AudaeoPrivacy Policy

Privacy Policy

Last updated: April 16, 2026

Overview

The AEO Audit ("Service") is operated by Impulse Creative ("we", "us", "our"). This privacy policy explains how we collect, use, store, and protect your data when you use our website audit and CRM insights platform at app.audaeo.com.

We take data privacy seriously. Your CRM data is never sold, shared with third parties for marketing, or used to train AI models. It is processed solely to generate audit insights for your use.

Information We Collect

Account Information

  • Email address — used for authentication and to send audit completion notifications
  • Name and company — optional profile fields you provide in Settings
  • CRM Portal ID — stored when you authenticate via OAuth to identify your CRM portal

Website Audit Data

  • Page URLs and content — scraped to perform the CLEAR Framework analysis
  • Page content (markdown) — stored for analysis, schema generation, and content brief creation
  • CLEAR scores and analysis — AI-generated audit results for each page
  • Keyword rankings — pulled for SEO analysis
  • Query fan-out data — AI-simulated buyer search queries and coverage analysis
  • Schema markup — JSON-LD generated for your pages
  • Content briefs — AI-generated content recommendations

CRM Data (Optional — GTM & AEO Tier)

If you connect your CRM, we access the following data through a secure OAuth 2.1 connection with PKCE. This data is pulled from your portal only and scoped to the last 90 days:

  • Deals — name, amount, stage, close date, industry, pipeline, source, deal type, closed-lost reason
  • Contacts — email, job title, lifecycle stage, lead status, traffic source, first/last touch URLs, page views, conversion events
  • Companies — name, industry, domain, employee count, revenue, geography
  • Tickets — subject, category, priority, pipeline, resolution, time to close
  • Meetings — title, outcome, notes
  • Notes — note content

We do not access: email content/bodies, call recordings, file attachments, financial account data, payment information, or any data from portals other than the one you explicitly authorize.

How Data is Stored

Database

All data is stored in a PostgreSQL database hosted in the US East region (AWS). The database is encrypted at rest and all connections use SSL/TLS encryption in transit.

Token Encryption

All OAuth tokens (access tokens, refresh tokens) are encrypted using AES-256-GCM before storage. Each token has a unique initialization vector (IV). Tokens are never stored in plaintext and are never exposed to the frontend.

Session Management

User sessions are managed via encrypted HttpOnly cookies with Secure and SameSite=Lax flags. Session data is AES-256-GCM encrypted in the cookie. Sessions do not use localStorage or client-side storage.

CRM Data Caching

CRM data is cached in our database as JSON to avoid repeated API calls. This cached data is:

  • Overwritten each time you refresh CRM data (not appended)
  • Deleted when the audit is deleted
  • Scoped to the specific audit — not shared across audits or users
  • Used only for generating AI recommendations and Ideal Customer Avatars

File Storage

We do not store uploaded files. Page content is scraped on-demand and stored as markdown text in the database. Screenshots captured during scraping are not persisted.

How Data is Used

  • Website analysis — page content is sent to AI services for CLEAR Framework scoring, query fan-out simulation, content brief generation, and schema markup generation
  • CRM insights — CRM data is sent to AI services to generate GTM recommendations, buyer personas, and Ideal Customer Avatars
  • Contact sync — your profile (name, company) is synced to a contact record in our CRM for internal use
  • Audit completion email — your email is used to send a notification when your audit completes

Third-Party Services

We use the following categories of third-party services to operate the platform:

  • AI analysis services — for CLEAR scoring, recommendations, fan-out simulation, and content briefs
  • Web scraping services — to retrieve publicly available page content for analysis
  • SEO data providers — for keyword ranking and search volume data
  • CRM integration — secure OAuth connection to your CRM portal
  • Email delivery — for magic link login and audit completion emails
  • Cloud hosting — application hosting and database hosting
  • Background job processing — for scheduling audit analysis batches

AI Data Processing

When processing your data with AI services:

  • Page content (HTML/markdown) is sent for CLEAR scoring — this includes the visible content of your web pages
  • CRM data sent to AI is aggregated and summarized — individual contact emails, names, or personal identifiers are not included. We send distributions (e.g., "VP Operations: 12, Director IT: 8") not individual records
  • AI API services do not use customer data for model training per their respective terms of service
  • AI-generated results (scores, recommendations, personas) are stored in our database and attributed to your audit

Data Retention

  • Audit data — retained until you delete the audit or your account
  • CRM cached data — retained until you re-pull (overwritten) or delete the audit
  • OAuth tokens — retained until you disconnect the integration or tokens expire
  • Login tokens — expire after 15 minutes, single use
  • Session cookies — expire after 30 days

Data Deletion

You can delete your audit data at any time from the app. When an audit is deleted, all associated data is permanently removed including page analyses, keywords, queries, content briefs, CRM insights, recommendations, Ideal Customer Avatars, and schema markup.

To request deletion of your user account and all associated data, contact our support team at impulsecreative.com/contact.

MCP (Model Context Protocol) Access

The AEO Audit provides an MCP server that allows AI assistants to access your audit data programmatically. This access:

  • Requires an API key that you control
  • Only exposes data from audits you have access to
  • Does not grant write access to your data or CRM
  • Can be revoked by changing your API key

Security

  • All data in transit encrypted via HTTPS/TLS
  • All data at rest encrypted
  • OAuth tokens encrypted with AES-256-GCM before database storage
  • Session cookies are HttpOnly, Secure, SameSite=Lax
  • PKCE (Proof Key for Code Exchange) used for CRM OAuth
  • Background job endpoints verified via cryptographic signatures
  • Rate limiting on authentication endpoints
  • Admin functions restricted to authorized personnel

Your Rights

You have the right to:

  • Access your stored data (available in-app and via CSV export)
  • Delete your audit data at any time
  • Disconnect your CRM integration
  • Request deletion of your account
  • Opt out of notification emails

Contact

For privacy questions, data requests, or concerns, contact our support team at impulsecreative.com/contact.