AEO Optima Docs
Configuration

Privacy & Data Rights

Data export, account deletion, consent management, cookie preferences, and data retention policies

Overview

AEO Optima implements full GDPR (Articles 15–20) and DPDP Act 2023 data subject rights. You can export all your personal data, request permanent account deletion, manage your consent preferences, and control cookie settings — all from self-service interfaces.

Data Export (Right of Access & Portability)

Download a complete JSON file containing all your personal data stored on AEO Optima.

What's included in the export

Data CategoryDetails
ProfileDisplay name, email, avatar, creation date
Auth metadataLast sign-in, MFA enrollment status
Organization membershipsAll organizations you belong to, your role in each
Project membershipsAll projects you have access to
Consent recordsEvery consent event (type, timestamp, IP, user-agent)
Audit logsAll actions logged under your user ID
MCP tokensToken metadata (no secrets)
API keysKey metadata (no secrets)
Scheduled reportsReports you created or are subscribed to
Usage recordsYour personal API usage and cost records
Alert rulesAlert configurations you created

How to export

  1. Go to Settings > Profile.
  2. Scroll to the Data & Privacy section.
  3. Click Export My Data.
  4. A JSON file downloads immediately.

Note: The export contains all your data with no artificial limits. Data retention policies (see below) naturally bound the volume.

Account Deletion (Right to Erasure)

Permanently delete your account and all associated personal data with a 30-day cancellation window.

How to request deletion

  1. Go to Settings > Profile.
  2. Scroll to the Danger Zone section.
  3. Click Delete Account and confirm.
  4. Your account enters a 30-day grace period.
  5. During the grace period, you can still log in and cancel deletion.
  6. After 30 days, an automated daily process permanently removes your data.

What gets deleted

The deletion cascade follows 7 steps:

  1. Sole-member organizations — If you are the only member of an organization, the entire organization and all its child data (projects, prompts, snapshots, analytics, reports, webhooks, etc.) are cascade-deleted across 31 related tables.
  2. MCP tokens — All your MCP API tokens are deleted.
  3. Scheduled reports — All reports you created are removed.
  4. Memberships — You are removed from all organization and project memberships.
  5. Consent records — All your consent records are deleted.
  6. Usage records — Your user_id is set to null (anonymized) to preserve aggregate billing data.
  7. Auth account — Your authentication record is deleted, which cascades to your profile.

Cancelling deletion

During the 30-day grace period, go to Settings > Profile and click Cancel Deletion. Your account returns to normal status immediately.

All consent events are recorded server-side for compliance audit trails.

TypeWhen recorded
terms_acceptanceOn signup
privacy_noticeOn signup
age_confirmationOn signup
cookie_analyticsWhen accepting/rejecting cookies
marketing_emailWhen opting in/out of marketing emails

Each consent record stores: user ID (or anonymous cookie ID), consent type, granted/denied status, notice version, IP address, user-agent, and timestamp.

First visit

On your first visit, a cookie consent banner appears with two options:

  • Accept All — Enables analytics cookies (Google Analytics / GA4).
  • Reject Non-Essential — Only essential cookies are set. GA4 is not loaded.

Changing preferences

Click Cookie Settings in the page footer at any time to reopen the consent banner and change your preferences.

Cookie consent preferences expire after 365 days, at which point the banner re-appears automatically.

Google Analytics (GA4) tracking scripts only load if you have accepted analytics cookies. No tracking occurs without explicit consent.

Data Retention

An automated weekly process permanently deletes data older than the following retention periods:

Data TypeRetention PeriodReason
Snapshots365 daysAnalytics data lifecycle
Audit logs730 days (2 years)Legal/compliance audit trail
Webhook deliveries90 daysPII in payload/response body
GA4 traffic data365 daysAnalytics sync data
Alert history180 daysAlert notification records
Consent records730 days (2 years)Legal proof of consent (IP, user-agent)
Usage records365 daysCost/billing analytics
GSC search data365 daysSearch Console sync data

Why retention matters: Records like consent events and webhook deliveries contain PII (IP addresses, user-agents, email addresses). Automated retention ensures this data is not stored indefinitely, reducing compliance risk.

The following legal pages are available from the footer on every page:

PageURLContent
Privacy Policy/privacyFull privacy notice covering data collection, processing, and rights
Terms of Service/termsPlatform usage terms and conditions
Cookie Policy/cookiesCookie types, purposes, and user controls
Acceptable Use/acceptable-useUsage restrictions and prohibited activities
Data Processing Addendum/dpaDPA with sub-processor table (6 vendors with locations)
Contact/contactContact form, grievance officer, SLAs, category-specific emails

Email Unsubscribe

All emails from AEO Optima include:

  • One-click unsubscribe (RFC 8058) — Works natively in Gmail, Apple Mail, and other modern email clients.
  • Browser unsubscribe — Click the unsubscribe link in the email footer for a styled confirmation page.
  • Signed tokens — Unsubscribe links use HMAC-signed tokens with 90-day validity to prevent unauthorized requests.

Plan Availability

All privacy and data rights features are available on every plan, including Free. These are fundamental rights, not premium features.