← Back to Home

Privacy Policy

Last updated: August 21, 2026

1. Introduction

Aeolo ("we," "our," or "us") operates a brand intelligence, AI-search visibility, and content-agent platform for businesses. This Privacy Policy applies to the Aeolo website, dashboard, APIs, MCP server, and Aeolo experiences made available through ChatGPT or Codex (collectively, the "Service").

This policy explains the categories of personal data we collect, why we use it, the categories of recipients that receive it, how long we retain it, and the controls available to you.

2. Information We Collect

  • Account Information: Name, email address, authentication identifiers, workspace membership, role, and account preferences.
  • Brand and Workspace Data: Domains, brand and product information, tracked prompts, strategies, source policies, content, images, approvals, publication status, and analysis results that you or an authorized teammate provide or create.
  • Connected-Service Data: Analytics, search, commerce, social, storage, and publishing data from services that you explicitly connect, together with encrypted OAuth credentials or connection metadata needed to maintain those integrations.
  • ChatGPT and Plugin Inputs: The task-specific tool arguments, selected Aeolo domain or record identifiers, content, and links that you intentionally ask ChatGPT or Codex to send to Aeolo. Aeolo does not request or reconstruct your full chat history.
  • Usage and Security Data: Tool calls, feature interactions, IP address, browser or device information, timestamps, authentication events, audit records, and error or diagnostic information needed to operate and secure the Service.
  • Billing Data: Plan, transaction, invoice, and entitlement records. Payment processors handle full payment card details; Aeolo does not store full card numbers.

3. How We Use Your Information

  • Authenticate users, enforce domain-level authorization, and operate workspaces and integrations.
  • Provide brand analysis, saved AI-visibility views, site audits, content-agent workflows, publishing, automation, attribution, and support.
  • Process a user-requested write or external action only within the selected workspace and with the confirmation or approval required by the Service.
  • Maintain reliability, debug failures, prevent fraud or abuse, protect accounts, and comply with legal obligations.
  • Improve the Service using product feedback and aggregated or de-identified operational information. We do not sell personal data or use it for targeted advertising.

4. Categories of Recipients

  • Infrastructure Providers: Cloud hosting, database, storage, caching, authentication, and content-delivery providers that operate the Service.
  • AI and Processing Providers: Model and processing providers that receive the minimum task data needed to perform analysis, generation, extraction, or evaluation requested through Aeolo.
  • Analytics, Reliability, and Support Providers: Services used for product analytics, error monitoring, observability, customer support, and security.
  • Connected Platforms: Google, Meta, commerce, content-management, storage, and publishing services receive data only when necessary to read an authorized connection or carry out an action you direct.
  • OpenAI: When you use Aeolo through ChatGPT or Codex, OpenAI sends the selected tool inputs to Aeolo and receives the tool results needed to answer your request. OpenAI processes its copy of that data under its own terms and privacy policies.
  • Professional and Legal Recipients: Payment processors, auditors, advisers, regulators, courts, or authorities where reasonably necessary for billing, legal compliance, security, or the protection of rights.

5. ChatGPT and OpenAI Plugin Data

Aeolo receives only the tool inputs and referenced resources that ChatGPT or Codex sends for the request you make. We do not request the full conversation transcript, passwords, API keys, payment-card data, MFA codes, government identifiers, or protected health information through plugin tools.

Read tools return data only for Aeolo domains that the authenticated user is authorized to access. Tools that create, update, delete, publish, deploy, send, or start paid work are labelled as write actions and are subject to user intent, confirmation, and workspace permissions.

Disconnecting Aeolo from ChatGPT prevents new plugin access but does not by itself delete the underlying Aeolo account or workspace. Use Aeolo account settings or the Data Deletion page to request deletion.

6. Google User Data and Limited Use

Aeolo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect Google, we request only the scopes needed for features you select, such as identity, Google Analytics, Search Console, or Drive access. Google data is used to show metrics, import user-selected assets, and provide recommendations for properties you explicitly connect.

We do not sell Google user data, use it for advertising, or permit unrelated human access. OAuth credentials are encrypted at rest. Disconnecting a domain removes its binding immediately. If the same Google credential is still used by another authorized Aeolo domain or channel, it is retained only for that remaining connection; otherwise it is deleted. You can revoke Aeolo account-wide from your Google Account permissions.

7. Meta Platform Data (Instagram and Threads)

When you connect an Instagram professional account or Threads profile, Aeolo requests the permissions needed to display the connected account and publish content that you explicitly create and approve.

Meta platform data is used only to provide the connected-account and publishing workflows you request. Aeolo does not read private messages and does not publish without a user-directed action.

Meta OAuth credentials are encrypted at rest and retained only while the connection remains active, subject to the retention rules below.

8. Data Retention

  • Temporary Onboarding Previews: Retained for up to 7 days unless you claim the preview into an authenticated workspace sooner.
  • Account and Workspace Data: Retained while the account or shared workspace is active. After a valid deletion request, data controlled only by the requesting account is removed from active systems without undue delay and ordinarily within 30 days.
  • Connected-Service Credentials: Retained until the connection is disconnected, the credential expires, or the owning account is deleted, except where the same encrypted credential is still required by another connection you maintain.
  • Operational and Error Logs: Normally retained for up to 90 days. Records needed to investigate abuse, fraud, or a security incident may be retained for up to 12 months or longer where legally required.
  • Billing and Legal Records: Retained for up to 5 years, or longer if applicable tax, accounting, dispute, or legal obligations require it.
  • Backups and De-Identified Data: Deleted data may remain in access-restricted backups for up to 90 days before rotation. Aggregated or de-identified information that can no longer reasonably identify a person may be retained longer.

9. Your Choices and Controls

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing of personal data. You can manage workspace access, disconnect integrations, revoke developer tokens, delete your account, and opt out of marketing communications. Contact us to exercise a right that is not available in-product.

10. Cookies

We use essential cookies for authentication and core functionality, and analytics cookies to understand service usage. You can control cookies through your browser settings, but disabling essential cookies may affect functionality.

11. International Data Transfers

Your data may be transferred to and processed in countries where our service providers operate, including the United States. We use appropriate safeguards where required by applicable law.

12. Security

We use industry-standard safeguards including encryption, secure authentication, access controls, and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

13. Regional Provisions

Users in the Republic of Korea, EU/EEA, United Kingdom, California, and other jurisdictions may have additional statutory privacy rights. These rights remain available where applicable. We do not sell personal information.

14. Changes and Contact

We may update this Privacy Policy by posting a revised version and changing the last-updated date. For privacy questions or requests, email contact@aeolo.io.

Questions about this page? Email contact@aeolo.io.