Information we collect
We collect information you provide directly, data from connected platforms, and technical data generated by using our service.
| Type | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash | You, at signup |
| Usage data | Pages visited, audits run, features used | Automatically |
| Audit input | Website URLs, uploaded files, chat prompts | You, when using the product |
| OAuth tokens | Access and refresh tokens for connected platforms | Third-party OAuth flow |
| Platform data | Ad campaigns, search data, email metadata | Connected integrations |
| Technical data | IP address, browser type, device info | Automatically |
Third-party integrations
When you connect external platforms, we access your data on those platforms only to provide the features you request. We access only the permissions you explicitly grant during the OAuth flow.
| Platform | Data accessed | Purpose |
|---|---|---|
| Google Ads | Account info, campaigns, ad groups, ads, keywords, negative keywords, conversion data, budgets, and performance metrics | Retrieve and display data, generate AI-powered audits and recommendations, and support campaign management workflows initiated or explicitly approved by you. |
| Meta Ads | Campaigns, ad sets, ad performance | Audit and recommendations |
| Google Search Console | Search queries, page performance | SEO analysis |
| Gmail | Email metadata, thread content | AI marketing analysis and insights |
| Public posts, subreddit data | Market research |
We do not store platform data longer than necessary to display it to you. You can disconnect any integration at any time from your Integrations page.
Google API User Data
Floating IQ accesses Google APIs to provide our marketing analysis features. We strictly limit our access to what is necessary.
Data Accessed
| Google API | Scopes Requested | Data Accessed | When & Why |
|---|---|---|---|
| Google Ads | adwords |
READ: Campaign names, status, budget, resource names; Ad group names, status, performance metrics; Keyword text, match type, status, quality scores, performance metrics; Search term reports; Account-level metrics (CTR, CPC, ROAS, conversions). WRITTEN (only after user approval): Campaign daily budget (amount_micros); Campaign status (PAUSED / ENABLED); Ad group criterion status (keyword pause/enable); Campaign-level and ad-group-level negative keyword criteria; Ad group ads (Responsive Search Ads); Campaign bidding strategy (target_cpa, target_roas); Campaign geo targeting criteria (location add/remove). | When you sync your Ads account, to generate AI recommendations and support campaign management actions initiated or explicitly approved by you. Floating IQ does not autonomously change your Google Ads account without your authorization. |
| Google Search Console | webmasters.readonly | Search queries, page performance | When you sync GSC, to analyze SEO and keyword opportunities. |
| Gmail | gmail.readonly | Email metadata, threads | When you sync Gmail, to provide AI email marketing summaries. |
| Google Identity | openid, userinfo.email | Email address, basic profile | During login, to authenticate your account securely. |
Data Usage & Third-Party Processing
Floating IQ processes Google data exclusively to perform the features you request (e.g., generating marketing reports and AI analysis). To provide these features, we use Large Language Models provided by third-party processors, primarily OpenAI. Your Google data is sent to OpenAI strictly for processing your specific requests. OpenAI does not use your data to train their models.
AI Processing and Recommendations: AI recommendations are advisory only until explicitly approved by the user. The AI never autonomously executes mutations. All AI-suggested changes are presented in an Approve/Reject interface, ensuring you maintain complete control over your accounts.
Data Sharing
We never sell your Google data. We never use your Google data for serving advertisements. Your data is only shared with subprocessors (like OpenAI for AI processing and Supabase for database storage) required to deliver the core functionality of Floating IQ.
Data Storage & Retention
Your Google OAuth tokens are encrypted at rest using AES-256 and stored securely in our database. We retain your cached Google data only as long as necessary to provide the service. If you disconnect your Google account, all associated OAuth tokens are revoked and deleted immediately, and cached data is deleted within 7 days.
Google Limited Use Policy
Floating IQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Floating IQ ensures that only the minimum Google user data required to provide the requested feature is accessed and processed.
Floating IQ does not use data obtained through Google Workspace APIs to develop, improve, or train generalized AI or machine learning models.
Revoking Google Access
You can revoke Floating IQ's access to your Google account at any time. To do so:
- From our App: Navigate to the Integrations page and click "Disconnect" on any connected Google service.
- From Google: Go to your Google Account Security settings and remove access for Floating IQ.
When you revoke access, we immediately delete all associated OAuth tokens and initiate the deletion of your cached Google data from our servers.
Explicit User Approval for Google Ads Mutations
Floating IQ NEVER performs Google Ads mutations automatically. Every action requires explicit user approval via an Approve/Reject UI before execution. Rejected or unapproved actions are never executed.
The following is a list of ALL supported mutations:
- Budget updates
- Campaign pause / resume
- Keyword pause / resume
- Negative keyword management
- Responsive Search Ad creation
- Geo targeting updates
- Smart bidding (Target CPA / Target ROAS) updates
How we use your data
- To run website audits, generate scores, and produce marketing recommendations
- To power AI analysis using OpenAI's API — your data is sent to OpenAI for processing
- To display dashboards showing your connected platform metrics
- To maintain your account and authenticate you
- To send service-related emails (never marketing without consent)
- To detect errors, improve reliability, and debug issues
- To comply with legal obligations
Data storage
Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. We strictly manage OAuth tokens with the following practices:
- Both access tokens AND refresh tokens are stored to maintain your active connection.
- AES-256 encryption is used for all stored credentials.
- Tokens are deleted immediately and permanently upon account disconnect.
- No credentials are ever logged or exposed in plaintext.
Our backend runs on Render. Our frontend is served as a static site. Both are hosted in the United States.
Data sharing
We share your data only with the following sub-processors, and only to deliver the service:
| Sub-processor | Purpose |
|---|---|
| OpenAI | AI analysis and content generation |
| Supabase | Database and authentication |
| Render | Backend hosting |
We may disclose data if required by law, court order, or to protect our rights or the safety of users.
Data retention
- Account data: retained while your account is active, deleted within 30 days of account deletion request
- Audit results: retained for your account history, deleted with your account
- OAuth tokens: deleted immediately when you disconnect an integration
- Platform data (cached): deleted within 7 days of disconnection
- Usage logs: retained for 90 days for debugging purposes
Your rights
Depending on your location, you may have the following rights:
- Access — request a copy of all data we hold about you
- Correction — update inaccurate data
- Deletion — request deletion of your account and all associated data
- Portability — receive your data in a machine-readable format
- Objection — object to certain types of processing
- Withdrawal — disconnect any integration and revoke access at any time
To exercise any right, email us at the address in the Contact section. We will respond within 30 days.
Export Your Data
Users may request an export of their data at any time before deletion. Data exports include all provided account information, generated reports, and cached integrations data. Requests can be made by contacting us at support@floatingiq.com.
Security
We implement industry-standard security measures: OAuth tokens encrypted at rest, HTTPS-only connections, Supabase Row Level Security so users can only access their own data, and no storage of plaintext credentials.
No system is perfectly secure. If you discover a security vulnerability, please contact us immediately at the address below.
Cookies
We use minimal, necessary cookies only: session authentication tokens and preferences. We do not use advertising cookies or third-party tracking pixels. We do not use Google Analytics or similar tracking tools.
Children
Floating IQ is not directed at anyone under the age of 16. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us and we will delete it immediately.
Changes to this policy
We may update this policy from time to time. We will notify you by email and update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the new policy.
Contact us
For any privacy-related questions, data requests, or to report a concern:
Floating IQ
Contact us: floatingiq.22@gmail.com