Legal Document

Privacy Policy

Effective: January 1, 2025 Last updated: June 2025 Applies to all users
Floating IQ ("we", "us", "our") operates as a marketing analysis platform. This policy explains what data we collect, how we use it, and your rights. By using our service you agree to this policy.
01

Information we collect

We collect information you provide directly, data from connected platforms, and technical data generated by using our service.

TypeExamplesSource
Account dataName, email address, password hashYou, at signup
Usage dataPages visited, audits run, features usedAutomatically
Audit inputWebsite URLs, uploaded files, chat promptsYou, when using the product
OAuth tokensAccess and refresh tokens for connected platformsThird-party OAuth flow
Platform dataAd campaigns, search data, email metadataConnected integrations
Technical dataIP address, browser type, device infoAutomatically
02

Third-party integrations

When you connect external platforms, we access your data on those platforms only to provide the features you request. We access only the permissions you explicitly grant during the OAuth flow.

PlatformData accessedPurpose
Google AdsCampaigns, keywords, performance metricsAudit and recommendations
Meta AdsCampaigns, ad sets, ad performanceAudit and recommendations
Google Search ConsoleSearch queries, page performanceSEO analysis
GmailEmail metadata, thread contentAI marketing analysis and insights
Google SheetsSpreadsheet content you selectExport and analysis
RedditPublic posts, subreddit dataMarket research

We do not store platform data longer than necessary to display it to you. You can disconnect any integration at any time from your Integrations page.

03

How we use your data

  • To run website audits, generate scores, and produce marketing recommendations
  • To power AI analysis using OpenAI's API — your data is sent to OpenAI for processing
  • To display dashboards showing your connected platform metrics
  • To maintain your account and authenticate you
  • To send service-related emails (never marketing without consent)
  • To detect errors, improve reliability, and debug issues
  • To comply with legal obligations
We do not sell your data. We do not use your data to train AI models. We do not share your marketing data with other users or third parties for advertising.
04

Data storage

Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. OAuth tokens are encrypted at rest using AES-256. We store only the presence of API keys — never the key values themselves in logs or error reports.

Our backend runs on Render. Our frontend is served as a static site. Both are hosted in the United States.

05

Data sharing

We share your data only with the following sub-processors, and only to deliver the service:

Sub-processorPurpose
OpenAIAI analysis and content generation
SupabaseDatabase and authentication
RenderBackend hosting

We may disclose data if required by law, court order, or to protect our rights or the safety of users.

06

Data retention

  • Account data: retained while your account is active, deleted within 30 days of account deletion request
  • Audit results: retained for your account history, deleted with your account
  • OAuth tokens: deleted immediately when you disconnect an integration
  • Platform data (cached): deleted within 7 days of disconnection
  • Usage logs: retained for 90 days for debugging purposes
07

Your rights

Depending on your location, you may have the following rights:

  • Access — request a copy of all data we hold about you
  • Correction — update inaccurate data
  • Deletion — request deletion of your account and all associated data
  • Portability — receive your data in a machine-readable format
  • Objection — object to certain types of processing
  • Withdrawal — disconnect any integration and revoke access at any time

To exercise any right, email us at the address in the Contact section. We will respond within 30 days.

08

Security

We implement industry-standard security measures: OAuth tokens encrypted at rest, HTTPS-only connections, Supabase Row Level Security so users can only access their own data, and no storage of plaintext credentials.

No system is perfectly secure. If you discover a security vulnerability, please contact us immediately at the address below.

09

Cookies

We use minimal, necessary cookies only: session authentication tokens and preferences. We do not use advertising cookies or third-party tracking pixels. We do not use Google Analytics or similar tracking tools.

10

Children

Floating IQ is not directed at anyone under the age of 16. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us and we will delete it immediately.

11

Changes to this policy

We may update this policy from time to time. We will notify you by email and update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the new policy.

12

Contact us

For any privacy-related questions, data requests, or to report a concern:

Floating IQ

Contact us: floatingiq.22@gmail.com