Privacy Policy
This policy describes how Miraqo processes the personal data of users who use the service available at app.miraqo.io and the marketing site miraqo.io, in accordance with EU Regulation 2016/679 (GDPR) and — with respect to Google API integrations — the Google API Services User Data Policy, including the Limited Use requirements.
1. Data controller
Delete di Terni Davide
VAT: IT02657410185
Email: privacy@miraqo.io
Registered address: Viale della Libertà 14, Pavia, Italy
2. Personal data collected
2.1 Data provided by the user
- Account: email, password (hashed), first and last name, organisation name.
- Billing: company name, VAT/tax ID, address, payment method (handled by Stripe — Miraqo does not store card details).
- SEO projects: domains, keywords, URLs and configurations entered by the user.
2.2 Data collected via Google integrations (OAuth)
If the user voluntarily chooses to connect their Google account to a Miraqo project, we access the following data in read-only mode via OAuth 2.0:
- Google Search Console (scope
webmasters.readonly): list of properties the user has access to, search queries, indexed pages, clicks, impressions, CTR and average position — limited to the properties selected by the user. - Google Analytics 4 (scope
analytics.readonly): list of accessible GA4 properties, daily aggregate metrics (sessions, users, engagement, conversions) broken down by landing page — limited to the property selected by the user.
OAuth tokens (access and refresh) are encrypted at rest with AES-128 (Fernet, django-cryptography library) before being saved to the database.
2.3 Automatically collected data
- Technical access logs (IP address, user agent, date and time) retained for 30 days.
- Technical session cookies (required for authentication).
- Error telemetry via Sentry, with
send_default_pii=False. - A count of the application sections each user opens (section name, day, number of views), retained for 90 days, to understand which features are used and improve the product (legitimate interest, Art. 6(1)(f) GDPR). No IP address, no browsing data outside the application, no third-party tools.
2.4 Data collected via the site chatbot
The site provides a virtual assistant (chatbot) to answer questions about features, pricing and the free trial, and to allow users who wish to be contacted. When used, we process:
- Message content exchanged with the assistant.
- Email, only if the user voluntarily provides it to be contacted (commercial contact request).
- Pseudonymised IP address (hash) and referring page, for security and abuse-prevention purposes.
Messages are processed by AI service providers (listed in §6). We advise against entering personal or sensitive data in the chat. Before the first message, explicit consent to this privacy policy is required: we record the date, time and version of the policy accepted.
Website usage statistics. We measure visits to this website with Matomo, a statistics software installed on our own infrastructure (self-hosted): no browsing data is sent to external analytics providers. Measurement uses no cookies and the IP address is anonymised before being stored; the collected data is aggregated and does not allow visitors to be identified.
2.5 Data collected via the free “AI Visibility Check” tool
The site offers a free tool, with no sign-up, that asks a question written by the user to some AI assistants (ChatGPT, Perplexity, Google AI Overview) and emails a link to the page with the answers obtained. When the user uses it we process:
- Brand name, website and question entered in the form, together with the country chosen for the answers.
- Email, used to send the link to the result and for any follow-up about the result itself.
- Pseudonymised IP address (hash) and referring page, for security and abuse prevention.
- Cloudflare Turnstile anti-bot check: the form loads a Cloudflare script that tells people apart from automated programs by analysing technical browser signals, with no cookies and no tracking; Cloudflare processes the IP address and technical request data as a data processor (see §6).
The question, brand and website are sent to the AI assistants through technical providers that run the queries on our behalf; the email is never sent to any of them. The assistants’ answers are third-party content and are shown as received. Please do not include personal data in the question. Explicit consent to the privacy policy is required before submission: we record the date, time and version of the policy accepted. The data entered is not used for newsletters nor shared with third parties.
3. Purposes of processing
- Providing the SaaS service (creating and managing SEO projects, ranking, audit, reports).
- Importing and displaying Google Search Console and Google Analytics 4 data in the user’s dashboard, with their explicit authorisation.
- Billing, subscription management and tax compliance.
- Service communications (notifications on significant changes, periodic reports, sync errors).
- Pre-sales assistance via chatbot and handling commercial contact requests, at the user’s initiative.
- Running the free “AI Visibility Check” tool and emailing the result, at the user’s request.
- Infrastructure security and abuse prevention.
4. Legal basis
- Performance of a contract (Art. 6.1.b GDPR) for providing the service.
- Explicit consent (Art. 6.1.a GDPR) for connecting Google integrations and for non-essential communications.
- Legal obligation (Art. 6.1.c GDPR) for billing and document retention.
- Legitimate interest (Art. 6.1.f GDPR) for security and abuse prevention.
- Explicit consent (Art. 6.1.a GDPR) for using the chatbot, the free “AI Visibility Check” tool and any contact requests.
5. Limited use of Google data (Limited Use Disclosure)
Miraqo fully complies with the Google API Services User Data Policy — Limited Use Disclosure.
Specifically, we declare that data received from Google Search Console and Google Analytics 4 is used exclusively to:
- Show the user their own ranking and organic traffic metrics in the Miraqo dashboard.
- Correlate GA4 traffic metrics with the user’s tracked keywords to enable richer analysis.
- Export data in PDF reports or shareable links created by the user.
We do NOT use Google data for:
- Transfer, sale or sharing with third parties for profiling, marketing, advertising or data brokering.
- Training AI models, whether internal or third-party.
- Human access, except (i) with the user’s explicit consent, (ii) for technical assistance with consent, (iii) legal obligations, or (iv) internal security purposes in aggregate, de-identified form.
6. Third parties that process data
The following parties, acting as processors under Art. 28 GDPR, may process personal data in the course of the services they provide:
- NameHero LLC (United States) — infrastructure hosting; the servers delivering the service are located in the United Kingdom (Erith data centre, OVH infrastructure). Off-site backups are stored in the United States (California). NameHero support staff, bound by confidentiality obligations, may access the servers from the United States and India solely as required for technical support. Transfers to the United States and India are governed by Standard Contractual Clauses (Modules 2 and 3) signed on 18 August 2026.
- Cloudflare, Inc. (United States) — CDN, DDoS protection and TLS certificate management for the website and the application. All traffic passes through its servers: it processes IP addresses, request headers and browsing metadata. It does not retain application content.
- Stripe Payments Europe Ltd. — payment processing and billing data.
- TeamSystem S.p.A. (Fatture in Cloud) — invoice issuance and transmission to the Italian Interchange System (SdI): receives company name, VAT/tax number, address, recipient code/PEC and amounts.
- Google Ireland Ltd. — limited to data requested by the user via OAuth (GSC, GA4).
- Google LLC (Google Fonts) — the application (
app.miraqo.io) loads web fonts via thefonts.googleapis.comandfonts.gstatic.comCDNs; when pages load, the browser’s IP address is transmitted to Google’s servers to serve the fonts. Themiraqo.iowebsite hosts its own fonts and does not contact Google. - Anthropic PBC (United States) — language models that process the requests of the AI features the user activates (assistant, content generation, review replies, brand analysis): receives the prompts, which contain no identifying data; the content is not used to train models, as provided by the provider’s Commercial Terms.
- OpenRouter Inc. (United States) — routing of image-generation requests only, to OpenAI’s image model (Content Generator add-on only): receives the description of the image to be generated.
- Indigo Stream Technologies Ltd. (Copyscape) (United States) — plagiarism check on texts produced by the Content Generator: receives the generated text. Active only for users who purchased the corresponding add-on.
- Functional Software Inc. (Sentry) (United States; data stored in the European region, Frankfurt) — application error telemetry, configured without PII.
- AhaSend B.V. (Netherlands) — delivery of the application’s transactional emails (sign-up, password reset, invitations, notifications and reports): processes the recipient and the content of the message. It does not record opens or link clicks, and links are not rewritten.
- DNSExit (United States) — SMTP smart host of the mail server: it relays outbound messages sent from our mailboxes (for example info@ and privacy@), processing recipient and content in transit. The mailboxes reside on NameHero’s servers.
All providers located outside the European Union operate under the safeguards set out in Chapter V of the GDPR (adequacy decisions, Standard Contractual Clauses and/or the EU-US Data Privacy Framework, depending on the provider).
7. Retention period
- Account and project data: for as long as the organisation exists, even with an expired subscription. Closing the organisation from the settings deletes them immediately and irreversibly; only backup copies remain, overwritten by normal rotation. Organisations expired for more than 24 months may be closed by us, with 30 days’ notice by email.
- Billing data: 10 years as required by Italian tax regulations.
- Google OAuth tokens (GSC, GA4): while the integration remains active; deleted within 24 hours of manual disconnection or account deletion.
- Synced GSC/GA4 data: up to 16 months (rolling window aligned with Google API limits), deleted on revocation or account deletion.
- Access logs: 30 days.
- Sentry errors: 30 days.
- Site chat transcripts: maximum 30 days from the conversation, then automatically deleted.
- Contact requests (leads) from the chatbot and from the free “AI Visibility Check” tool: up to 24 months from last contact, unless an earlier deletion request is made; proof of consent (date and policy version) is retained alongside the lead.
- Free “AI Visibility Check” requests (question, AI assistants’ answers, result page, pseudonymised IP address): 30 days from the request, then automatically deleted.
8. Security measures
- HTTPS mandatory on all endpoints (TLS 1.2+).
- OAuth tokens and other credentials encrypted at rest (AES-128 Fernet).
- User passwords stored only as hashes using Argon2/PBKDF2.
- Login rate limiting, optional two-factor authentication.
- Daily backups of the database, filesystem and mailboxes to an external destination, with at least 10-day retention.
- Limited and audited administrative access.
9. Data subject rights
Users may exercise at any time the rights provided by Articles 15–22 GDPR:
- Access to their data.
- Rectification of inaccurate data.
- Erasure (right to be forgotten).
- Restriction of and objection to processing.
- Data portability (CSV/JSON export).
- Withdrawal of consent, in particular for Google integrations: available from the project “Integrations” page with immediate deletion of tokens and associated data, or directly from myaccount.google.com/permissions.
- Complaint to the supervisory authority. In Italy: www.garanteprivacy.it.
To exercise your rights, write to privacy@miraqo.io. We respond within 30 days.
10. Cookies
The site uses only technical session cookies, necessary for the app to function and not used for profiling. The virtual assistant (chatbot) does not use cookies or store data on the user’s device. The free “AI Visibility Check” tool stores in the browser, only for the lifetime of the tab (sessionStorage), a technical code that lets the user correct the email address after submission: it is not a cookie and is not used for tracking. For details, see the Cookie Policy.
11. Changes to this policy
Significant changes will be notified by email to registered users and published on this page with at least 30 days’ notice before taking effect, except for changes required by legal obligations.
12. Contact
For any question about the use of your data, contact us at privacy@miraqo.io.