Privacy

What this platform stores, who it sends data to, and why. Written against what the software actually does — if you find a gap between this page and the product, the page is the bug.

Last updated 24 August 2026

What we hold about you

An account here holds very little about a person. The columns that exist are:

DataWhy it exists
Email addressIdentifies the account, receives sign-in and reset messages.
PasswordStored as a scrypt hash, never as text. We cannot read it, and a database dump does not yield it.
Two-factor secretOnly if you turn two-step verification on. Removing it removes the secret.
Failed sign-in count and lockout timeRate-limits guessing. Cleared on a successful sign-in.
Google or GitHub identityOnly if you sign in with one. We store the provider's id and the email it returns — never a password or a token that can act on your behalf there.

We do not store a name, a phone number, a postal address or a payment card. Card details go to PayPal and never touch this system.

What we hold about your websites

The product measures whether AI answer engines cite the domains you add. To do that it stores the prompts in your panel, the answers those engines returned, which domains each answer cited, and the derived rates. This is business data about public web content, not personal data — but answers come back as free text, so an answer could quote a person.

If you connect a CMS, the access token you supply is encrypted at rest with a key held outside the database (AEO_CREDENTIAL_KEY). A dump of the database yields ciphertext. You can revoke a connection at any time, which marks the credential revoked and stops it being used.

Who we send data to

Each of these receives something, and only what it needs:

ProcessorWhat it receives
PayPalThe amount and plan being purchased. Payment details are entered on PayPal, not here.
ResendYour email address and the message body, to deliver sign-in and reset mail.
Answer engines — OpenAI, Anthropic, Perplexity, and SerpApi for Google AI OverviewsThe prompts in your panel. These are questions about your market, generated from the brand and category you supplied. Your account details are not sent.
Google (Search Console, Analytics)Only if you connect them, and only to read your own reporting data back.

We do not sell data or share it between customer accounts. The dashboard records first-party product events such as page views, completed runs, and opened opportunities to operate onboarding, account-health, and retention workflows. These records stay in our database, contain no page content or typed prompt text, and are not sent to an advertising network or third-party analytics tracker.

How long we keep it

Measurement history is kept for as long as the account exists, because the product's value is the trend line — deleting last quarter's runs would delete the comparison you are paying for. Deleting an account removes its brands, panels, runs, answers, articles and credentials with it.

After an account is closed we remove it and its measurement data within 30 days. Two things outlive that, and for different reasons:

  • Invoices and payment records. Indonesian company-records law requires financial documents to be retained for ten years, so these are kept whether or not the account still exists. They hold an account name, an email and an amount — not card details, which we never had.
  • Aggregate counts with no account attached — how many runs the platform performed in a month. Nothing in them identifies anyone.

Payments, cancellation and refunds

Plans are billed for a fixed period in advance. You can cancel whenever you like — there is no notice period and nothing to phone about.

  • Cancelling stops the next renewal, not the current period. When you cancel, your plan stays active until the end of the period you have already paid for, and the service simply does not renew after that. You keep full access until then.
  • Payments are non-refundable. We do not refund the unused part of a period when you cancel — you have the service you paid for until the period ends, and that is what the payment covered.

We keep the invoice and payment record for that charge — see “How long we keep it” above.

Your choices

  • You can export your invoices as CSV from the Invoices page at any time.
  • You can revoke a CMS connection without deleting anything else.
  • You can ask for your account and its data to be deleted. Write to us and we will do it.

We are established in Indonesia and this service is provided under Indonesian law. If you are in a jurisdiction with its own statutory data rights — the EU's GDPR, the UK's DPA, California's CCPA — write to us and we will honour a request to access, correct or delete your data regardless of whether we are strictly bound by that regime. It is a small amount of data and refusing on a technicality would be a poor way to treat a customer.

Who we are

This service is operated by OptimaFlow, based in Yogyakarta, Indonesia. Contact details for privacy questions are at the bottom of this page.

We have no dedicated data-protection officer — we are a small team, and appointing one on paper who is not actually the person answering would be theatre. Privacy questions reach a human at the address below.