Information we collect
We collect information you provide directly, data from connected platforms, and technical data generated by using our service.
| Type | Examples | Source |
|---|---|---|
| Account data | Name, email address, and an account identifier (UID) | Firebase Authentication (Google sign-in or email/password). Your password is managed by Firebase — we do not store it. |
| Workspace data | Business/workspace names, website URLs, and persistent per-workspace "business memory" the AI builds from your conversations and data | You, when you create and use workspaces |
| Usage data | Audits run, chats, features used | Automatically |
| Chat & audit input | Website URLs, uploaded files, chat prompts and messages | You, when using the product (web app or Telegram) |
| OAuth tokens | Access and refresh tokens for connected platforms | Third-party OAuth flow |
| Platform data | Ad campaigns, search data, email metadata, Notion pages | Connected integrations |
| Telegram link data | Telegram user ID, chat ID, username, and the workspace linked to your Telegram (only if you connect Telegram) | Telegram, when you link it |
| Technical data | IP address, browser type, device info | Automatically |
Third-party integrations
When you connect external platforms, we access your data on those platforms only to provide the features you request. We access only the permissions you explicitly grant during the OAuth flow.
| Platform | Data accessed | Access | Purpose |
|---|---|---|---|
| Google Ads | Account info, campaigns, ad groups, ads, keywords, negative keywords, conversion data, budgets, and performance metrics | Read + write (write only after your explicit approval) | Retrieve and display data, generate AI-powered audits and recommendations, and support campaign management actions you initiate or explicitly approve. |
| Meta Ads | Campaigns, ad sets, ad performance | Read-only | Audit and AI recommendations |
| Google Search Console | Search queries, page performance | Read-only | SEO analysis |
| Gmail | Email metadata, thread content | Read-only | AI marketing analysis and insights |
| Notion | Pages and databases you authorize | Read + create pages (page creation only after your explicit approval) | Read reference material and, when you approve it, create pages for documentation and tracking |
We do not store platform data longer than necessary to provide the features you use. You can disconnect any integration at any time from your Integrations page. Each integration is connected within a specific workspace and is only used for that workspace.
Telegram (optional AI assistant interface)
Telegram is an optional way to chat with the same Floating IQ AI assistant you use on the web — it is not a separate product, AI, or data store. Linking Telegram is entirely your choice, and the assistant, memory, and integrations are unchanged whether you use the web app or Telegram.
- How linking works: From the Integrations page we generate a secure, single-use, time-limited token and open our Telegram bot with it. When you press Start, the bot links your Telegram account to your Floating IQ account.
- What we store: your Telegram user ID, chat ID, username (if set), the workspace currently linked to your Telegram, and the messages you exchange with the assistant (stored as part of your workspace chat history, the same way web chats are stored).
- What it can access: messages sent through Telegram are answered using your currently selected workspace's data, connected integrations, and long-term memory. You can switch workspaces from Telegram, and the assistant only ever accesses workspaces you own.
- Processing: messages are transmitted through Telegram's servers (subject to Telegram's own privacy policy) and processed by our AI provider (OpenAI) to generate replies.
- Duplicate protection & disconnect: a Telegram account can be linked to only one Floating IQ account. You can unlink at any time from the Integrations page, which removes the stored Telegram link.
Workspaces & data isolation
Floating IQ is multi-tenant. Each user can have multiple businesses/workspaces, and all workspace-owned data — integrations, cached platform data, chat history, and business memory — is strictly isolated per workspace and per user. Every request resolves an active workspace, ownership is verified against your account, and database access is scoped so one workspace can never read another workspace's data. This isolation applies identically whether you access the assistant from the web app or from Telegram.
Google API User Data
Floating IQ accesses Google APIs to provide our marketing analysis features. We strictly limit our access to what is necessary.
Data Accessed
| Google API | Scopes Requested | Data Accessed | When & Why |
|---|---|---|---|
| Google Ads | adwords |
READ: Campaign names, status, budget, resource names; Ad group names, status, performance metrics; Keyword text, match type, status, quality scores, performance metrics; Search term reports; Account-level metrics (CTR, CPC, ROAS, conversions). WRITTEN (only after user approval): Campaign daily budget (amount_micros); Campaign status (PAUSED / ENABLED); Ad group criterion status (keyword pause/enable); Campaign-level and ad-group-level negative keyword criteria; Ad group ads (Responsive Search Ads); Campaign bidding strategy (target_cpa, target_roas); Campaign geo targeting criteria (location add/remove). | When you sync your Ads account, to generate AI recommendations and support campaign management actions initiated or explicitly approved by you. Floating IQ does not autonomously change your Google Ads account without your authorization. |
| Google Search Console | webmasters.readonly | Search queries, page performance | When you sync GSC, to analyze SEO and keyword opportunities. |
| Gmail | gmail.readonly | Email metadata, threads | When you sync Gmail, to provide AI email marketing summaries. |
| Google Identity | openid, userinfo.email | Email address, basic profile | During login, to authenticate your account securely. |
Data Usage & Third-Party Processing
Floating IQ processes Google data exclusively to perform the features you request (e.g., generating marketing reports and AI analysis). To provide these features, we use Large Language Models provided by third-party processors, primarily OpenAI. Your Google data is sent to OpenAI strictly for processing your specific requests. OpenAI does not use your data to train their models.
AI Processing and Recommendations: AI recommendations are advisory only until explicitly approved by the user. The AI never autonomously executes mutations. All AI-suggested changes are presented in an Approve/Reject interface, ensuring you maintain complete control over your accounts.
Data Sharing
We never sell your Google data. We never use your Google data for serving advertisements. Your data is only shared with subprocessors (like OpenAI for AI processing and Supabase for database storage) required to deliver the core functionality of Floating IQ.
Data Storage & Retention
Your Google OAuth tokens are encrypted at rest using AES-256 and stored securely in our database. We retain your cached Google data only as long as necessary to provide the service. If you disconnect your Google account, all associated OAuth tokens are revoked and deleted immediately, and cached data is deleted within 7 days.
Google Limited Use Policy
Floating IQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Floating IQ ensures that only the minimum Google user data required to provide the requested feature is accessed and processed.
Floating IQ does not use data obtained through Google Workspace APIs to develop, improve, or train generalized AI or machine learning models.
Revoking Google Access
You can revoke Floating IQ's access to your Google account at any time. To do so:
- From our App: Navigate to the Integrations page and click "Disconnect" on any connected Google service.
- From Google: Go to your Google Account Security settings and remove access for Floating IQ.
When you revoke access, we immediately delete all associated OAuth tokens and initiate the deletion of your cached Google data from our servers.
Explicit User Approval for Google Ads Mutations
Floating IQ NEVER performs Google Ads mutations automatically. Every action requires explicit user approval via an Approve/Reject UI before execution. Rejected or unapproved actions are never executed.
The following is a list of ALL supported mutations:
- Budget updates
- Campaign pause / resume
- Keyword pause / resume
- Negative keyword management
- Responsive Search Ad creation
- Geo targeting updates
- Smart bidding (Target CPA / Target ROAS) updates
How we use your data
- To run website audits, generate scores, and produce marketing recommendations
- To power AI analysis using OpenAI's API — your data is sent to OpenAI for processing
- To display dashboards showing your connected platform metrics
- To maintain your account and authenticate you
- To send service-related emails (never marketing without consent)
- To detect errors, improve reliability, and debug issues
- To comply with legal obligations
Data storage
Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. We strictly manage OAuth tokens with the following practices:
- Both access tokens AND refresh tokens are stored to maintain your active connection.
- AES-256 encryption is used for all stored credentials.
- Tokens are deleted immediately and permanently upon account disconnect.
- No credentials are ever logged or exposed in plaintext.
Account authentication is handled by Firebase Authentication (Google); we verify Firebase-issued tokens on our backend and do not store your password. Our backend runs on Render. Our frontend is served as a static site. Both are hosted in the United States.
Data sharing
We share your data only with the following sub-processors, and only to deliver the service:
| Sub-processor | Purpose |
|---|---|
| OpenAI | AI analysis and content generation |
| Supabase | PostgreSQL database storage |
| Firebase (Google) | Account authentication (Firebase Authentication) |
| Render | Backend hosting |
| Telegram | Message delivery for the optional Telegram interface (only if you link Telegram) |
We may disclose data if required by law, court order, or to protect our rights or the safety of users.
Data retention
- Account data: retained while your account is active, deleted within 30 days of account deletion request
- Audit results: retained for your account history, deleted with your account
- OAuth tokens: deleted immediately when you disconnect an integration
- Platform data (cached): deleted within 7 days of disconnection
- Usage logs: retained for 90 days for debugging purposes
Your rights
Depending on your location, you may have the following rights:
- Access — request a copy of all data we hold about you
- Correction — update inaccurate data
- Deletion — request deletion of your account and all associated data
- Portability — receive your data in a machine-readable format
- Objection — object to certain types of processing
- Withdrawal — disconnect any integration and revoke access at any time
To exercise any right, email us at the address in the Contact section. We will respond within 30 days.
Export Your Data
Users may request an export of their data at any time before deletion. Data exports include all provided account information, generated reports, and cached integrations data. Requests can be made by contacting us at floatingiq.22@gmail.com.
Security
We implement industry-standard security measures: OAuth tokens encrypted at rest, HTTPS-only connections, Supabase Row Level Security so users can only access their own data, and no storage of plaintext credentials.
No system is perfectly secure. If you discover a security vulnerability, please contact us immediately at the address below.
Cookies & local storage
We use only what is necessary to keep you signed in and remember basic preferences. Your authentication session is managed by Firebase, and we store lightweight preferences (such as your active workspace) in your browser's local storage. We do not use advertising cookies or third-party tracking pixels, and we do not use Google Analytics or similar tracking tools.
Children
Floating IQ is not directed at anyone under the age of 16. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us and we will delete it immediately.
Changes to this policy
We may update this policy from time to time. We will notify you by email and update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the new policy.
Contact us
For any privacy-related questions, data requests, or to report a concern:
Floating IQ
Contact us: floatingiq.22@gmail.com