Security and data

What happens to your data

Which AI providers we send your questions to, where the service runs, how long we keep things, and how to get a DPA. Written for the person who has to approve the purchase.

Last reviewed 1 Oct 2026. The privacy policy is the binding text; this page summarises it.

Who we are
VerifyAll Solutions Private Limited, Nagpur, Maharashtra, India. AEOTrack is our product. Company details.
What we send to AI providers
The questions you track, your brand and competitor names, your website address and public page content. We do not send your account identity with them.
AI providers
OpenAI (ChatGPT), Google (Gemini), Anthropic (Claude), Perplexity and xAI (Grok), through their official APIs with web search on. Google AI Mode answers come through SerpApi.
Where it runs
The website, app and API run on Vercel; the database is a managed MySQL service.
Data retention
Your account data, tracked sites, answers and scores stay while your account is active, so trend charts work. Ask us to delete your account and we remove your personal data within 30 days. A free check’s result is reused for 7 days, then a new check runs.
Payments
Through Stripe. Card numbers never reach our servers.
How we protect it
TLS on every connection, with HSTS. Passwords stored as bcrypt hashes. Stored integration credentials (for example GitHub or WordPress) encrypted. The browser session is an HttpOnly cookie, and the website and app enforce a Content-Security-Policy.
DPA
On request: privacy@aeotrack.io.
Certifications
None today (no SOC 2, no ISO 27001). We answer security questionnaires on request.

GDPR, UK GDPR and India’s DPDP Act

EU and UK. If you are in the European Economic Area or the United Kingdom, you have the rights the GDPR and UK GDPR give you: access, correction, erasure, restriction, portability, objection and withdrawal of consent. We answer requests within 30 days, and we sign a DPA for business customers on request.

India. We are an Indian company and handle personal data under the Digital Personal Data Protection Act, 2023. Consent, correction, erasure and grievance requests go to privacy@aeotrack.io.

Everyone. We do not sell personal data and do not share it with advertisers. Details are in the privacy policy and the cookie policy.

Subprocessors

Who else handles your data, and why

The same list as section 6 of the privacy policy. We update both when it changes.

SubprocessorWhat forWhat it receives
OpenAIChatGPT answers; content analysis and plan suggestionsYour questions, brand and competitor names, website URL and public page content
AnthropicClaude answers; content analysisThe same
GoogleGemini answers; Google sign-in; Search Console and GA4 when you connect themThe same; your sign-in profile; the Google properties you connect
PerplexityPerplexity answersYour questions
xAIGrok answersYour questions
SerpApiGoogle AI Mode answers and the SERP monitorYour questions and keywords
VercelHosting of the website, the app and the APIAll service data in transit
Managed MySQL hostingThe database: accounts, tracked sites, answers and scoresAll stored service data
StripePayments and subscriptionsBilling details; card data stays with Stripe
BrevoAccount, report and billing emailsName, email address, email content
Google Analytics, Microsoft ClarityWebsite and product analyticsUsage data from cookies; not loaded for staff and test accounts
FAQ

Questions from procurement

Do you train AI models on my data?

No. We send your questions to the AI providers to get their answers; we do not train models. Each provider's API terms govern what it does with API traffic.

Can I get a DPA?

Yes. Write to privacy@aeotrack.io and we send our data processing agreement, with the list of subprocessors and where they host your data.

Are you SOC 2 or ISO 27001 certified?

No, not today. We would rather say so than imply it. If your procurement team has a security questionnaire, send it to privacy@aeotrack.io and we will answer it.

How do I delete my data?

Write to privacy@aeotrack.io from the account's email address. We remove your personal data within 30 days, except what we must keep for legal, accounting or tax reasons.

Found a security problem? Write to privacy@aeotrack.io with “Security report” in the subject.