Your Privacy Matters

Privacy Policy

Last updated: March 25, 2026

Encrypted Everything

TLS 1.3 in transit, AES-256 at rest. API keys encrypted before storage.

No Content Selling

We never sell, share, or monetize your content or usage patterns.

You Own Your Data

Export or delete at any time. Full GDPR and CCPA compliance.

Minimal Collection

Only what's necessary. No tracking pixels, no fingerprinting.

1. Information We Collect

Account Information

Email address and, if using Google OAuth, name and profile picture. We never store your Google password.

Content You Provide

Search queries, website URLs, content text, and brand names submitted for analysis. Processed by our AI systems to generate scores and recommendations.

CMS Credentials

If you connect WordPress, Shopify, or a custom API, credentials are stored encrypted and used solely to publish on your behalf. Never shared with third parties.

Usage & Log Data

Basic first-party analytics (pages visited, features used). Server logs (IP, browser, timestamps) retained 30 days. No third-party tracking pixels or ad networks.

2. How We Use Your Information

We Do

  • Provide and improve the platform
  • Process content through AI analysis
  • Monitor AI visibility on your behalf
  • Publish to your connected CMS
  • Send service-related emails
  • Prevent fraud and abuse

We Never

  • Sell to third parties or data brokers
  • Train AI models on your content
  • Serve targeted advertising
  • Profile you for external marketing

3. Third-Party Services

ServicePurposeData Shared
OpenAI (GPT-4o)AI analysisQueries & content (not used to train models)
SupabaseAuth & databaseEmail, hashed password, OAuth tokens
VercelHosting & CDNRequest headers, IP (routing only)
AI PlatformsVisibility monitoringBrand name & industry keywords only

4. Data Security

Encryption in transit

TLS 1.3

Encryption at rest

AES-256

API key storage

Application-level encryption

Rate limiting

Per-user on all endpoints

Security headers

X-Frame-Options, CSP, HSTS

Input validation

Zod schemas server-side

SSRF protection

Public IPs only

OAuth security

Open redirect prevention

5. Data Retention

Data TypeRetention
Account dataWhile active; deleted within 30 days of account deletion
Analysis dataWhile project exists; deleted with project
AI visibility scans12 months for trend tracking; older data purged
Server logs30 days, then permanently deleted
CMS credentialsDeleted immediately when connection removed

6. Your Rights

Access

Request a copy of all personal data

Correction

Update inaccurate information

Deletion

Delete your account and all data

Portability

Export in CSV, PDF, or JSON

Opt-out

Unsubscribe from non-essential emails

Restriction

Stop processing while investigating a complaint

GDPR (EU/EEA)

Legal basis: contract performance, legitimate interest (security), and consent (marketing). You may lodge a complaint with your local supervisory authority.

CCPA (California)

Right to know, request deletion, and opt out of data sales. We do not sell personal information.

7. Terms of Service

Acceptable Use

  • No spam, malware, or harmful content generation
  • No reverse-engineering or scraping our AI systems
  • No sharing credentials or unauthorized access
  • No automated scripts exceeding rate limits

Availability

99.9% uptime target. Scheduled maintenance with advance notice. AI monitoring depends on third-party API availability.

Billing

Free tier with limits. Paid plans billed monthly or annually. Cancel anytime — access continues through billing period. Refunds within 14 days.

Intellectual Property

You retain full ownership of all content you create, upload, or generate through Auragap. We claim no rights to your content. The Auragap platform, branding, and proprietary analysis methods are owned by Auragap Inc.

8. Cookies

CookiePurposeRequired
AuthenticationKeep you logged inEssential
PreferencesDark/light modeFunctional

We do not use advertising cookies, cross-site tracking, or third-party analytics cookies.

9. Contact Us

We respond to all data-related requests within 30 days. This policy may be updated with 30 days notice via email.

Auragap is not intended for anyone under 16. We do not knowingly collect children's data.