retained for a limited period after deletion where required or justified.
International Transfers
We may process and store information in the United States and other jurisdictions where we or our service providers operate. Where required, we use appropriate transfer mechanisms such as Standard Contractual Clauses or other lawful safeguards.
Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, export, or object to processing of your personal information, and to opt out of marketing communications. California residents may also have rights to know, delete, correct, limit use of sensitive personal information, and opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising.
Submit privacy requests to privacy@aeogoal.com. We may need to verify your identity and, for data controlled by an AEO Goal customer, may direct the request to that customer.
Children
AEO Goal is a business service and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service, by email, or by another reasonable method.
Contact
For privacy questions or requests, email privacy@aeogoal.com. For legal notices, email legal@aeogoal.com.