Overview and scope
EqualAI is operated by EqualAI. This Privacy Policy explains how EqualAI collects, uses, stores, and protects information when users use our website and application.
App name: EqualAI. Operator: EqualAI. Contact email: team@equalai.io. Website domain: equalai.io.
EqualAI helps teams measure AI search visibility, prompt performance, model responses, citations, sentiment, competitors, AI referral paths, and related recommendations. This policy applies to website visitors, trial users, customers, workspace members, agency clients, enterprise users, and support contacts.
For customer workspace data that we process on behalf of a business customer, the customer is generally the controller and EqualAI acts as processor. For our website, account administration, billing, security, service analytics, and marketing operations, EqualAI may act as an independent controller where permitted by law.
Information we collect
We collect account and profile information such as name, business email, company, role, password or authentication metadata, workspace membership, plan, preferences, and communications with our team.
We collect product configuration and customer content needed to provide the service, including tracked domains, brand names, competitors, prompt libraries, target markets, model selections, tags, notes, annotations, report settings, exports, API usage, integration settings, and support requests.
We collect AI visibility data generated through the platform, including prompts submitted for tracking, AI model responses, cited URLs, citation domains, sentiment labels, entity mentions, ranking or share-of-voice metrics, recommendations, crawler and referral observations, and timestamps.
We collect technical, device, and usage data such as IP address, browser, operating system, approximate location, pages viewed, referring URLs, session events, feature usage, log data, error reports, authentication events, security events, and cookie or similar technology identifiers.
We collect billing metadata such as subscription plan, invoice status, billing address, tax information, payment status, card brand, last four digits, expiration month/year, and transaction identifiers. Full payment card numbers, CVCs, and sensitive payment credentials are processed by our payment processor and are not stored by EqualAI.
Google User Data
If you connect your Google account, EqualAI may access Google Analytics and Google Search Console data that you authorize through Google OAuth. This may include Google Analytics property information, aggregate traffic metrics such as sessions, users, conversions, traffic sources, landing pages, and time-series reporting data. It may also include Search Console site and query performance data such as verified site URLs, search queries, clicks, impressions, click-through rate, and average position.
EqualAI uses Google Analytics data to generate user-facing AI Traffic and Agent Analytics reports, including AI referral sources, landing pages, sessions, users, conversions, and reporting trends. EqualAI uses Google Search Console data in Prompt Research to help users view their own Search Console queries and convert selected queries into AI visibility prompts.
EqualAI requests read-only access to Google Analytics and Google Search Console. EqualAI does not create, edit, delete, or manage Google Analytics properties, Google Analytics events, Search Console sites, Search Console settings, or Google account settings.
Google API Services User Data Policy and Limited Use
EqualAI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
EqualAI uses Google API data only to provide and improve user-facing features that are visible in the EqualAI application, including AI Traffic / Agent Analytics reporting and Prompt Research. EqualAI does not sell Google API data, does not use Google API data for advertising, does not use Google API data to build individual profiles, and does not use Google API data for lending, credit, or eligibility decisions.
EqualAI does not use Google Analytics or Google Search Console data received through Google OAuth to train, improve, or develop generalized AI or ML models.
Google API Data and AI Providers
Some EqualAI features use third-party AI providers to run prompt checks, draft content, analyze text, or power AI-assisted workflows. The content processed for these features is used only to provide the requested user-facing feature.
EqualAI does not transfer Google Analytics or Google Search Console data, or prompts derived from that data, to DeepSeek or to any AI provider whose terms permit generalized model training on submitted content.
Where EqualAI uses an AI provider to process Customer Data, EqualAI uses approved AI providers whose terms prohibit generalized model training on Customer Data. Google API data is processed only as necessary to provide the user-facing feature requested by the user and in accordance with Google API Services User Data Policy Limited Use requirements.
How we use information
We use information to provide, maintain, secure, and improve EqualAI, including authentication, workspace administration, prompt tracking, report generation, citation analysis, recommendations, exports, integrations, support, billing, fraud prevention, and service communications.
We use product and usage data to debug errors, monitor reliability, prevent abuse, enforce limits, analyze feature adoption, develop new functionality, and understand which workflows are useful for customers.
We use account and contact information to respond to requests, send transactional notices, provide onboarding, deliver invoices, communicate product updates, and, where permitted, send marketing messages. You can opt out of marketing messages without affecting service notices.
We may create aggregated or de-identified statistics, benchmarks, and research from product data. We do not identify a customer, user, brand, domain, or workspace in public materials without permission or another lawful basis.
Legal bases for processing
Where GDPR, UK GDPR, India's Digital Personal Data Protection Act, or similar laws apply, we process personal data based on one or more lawful grounds, including performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of rights, security, and service integrity.
Examples of legitimate interests include providing and improving the service, securing accounts, preventing fraud or abuse, responding to requests, measuring business performance, and understanding whether website and product experiences are effective.
Where processing depends on consent, such as certain analytics, marketing communications, or non-essential cookies in some regions, you may withdraw consent at any time through the available controls or by contacting us. Withdrawal does not affect prior lawful processing.
AI prompts, outputs, and third-party models
EqualAI measures public and customer-configured AI visibility signals. Prompts, domains, competitor names, and related configuration may be sent to third-party AI engines, search providers, or data providers when needed to run tracking, retrieve responses, analyze citations, or generate reports.
Customers are responsible for deciding what they configure in the platform. Do not submit sensitive personal data, payment card data, health data, government identifiers, children's data, secrets, private credentials, or regulated confidential information unless your agreement explicitly permits that use and appropriate safeguards are in place.
AI model outputs are generated by third-party systems and may be incomplete, inaccurate, biased, outdated, or non-deterministic. We process outputs to provide measurement and recommendations, but EqualAI does not control the underlying third-party model behavior.
Data Sharing and Subprocessors
EqualAI does not sell Google user data. EqualAI may share limited data with service providers and subprocessors that help operate, secure, support, and improve the application, such as hosting, database, monitoring, analytics, security, payment, communications, and AI infrastructure providers.
These providers are allowed to process data only as needed to provide services to EqualAI and are not allowed to use Google API data for advertising, data brokerage, or generalized AI/ML model training.
We may disclose information if required by law, subpoena, court order, governmental request, to protect rights and safety, to investigate abuse, to enforce our terms, or in connection with a merger, acquisition, financing, reorganization, or sale of assets.
International transfers
EqualAI may process and store information in countries other than where you are located, including through cloud, analytics, payment, support, and communications providers. These countries may have data protection laws that differ from your jurisdiction.
Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, UK transfer mechanisms, data processing agreements, vendor due diligence, and other lawful transfer tools.
Data storage and security
EqualAI stores integration configuration and encrypted credentials only as needed to provide the connected reporting features. EqualAI uses reasonable administrative, technical, and organizational safeguards designed to protect user data from unauthorized access, disclosure, alteration, or destruction.
OAuth credentials are stored securely and are used only to refresh authorized Google API access for the connected project.
We use administrative, technical, and organizational safeguards designed to protect personal data, including access controls, encryption in transit, cloud security controls, monitoring, backup practices, and least-privilege operational access.
No online service can guarantee absolute security. You are responsible for maintaining strong credentials, controlling workspace access, reviewing integrations, and using the service in line with your legal obligations.
Data Retention and Deletion
EqualAI retains Google integration data only as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business records.
Users can disconnect Google Analytics from Project Settings under the GA4 tab, after which EqualAI stops fetching new Google Analytics data for that project. Users may revoke EqualAI’s access to Google Analytics and Google Search Console at any time from their Google Account permissions page, or contact team@equalai.io to request removal of connected Google integration data.
OAuth credentials are stored securely and used only to maintain authorized Google API access for the connected project.
Customer workspace data is retained according to the subscription plan, order form, DPA, backup practices, and deletion requests. Backups and logs may persist for a limited period before being overwritten or deleted through normal retention cycles.
Billing, tax, invoice, security, and legal records may be retained longer where required by law or legitimate business needs. We may retain aggregated or de-identified data that no longer identifies a person or customer.
Your privacy rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of your personal data. You may also have the right to complain to a data protection authority.
Users may contact us at team@equalai.io to request access, correction, deletion, or export of their personal data.
Workspace owners and administrators can manage users, remove access, update settings, and request export or deletion of customer data. Individual users may contact the customer that controls their workspace data or contact EqualAI for help routing the request.
We may need to verify your identity and authority before fulfilling a request. Some requests may be limited by legal obligations, security needs, contractual duties, backup retention, or the rights of others.
Children and sensitive data
EqualAI is a business service and is not intended for children. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child provided personal data, contact us so we can take appropriate action.
The service is not designed to process special category data, sensitive personal data, payment card numbers, passwords outside authentication flows, protected health information, or regulated financial data unless expressly agreed in writing.
Contact
For privacy requests, contact team@equalai.io. For security matters, contact team@equalai.io. For enterprise or DPA requests, contact the EqualAI team through the enterprise workflow.
Changes to this policy
We may update this Privacy Policy to reflect product changes, legal requirements, vendor changes, or operational improvements. The updated date on this page indicates when the policy was last revised.
Material changes will be communicated through reasonable means, such as the website, account notices, email, or contractual notice procedures. Continued use of the service after an update means the updated policy applies.