Privacy Policy

    Last Updated: August 12, 2026

    1. Overview

    This Privacy Policy describes how GeoNexo AI ("GeoNexo," "we," "us," or "our") collects, uses, stores, shares, and protects your personal information when you use our website at geonexo.ai, dashboard, APIs, and related services (collectively, the "Service"). By using the Service, you consent to the practices described in this policy.

    2. Information We Collect

    We collect information in the following categories:

    2.1 Information You Provide Directly

    • Account information: email address, full name, display name, and password (or Google/Apple sign-in credentials).
    • Business information: website URL, business name, business type, services offered, products, target locations, primary location, brand voice, and competitor names.
    • Brand assets you upload or that we collect from your website: logos, colours, fonts, product photos, premises photos, and photographs of people (for example team headshots) that you choose to use in generated content.
    • Profile information: avatar/profile picture (uploaded to our storage), referral codes.
    • Team and client information: names and email addresses of colleagues you invite, and the business details of client workspaces created by agency accounts.
    • Communication preferences: report opt-out preferences, email unsubscribe preferences, and, where you enable it, the phone number used for WhatsApp briefs.
    • Contact inquiries and bookings: name, email, subject, and message when you submit a contact form or book a call through our scheduling provider (Cal.com).
    • Payment information: processed by Stripe. We store your Stripe customer and subscription IDs but do not store credit card numbers, CVVs, or full payment details on our servers.

    2.2 Information Collected Automatically

    • Usage analytics: page views, feature usage, button clicks, onboarding step completion, and navigation patterns collected via PostHog (our analytics provider).
    • Attribution data: the landing page, campaign, and referral source associated with your first visit and sign-up.
    • Device and browser information: browser type, operating system, screen resolution, and device type.
    • AI scan data: visibility scores, sentiment analysis, citation data, competitor mentions, source and discussion data, and AI model responses generated when we scan your brand's presence across AI platforms.
    • Content and generation logs: records of content and images generated through the Service (blog posts, FAQs, social posts, schema markup, image prompts), including the content body, prompts used, model and quality settings, and processing metadata.
    • Publishing and scheduling records: scheduled publish times, approvals, edits, and publication results for connected platforms.
    • API usage: requests made with your API keys, including timestamps, endpoints, and rate-limit counters.

    2.3 Information from Third-Party Integrations

    • When you connect third-party accounts (Google Analytics, Google Search Console, Google Business Profile, LinkedIn, X/Twitter, Facebook, Instagram, WordPress, Webflow, Ghost), we receive access tokens and basic account information (account name, account ID) through OAuth flows managed by Nango.
    • LinkedIn: profile information (name, profile ID), post content, and engagement analytics.
    • X (Twitter): handle, avatar URL, user ID, and content publishing capabilities.
    • Facebook and Instagram: page and business account IDs, names, and publishing permissions you grant.
    • Google services: search rankings, traffic data, and business profile information as authorized by you.

    3. How We Use Your Information

    We use the information we collect to:

    • Provide, maintain, and improve the Service, including AI visibility scans, content and image generation, the publishing calendar, and analytics dashboards.
    • Process payments, manage trials, and administer subscription plans via Stripe.
    • Send transactional emails and, where enabled, WhatsApp briefs: account verification, password resets, visibility reports, trial and subscription updates, approval reminders, and payment failure notices.
    • Publish content on your behalf to connected third-party platforms at the times you schedule or approve.
    • Analyze usage patterns and attribution via PostHog to improve the product, identify bugs, and understand feature adoption and conversion.
    • Detect and prevent fraud, abuse, and violations of our Terms, including monitoring for flagged accounts and API misuse.
    • Provide customer support, respond to inquiries, and prepare for scheduled calls.
    • Sync your account and attribution data with our CRM (Attio) for customer relationship management and sales follow-up.
    • Identify you publicly as a GeoNexo customer using your business name, logo, and website URL, as described in section 6 and in our Terms and Conditions.

    4. Data Storage & Security

    • Your data is stored on cloud infrastructure provided by Supabase (hosted on AWS). Our database is protected by Row-Level Security (RLS) policies ensuring users can only access data belonging to their own account and projects.
    • Sensitive tokens (third-party OAuth access tokens, platform credentials) are encrypted at rest using PGP symmetric encryption with a server-side encryption key stored in a secure vault.
    • API keys are stored as hashes; the full key is shown once at creation and can be revoked at any time.
    • We use HTTPS/TLS for all data in transit between your browser and our servers.
    • File storage (avatars, brand assets, generated images, blog images, email assets) is hosted on Supabase Storage with access controls appropriate to each bucket.
    • Project data is shared with all members of that project, and edits (including collaborative content editing) are synced in real time to other members.
    • We do not store your third-party passwords. OAuth integrations are managed through Nango, which handles token refresh and storage.
    • While we implement commercially reasonable security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data and shall not be liable for unauthorized access resulting from sophisticated attacks, zero-day vulnerabilities, or circumstances beyond our reasonable control.

    5. Data Sharing & Sub-Processors

    We do not sell your personal information. We share it with the following categories of service providers (sub-processors) who process it on our behalf:

    • Hosting and database: Supabase (AWS, United States).
    • Payments: Stripe processes your payments and receives your billing information under its own privacy policy.
    • Analytics: PostHog receives identified and anonymized product usage data, hosted in the United States.
    • CRM and sales: Attio receives account information (user ID, email, name, business, plan, and attribution data).
    • OAuth provider: Nango manages OAuth connections and stores access/refresh tokens for connected integrations.
    • AI providers: OpenAI, Google, Anthropic-compatible gateways, Perplexity, xAI, and DeepSeek receive prompts containing your brand, business, and content data to run visibility scans and generate text; OpenAI's image models receive your prompts and any reference images you supply to generate images.
    • Data and scraping providers: Bright Data and similar providers are used to retrieve AI answers, search results, and publicly available web content.
    • Email delivery: our transactional email infrastructure processes recipient addresses and message content, and we maintain send logs, suppression lists, and unsubscribe records.
    • Messaging: where you enable WhatsApp briefs, your phone number and message content are processed by the WhatsApp Business API provider.
    • Scheduling: Cal.com processes the details you submit when booking a call.
    • Content publishing: when content is published, we transmit it and any associated media to the platforms you have connected.
    • We may disclose your information if required by law, legal process, or government request, or to protect the rights, property, or safety of GeoNexo, our users, or the public. In a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

    6. Use of Your Name & Logo

    When you become a customer, we may identify you publicly as a GeoNexo customer using your business name, logo, brand marks, and website URL — for example on our website, customer logo walls, sales and investor materials, and social media. This is a factual reference to an existing business relationship and does not imply your endorsement. We will not publish a quote, testimonial, case study, or results data about you without your separate written approval. You can opt out at any time by emailing support@geonexo.ai; we will stop using your name and logo in new materials and remove them from materials we control within thirty (30) days.

    7. Cookies & Local Storage

    • We use browser local storage (prefixed with 'geonexo:') to cache onboarding data, session preferences, and temporary UI state. This data is cleared upon sign-out.
    • PostHog may set cookies for analytics and user identification purposes.
    • Supabase authentication uses secure tokens stored in local storage for session management.
    • We use advertising and conversion pixels, including the Meta Pixel and the OpenAI advertising pixel, to measure the performance of our ad campaigns.

    8. Data Retention

    • Account data is retained for as long as your account is active.
    • Upon account deletion, we permanently delete your profile, projects, scan results, generated content, brand assets, connected integrations, and all associated data. This process is irreversible.
    • We may retain anonymized, aggregated data that cannot be used to identify you for analytical and product improvement purposes.
    • Financial transaction records may be retained as required by applicable tax and accounting laws.
    • Email send logs, suppression lists, and audit logs may be retained for compliance and abuse prevention purposes.
    • Orphaned data from recycled email addresses is automatically purged when a new account is created with the same email.

    9. Your Rights

    Depending on your jurisdiction, you may have the following rights:

    • Access: You can view your personal data through your Account settings and dashboard.
    • Correction: You can update your display name, avatar, and other profile information at any time.
    • Deletion: You can permanently delete your account and all associated data through Account settings. Deletion requires typing 'DELETE' as confirmation.
    • Data portability: You can view and export your scan results, publishing calendar, and generated content through the dashboard.
    • Opt-out of communications: You can opt out of visibility reports and WhatsApp briefs in Account settings, and unsubscribe from transactional emails via unsubscribe links.
    • Disconnect integrations: You can revoke third-party platform access at any time through the Integrations settings.
    • To exercise any rights not covered above, contact us at support@geonexo.ai.

    10. Children's Privacy

    The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at support@geonexo.ai.

    11. International Data Transfers

    Your information may be transferred to and processed in the United States, where our servers and service providers are located. By using the Service, you consent to the transfer of your data to the United States and acknowledge that data protection laws in the United States may differ from those in your jurisdiction. We implement appropriate safeguards to protect your data during international transfers.

    12. California Privacy Rights (CCPA)

    If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and how it is used, the right to request deletion of your personal information, and the right to opt out of the "sale" of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at support@geonexo.ai.

    13. European Privacy Rights (GDPR)

    If you are located in the European Economic Area (EEA) or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, restriction of processing, data portability, and objection. Our legal bases for processing include: (a) performance of our contract with you (providing the Service); (b) your consent (for optional features like integrations and analytics); and (c) our legitimate interests (fraud prevention, product improvement). To exercise your GDPR rights or lodge a complaint, contact us at support@geonexo.ai or your local supervisory authority.

    14. Data Breach Notification

    In the event of a data breach that is reasonably likely to result in a risk to the rights and freedoms of affected individuals, we will notify affected users and relevant supervisory authorities as required by applicable law. Notification will be made without undue delay and, where feasible, within 72 hours of becoming aware of the breach. However, GeoNexo shall not be liable for damages resulting from a data breach except to the extent required by applicable law and subject to the limitations set forth in our Terms and Conditions.

    15. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy. We encourage you to review this page periodically.

    16. Contact Us

    If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

    This Privacy Policy should be read in conjunction with our Terms and Conditions.