PRIVACY AT AIMATE

Your data should be
as traceable as your evidence.

This policy explains what Aimate collects, why we use it, and the controls available when you connect a website, an AI monitoring workspace, or Google Search Console.

Effective: 26 July 2026

01

Scope and roles

This Privacy Policy applies to the Aimate website, enquiries, customer workspaces, reports and related services (collectively, the “Service”). “Aimate,” “we,” “us” and “our” refer to the operator of the Service.

For website visitors and prospective customers, Aimate normally acts as the controller of personal information. When an organization uses Aimate to monitor its brands, prompts and connected properties, that organization may be the controller and Aimate processes workspace data on its instructions. A customer agreement or data processing agreement may provide additional terms.

02

Data we collect

Information you provide

We collect information submitted through our forms or supplied during onboarding, such as your name, business email, company website, organization, requested plan, prompt requirements and message content. If you create a workspace, we may also collect account details, team membership, preferences and support communications.

Workspace and AI visibility data

Depending on your configuration, we process brand profiles, competitors, markets, monitored prompts, schedules, raw provider responses, mentions, citations, source URLs, sentiment or classification results, provider status, reports and audit records. Prompts may contain information supplied by you; please do not include sensitive personal information unless it is necessary and authorized.

Google Search Console data

If you choose to connect Google Search Console, we may receive the Google account identifier needed to manage the connection, OAuth authorization credentials, the Search Console properties you can access, and search-performance data for properties you select. We do not receive your Google password.

Search-performance data may include clicks, impressions, click-through rate, average position, dates and permitted dimensions such as query, page, country, device and search appearance. We may combine this data with Aimate’s AI mention and citation evidence to provide the dashboards, correlations and reports you request.

Technical and website data

Our systems may automatically receive IP address, browser and device type, requested pages, timestamps, referral information, diagnostics, security events and similar server logs. We use essential storage where needed for security, preferences and session operation. The website currently loads its typefaces from Google Fonts, which may cause your browser to communicate technical request information to Google. We do not use advertising cookies or sell cross-site browsing profiles.

03

How we use data

We use information when reasonably necessary to:

  • provide, configure and maintain the Service and customer workspaces;
  • run monitored prompts and store traceable responses, citations and reports;
  • connect authorized Search Console performance with AI visibility evidence;
  • respond to enquiries, provide support and communicate service information;
  • protect accounts, investigate misuse and maintain reliable provider status;
  • measure and improve Service performance using aggregated or de-identified information;
  • meet contractual, accounting, legal and regulatory obligations; and
  • establish, exercise or defend legal claims.

Depending on where you live, our legal bases may include performing a contract, taking steps at your request, your consent, compliance with law, and our legitimate interests in operating and securing a business service. You may withdraw consent where processing relies on consent, without affecting earlier lawful processing.

04

Google API data and Limited Use

Google API disclosure

Aimate’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We request only the Google permissions reasonably necessary for the feature you activate and prefer read-only access where the feature permits it. Google data is used to display, analyze and report the Search Console information you instruct us to process. We do not use Google user data for personalized advertising, sell it, build advertising profiles, determine creditworthiness, or train generalized AI or machine-learning models.

Human access to Google user data is limited to circumstances where you give explicit permission for support, access is necessary for security or abuse investigation, we must comply with applicable law, or the data has been aggregated and de-identified for internal operations. Personnel and service providers with access are subject to appropriate confidentiality and security obligations.

You can disconnect a Google property in Aimate when that control is available, revoke Aimate’s access from your Google Account connections, or email us to request deletion. Revocation stops future collection but does not automatically remove information already retained for an authorized purpose; deletion is handled as described below.

Learn more in the Google API Services User Data Policy.

05

How data is shared

We may disclose information only as needed to:

  • infrastructure, cloud hosting, database, email, security and support providers acting for us under contractual safeguards;
  • AI or answer-engine providers when your configured prompt is run against that provider;
  • authorized members and administrators of your organization’s workspace;
  • advisers, auditors, authorities or other parties when required by law or reasonably necessary to protect rights and safety; or
  • a successor involved in a merger, financing, acquisition or sale, subject to this policy and appropriate notice.

We do not sell personal information or Google user data. We do not share it for cross-context behavioral advertising.

06

Retention and deletion

We retain information only while it is reasonably needed for the purposes described here, including to provide an active workspace, maintain evidence requested by a customer, resolve disputes, meet legal obligations and protect the Service. Retention can vary by data type, workspace settings and customer agreement.

OAuth credentials are retained only while needed to maintain the authorized connection and are disabled or deleted when the connection is revoked or the relevant account is deleted, subject to short-lived backups and legal requirements. After a verified deletion request, we aim to delete or de-identify applicable personal and Google user data within 30 days, unless a longer period is required by law, security needs or an active contractual dispute. Backup copies may persist for a limited recovery cycle before being overwritten.

07

Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing; receive a portable copy; withdraw consent; and appeal or complain to a data-protection authority. You may also opt out of non-essential marketing communications using the link in the message or by contacting us.

To exercise a privacy right, email hello@aimate.com. We may ask for information needed to verify your identity and authority. If your data belongs to a customer-controlled workspace, we may direct the request to that organization.

08

Security, transfers and children

We use administrative, technical and organizational safeguards designed to protect information, including access controls, least-privilege permissions, secure transport, monitoring and credential protections. No internet service can guarantee absolute security, so please notify us promptly if you suspect unauthorized access.

Aimate and its providers may process information in countries other than yours. Where required, we use appropriate transfer safeguards. The Service is intended for organizations and is not directed to children under 16. We do not knowingly collect personal information from children.

09

Changes and contact

We may update this policy as the Service, integrations or legal requirements change. We will publish the revised policy here, update the effective date and provide additional notice when a change is material.

PRIVACY QUESTIONS & REQUESTSAimate Privacyhello@aimate.com
Send a privacy request