Legal Document

Privacy Policy

Effective: January 1, 2025 Last updated: July 2026 Applies to all users
Floating IQ ("we", "us", "our") operates as a marketing analysis platform. This policy explains what data we collect, how we use it, and your rights. By using our service you agree to this policy.
01

Information we collect

We collect information you provide directly, data from connected platforms, and technical data generated by using our service.

TypeExamplesSource
Account dataName, email address, password hashYou, at signup
Usage dataPages visited, audits run, features usedAutomatically
Audit inputWebsite URLs, uploaded files, chat promptsYou, when using the product
OAuth tokensAccess and refresh tokens for connected platformsThird-party OAuth flow
Platform dataAd campaigns, search data, email metadataConnected integrations
Technical dataIP address, browser type, device infoAutomatically
02

Third-party integrations

When you connect external platforms, we access your data on those platforms only to provide the features you request. We access only the permissions you explicitly grant during the OAuth flow.

PlatformData accessedPurpose
Google AdsAccount info, campaigns, ad groups, ads, keywords, negative keywords, conversion data, budgets, and performance metricsRetrieve and display data, generate AI-powered audits and recommendations, and support campaign management workflows initiated or explicitly approved by you.
Meta AdsCampaigns, ad sets, ad performanceAudit and recommendations
Google Search ConsoleSearch queries, page performanceSEO analysis
GmailEmail metadata, thread contentAI marketing analysis and insights
RedditPublic posts, subreddit dataMarket research

We do not store platform data longer than necessary to display it to you. You can disconnect any integration at any time from your Integrations page.

03

Google API User Data

Floating IQ accesses Google APIs to provide our marketing analysis features. We strictly limit our access to what is necessary.

Data Accessed

Google APIScopes RequestedData AccessedWhen & Why
Google Adsadwords READ: Campaign names, status, budget, resource names; Ad group names, status, performance metrics; Keyword text, match type, status, quality scores, performance metrics; Search term reports; Account-level metrics (CTR, CPC, ROAS, conversions).

WRITTEN (only after user approval): Campaign daily budget (amount_micros); Campaign status (PAUSED / ENABLED); Ad group criterion status (keyword pause/enable); Campaign-level and ad-group-level negative keyword criteria; Ad group ads (Responsive Search Ads); Campaign bidding strategy (target_cpa, target_roas); Campaign geo targeting criteria (location add/remove).
When you sync your Ads account, to generate AI recommendations and support campaign management actions initiated or explicitly approved by you. Floating IQ does not autonomously change your Google Ads account without your authorization.
Google Search Consolewebmasters.readonlySearch queries, page performanceWhen you sync GSC, to analyze SEO and keyword opportunities.
Gmailgmail.readonlyEmail metadata, threadsWhen you sync Gmail, to provide AI email marketing summaries.
Google Identityopenid, userinfo.emailEmail address, basic profileDuring login, to authenticate your account securely.

Data Usage & Third-Party Processing

Floating IQ processes Google data exclusively to perform the features you request (e.g., generating marketing reports and AI analysis). To provide these features, we use Large Language Models provided by third-party processors, primarily OpenAI. Your Google data is sent to OpenAI strictly for processing your specific requests. OpenAI does not use your data to train their models.

AI Processing and Recommendations: AI recommendations are advisory only until explicitly approved by the user. The AI never autonomously executes mutations. All AI-suggested changes are presented in an Approve/Reject interface, ensuring you maintain complete control over your accounts.

Data Sharing

We never sell your Google data. We never use your Google data for serving advertisements. Your data is only shared with subprocessors (like OpenAI for AI processing and Supabase for database storage) required to deliver the core functionality of Floating IQ.

Data Storage & Retention

Your Google OAuth tokens are encrypted at rest using AES-256 and stored securely in our database. We retain your cached Google data only as long as necessary to provide the service. If you disconnect your Google account, all associated OAuth tokens are revoked and deleted immediately, and cached data is deleted within 7 days.

04

Google Limited Use Policy

Floating IQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Floating IQ ensures that only the minimum Google user data required to provide the requested feature is accessed and processed.

Floating IQ does not use data obtained through Google Workspace APIs to develop, improve, or train generalized AI or machine learning models.

Revoking Google Access

You can revoke Floating IQ's access to your Google account at any time. To do so:

  • From our App: Navigate to the Integrations page and click "Disconnect" on any connected Google service.
  • From Google: Go to your Google Account Security settings and remove access for Floating IQ.

When you revoke access, we immediately delete all associated OAuth tokens and initiate the deletion of your cached Google data from our servers.

05

Explicit User Approval for Google Ads Mutations

Floating IQ NEVER performs Google Ads mutations automatically. Every action requires explicit user approval via an Approve/Reject UI before execution. Rejected or unapproved actions are never executed.

The following is a list of ALL supported mutations:

  • Budget updates
  • Campaign pause / resume
  • Keyword pause / resume
  • Negative keyword management
  • Responsive Search Ad creation
  • Geo targeting updates
  • Smart bidding (Target CPA / Target ROAS) updates
06

How we use your data

  • To run website audits, generate scores, and produce marketing recommendations
  • To power AI analysis using OpenAI's API — your data is sent to OpenAI for processing
  • To display dashboards showing your connected platform metrics
  • To maintain your account and authenticate you
  • To send service-related emails (never marketing without consent)
  • To detect errors, improve reliability, and debug issues
  • To comply with legal obligations
We do not sell your data. We do not use your data to train AI models. We do not share your marketing data with other users or third parties for advertising.
07

Data storage

Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. We strictly manage OAuth tokens with the following practices:

  • Both access tokens AND refresh tokens are stored to maintain your active connection.
  • AES-256 encryption is used for all stored credentials.
  • Tokens are deleted immediately and permanently upon account disconnect.
  • No credentials are ever logged or exposed in plaintext.

Our backend runs on Render. Our frontend is served as a static site. Both are hosted in the United States.

08

Data sharing

We share your data only with the following sub-processors, and only to deliver the service:

Sub-processorPurpose
OpenAIAI analysis and content generation
SupabaseDatabase and authentication
RenderBackend hosting

We may disclose data if required by law, court order, or to protect our rights or the safety of users.

09

Data retention

  • Account data: retained while your account is active, deleted within 30 days of account deletion request
  • Audit results: retained for your account history, deleted with your account
  • OAuth tokens: deleted immediately when you disconnect an integration
  • Platform data (cached): deleted within 7 days of disconnection
  • Usage logs: retained for 90 days for debugging purposes
10

Your rights

Depending on your location, you may have the following rights:

  • Access — request a copy of all data we hold about you
  • Correction — update inaccurate data
  • Deletion — request deletion of your account and all associated data
  • Portability — receive your data in a machine-readable format
  • Objection — object to certain types of processing
  • Withdrawal — disconnect any integration and revoke access at any time

To exercise any right, email us at the address in the Contact section. We will respond within 30 days.

11

Export Your Data

Users may request an export of their data at any time before deletion. Data exports include all provided account information, generated reports, and cached integrations data. Requests can be made by contacting us at support@floatingiq.com.

12

Security

We implement industry-standard security measures: OAuth tokens encrypted at rest, HTTPS-only connections, Supabase Row Level Security so users can only access their own data, and no storage of plaintext credentials.

No system is perfectly secure. If you discover a security vulnerability, please contact us immediately at the address below.

13

Cookies

We use minimal, necessary cookies only: session authentication tokens and preferences. We do not use advertising cookies or third-party tracking pixels. We do not use Google Analytics or similar tracking tools.

14

Children

Floating IQ is not directed at anyone under the age of 16. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us and we will delete it immediately.

15

Changes to this policy

We may update this policy from time to time. We will notify you by email and update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the new policy.

16

Contact us

For any privacy-related questions, data requests, or to report a concern:

Floating IQ

Contact us: floatingiq.22@gmail.com