GEO Optimizer Privacy Policy

Privacy Policy

Last updated: May 12, 2026

Note: This document is intended as a professional draft. Before deploying to production, the data controller name and privacy contact must be completed.

Data Controller

[Name to be completed]

Email: [privacy email to be completed]

For technical issues, open an issue on our GitHub repository.

What data we process

1. Technical navigation data

IP addresses, browser type, operating system, and request timestamps may be logged by the hosting/server infrastructure for security and operational purposes. These logs are processed under legitimate interest and security obligations.

2. URLs submitted for audit

When you voluntarily submit a URL through the audit form, the backend processes that URL to generate a GEO report. The URL is transmitted to the server, analyzed in real time, and the result is returned to you. We do not declare persistent storage of submitted URLs unless explicitly configured in the backend; audit data is processed as a service execution measure.

3. Cookie and storage preferences

Your consent choices (necessary, preferences, analytics, marketing) are stored in localStorage on your device with a 6-month expiration or until the consent version changes. This data is not transmitted to any server and remains entirely on your device.

4. Analytics data (optional)

If you explicitly consent to analytics and a Google Analytics 4 measurement ID is configured, aggregated, anonymized navigation data may be collected. This is disabled by default and requires explicit opt-in.

Legal basis

  • Service execution / pre-contractual measures: processing URLs you submit for audit, generating reports, and delivering results.
  • Legitimate interest / security obligations: technical logs (IP, timestamps) required for server security, abuse prevention, and infrastructure monitoring.
  • Consent: analytics and marketing cookies/storage. You can revoke consent at any time via the cookie preferences panel.
  • Legal obligation / technical necessity: storing your cookie consent choice to comply with ePrivacy and GDPR requirements.

How long we keep data

  • Audit URL submissions: Not declared as persistent storage. Processed in real time and not retained beyond the session unless backend configuration specifies otherwise.
  • Technical logs: Retention period depends on the hosting provider policy (to be completed).
  • Cookie consent preferences: Stored in localStorage for 6 months or until the consent policy version changes.
  • Analytics data (if consented): Retained by Google Analytics under their data retention policies.

Recipients and transfers

Recipients of your data may include:

  • Hosting/infrastructure providers: the server hosting the site and API may process technical logs.
  • Google LLC: only if Google Analytics 4 is activated and you have provided explicit consent to analytics.

Links to GitHub, PyPI, and other external resources in the footer are navigated by you voluntarily; no automatic data sharing occurs with these platforms during normal browsing.

Transfers outside the EU

If Google Analytics 4 is activated, data may be transferred to Google servers in the United States under the conditions defined by Google. We do not currently use analytics by default, and no transfer occurs without your explicit consent.

Your rights

Under the GDPR and applicable privacy laws, you have the right to:

  • Access your personal data
  • Request rectification of inaccurate data
  • Request erasure ("right to be forgotten")
  • Request restriction of processing
  • Object to processing based on legitimate interest
  • Data portability
  • Revoke consent at any time (without affecting the lawfulness of processing before revocation)
  • Lodge a complaint with your national Data Protection Authority (e.g., the Italian Garante per la Protezione dei Dati Personali)

To exercise your rights, contact the data controller at the email listed above.

Cookies

This site uses a minimal cookie and storage system designed for privacy-by-default compliance. Only necessary storage is active without consent. Analytics and marketing are disabled by default. For the full inventory and detailed information, see our Cookie Policy.

Cookie and storage policy

For the complete inventory of cookies and storage technologies used on this site, including categories, providers, and retention, see our Cookie Policy.

Changes to this policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically.