App & SaaS Platform

Privacy Policy for the AlwaysRight App

Specific notices for registered users of the AlwaysRight platform and AI agents. Last updated: August 2026.

Just visiting our marketing website?
Go to website privacy policy

1. Scope of the App Privacy Policy

This privacy policy applies to the registration, sign-in, and use of the AlwaysRight web application (SaaS platform), its AI agent workflows, databases, and integrations. It supplements the general website privacy policy with specific information on data processing within the platform.

2. Data Controller

Tim Geier

Julius-Frank-Straße 69

28865 Lilienthal

Germany

Phone: 0176 53026544

Email: hello@alwaysright.de

3. Account & Login (Supabase Auth, Google OAuth)

3.1 User Account & Registration

To use the AlwaysRight platform, we process your email address and a password (stored exclusively as a cryptographic hash). Session and account management is handled via Supabase Auth. The legal basis is Art. 6(1)(b) GDPR (performance of a contract).

3.2 Single Sign-On via Google

When signing in via "Sign in with Google", Google Ireland Limited transmits your email address, name, and Google account ID to us. No further profile data is requested from your Google account. The legal basis is Art. 6(1)(a) GDPR (consent).

4. Handling of Google User Data (Google User Data Policy)

Transparency in accordance with the Google API Services (Search Console, Analytics 4 & Google Ads) & OAuth Client Requirements policies

4.1 Google User Data We Access

When you sign in via Google or connect Google services to AlwaysRight, we access only the following data that you have explicitly authorized:

  • Google Sign-In / profile data: email address, name, profile picture URL, and unique Google account ID (sub).
  • Google Search Console API (optional, read-only): list of connected sites/properties, performance metrics (impressions, clicks, CTR, average position), and search query analytics (Scope: webmasters.readonly).
  • Google Analytics 4 API (optional, read-only): analytics properties, session data, page views, conversion events, and traffic sources (Scope: analytics.readonly).
  • Google Ads API (optional, read-only): accessible ad accounts (Customer IDs, Login Customer IDs / MCC), campaign structures, ad groups, keywords (match types, quality scores), search terms reports, and performance & cost metrics (impressions, clicks, CTR, average CPC, total spend, conversions) (Scope: adwords). AlwaysRight performs read-only queries only and never modifies bids, budgets, or campaigns without explicit human action.

4.2 How Your App Uses Google User Data

The Google user data we collect is used by AlwaysRight exclusively for the following purposes:

  • Authentication and identity verification to provide and secure your user account.
  • Displaying SEO & SEA dashboards, ranking statistics, traffic trends, and ad performance analytics within the app.
  • Generating AI-powered content, keyword, and SEA recommendations (such as discovering SEO/SEA keyword synergies, finding wasted ad spend, and suggesting negative keywords) to optimize your overall search presence.

Note: Google user data is used exclusively to provide and improve user-facing features of AlwaysRight and is not processed for any unrelated or undisclosed purpose.

4.3 Sharing & Disclosure of Data & the Google Limited Use Policy

We do not sell, rent, or share your Google user data with third parties under any circumstances. Data is only transmitted to necessary technical infrastructure providers (e.g., Supabase for database hosting, Vercel for application hosting) to deliver our service, under strict data processing agreements (DPAs).

Google user data is never used for advertising, data trading, or to train general-purpose AI models of third-party providers.

Google API Services User Data Policy Compliance Statement

"AlwaysRight's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements."

4.4 Data Protection & Security Mechanisms

We use modern technical and organizational security measures to protect your sensitive Google user data:

  • Encryption in transit: All data transfers between user, AlwaysRight, and Google APIs take place over encrypted HTTPS/TLS 1.3 connections.
  • Encryption at rest: Sensitive Google OAuth access and refresh tokens (Search Console, Analytics 4, Google Ads) are stored encrypted in our database using the AES-256-GCM algorithm.
  • Secure secret management: Developer tokens and server secrets are strictly managed as server-side environment variables and never exposed to the client.
  • Access restrictions & location: Strict role separation (principle of least privilege). Database storage takes place in ISO 27001-certified data centers within the European Union (Frankfurt, Germany).

4.5 Retention, Revocation & Deletion of Google Data

Google user data is only stored for as long as your user account is active or the connection to Google services persists.

Revoking access: You can disconnect Google services (Search Console, Analytics, Ads) at any time:

  1. Directly in the AlwaysRight app settings under "Connectors" or "Integrations".
  2. Or in your Google account under Google security settings (third-party apps with account access).

Final deletion: When an integration is disconnected or your AlwaysRight account is deleted, all stored OAuth tokens and cached Google performance data are permanently deleted from our servers immediately, and no later than within 30 days. You can also request deletion at any time by emailing hello@alwaysright.de.

5. Web Crawling & Content Processing

The platform analyzes target URLs you authorize, as well as competitor pages, for SEO structure, factual accuracy, and freshness.

  • Publicly accessible body text and meta information
  • JSON-LD schemas and internal links
  • Extracted claims and fact references

Data processing agreement: Insofar as crawled data contains personal content, we act as a data processor pursuant to Art. 28 GDPR. A DPA can be signed directly in the dashboard.

6. AI Processing & Transparency (Art. 50 EU AI Act)

Our agents use specialized generative AI systems for text analysis, fact-checking, clustering, and content creation.

  • OpenAI Ireland Ltd. (GPT models): text analysis & structuring. No API data is used for model training.
  • Anthropic, PBC (Claude models): agent chat & complex analysis. No API data is used for model training.
  • Perplexity AI, Inc.: real-time fact-checking against web sources.

No automated individual decision-making within the meaning of Art. 22 GDPR takes place. All AI output is subject to human review before publication.

7. Subprocessors & Infrastructure

  • Vercel Inc. (USA / DPF certified) — hosting & serverless edge infrastructure.
  • Supabase Inc. (USA / server location EU Frankfurt) — database, auth & storage.
  • PostHog, Inc. (USA / hosted on EU cloud) — in-app event analytics & feature usage.
  • DataForSEO OÜ (Estonia / EU) — SEO & SERP data queries.
  • Microsoft Corporation / Bing Webmaster API (USA / DPF certified) — Optional retrieval of Bing search performance and crawling data via API key.
  • Firecrawl (Sideguide Tech) (USA) — content extraction.

8. Third-Party Connectors (GitHub Autopilot & Bing Webmaster Tools)

GitHub Autopilot: When using the GitHub Autopilot, your Personal Access Token (PAT) is stored encrypted (AES-256) and used exclusively to create pull requests with optimized content and schema fixes in your repository on your behalf.

Bing Webmaster Tools: When connecting Bing Webmaster Tools, your API key is stored encrypted (AES-256) to retrieve search statistics and crawl data for your verified Bing websites. No write actions are performed on your Microsoft account.

9. Your Rights & DPAs

You have the right at any time to access, rectify, erase, and port your data (Art. 15–20 GDPR). Upon request, we provide business customers with a ready-made data processing agreement (DPA pursuant to Art. 28 GDPR). Contact: hello@alwaysright.de.