Privacy Policy

Last updated: 21 August, 2026

This Privacy Policy explains how IvaBot collects, uses, stores and protects personal data when you use the IvaBot website, application and related services.

1. Who is responsible for your data

The data controller is Galyna Arikh, acting as an individual, based in Romania.

Contact for any privacy question, request or complaint: [email protected]

We aim to respond within 30 days.

2. What data we collect

2.1. Account and authentication data

Provided by you at registration, or by Google when you sign in with a Google account:

2.2. Payment data

IvaBot does not receive, see or store card details. All payments are processed by Stripe, which collects the cardholder name, billing address and card number directly.

What we store in our own database is limited to identifiers that let us match a payment to your account: your Stripe customer ID, the ID of your last checkout session, and the ID of your last refund.

2.3. Usage and interaction data

2.4. Data generated by the tools

The content the tools produce for you belongs to you.

2.5. Automatically collected technical data

2.6. Search engine data

IvaBot retrieves search results, keyword metrics and ranking signals from DataForSEO, and queries ChatGPT, Perplexity and Google AI to check AI visibility.

This data is stored, not merely displayed. Each run is saved to your account with its date, so that you can compare results over time and reopen an earlier report. Section 7 explains how long it is kept.

3. Why we use your data, and on what legal basis

PurposeLegal basis
Creating your account and authenticating youPerformance of a contract
Running the tools and delivering their resultsPerformance of a contract
Tracking credits, processing payments and issuing refundsPerformance of a contract
Keeping your saved reports available so you can compare runsPerformance of a contract
Recording errors and monitoring the service so faults can be found and fixedLegitimate interest in a working, secure service
Preventing fraud and abuse of the payment flowLegitimate interest, and Stripe's own legal obligations
Understanding how visitors use the site, through analytics and session recordingsYour consent
Keeping accounting recordsLegal obligation, once it applies to the controller

We do not sell personal data.

We do not use your personal data to train AI models. Prompts sent to OpenAI and to the AI engines checked by the AI Readiness tool are processed only to generate a response, under those providers' API terms, which exclude use for training.

4. Who else processes your data

ProcessorWhat it handlesWhere
SupabaseAuthentication, database, server functionsEU / US
StripePayments, cards, fraud preventionEU / US
WebflowWebsite hosting, page delivery, server logsUS
GitHubDelivery of application script filesUS
GoogleSign-in with Google, Google AnalyticsUS
MicrosoftClarity analytics and session recordingsUS
OpenAIGenerating audit text, briefs and articlesUS
DataForSEOSearch results, keyword metrics, backlinks, AI engine queriesEU
MakeWorkflow automation between the aboveEU

Each processor handles data under its own privacy terms and under a data processing agreement. We share no more than each one needs to perform its function.

5. International transfers

Some of the processors above store or process data outside the European Economic Area, mainly in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on the EU-US Data Privacy Framework where the processor is certified under it.

6. Cookies and similar technologies

We group cookies into two categories.

Strictly necessary

These are set without consent, because the service cannot work without them.

Cookie or storageSet byPurposeDuration
Authentication sessionSupabaseKeeps you signed in and linked to your own dataUntil you sign out or the session expires
Local application stateIvaBotHolds your tracked pages and prompts in your browser between visitsUntil you clear your browser storage
Payment and fraud preventionStripeCompletes checkout and detects fraudulent paymentsSet by Stripe, up to 1 year
Analytics

These are set only after you accept them in the cookie banner.

Cookie or storageSet byPurposeDuration
Google AnalyticsGoogleCounts visits and shows which pages are usedUp to 2 years
Microsoft ClarityMicrosoftRecords how pages are used, including mouse movement, clicks, scrolling and session replaysUp to 1 year

Session recordings capture how you move around a page. They do not capture what you type into password fields.

You can change or withdraw your choice at any time through the cookie settings link in the site footer. Withdrawing consent stops further collection; it does not undo collection that already happened.

7. How long we keep data

8. Your rights

Under the GDPR you may at any time:

Write to [email protected] to exercise any of these. We may ask you to confirm your identity before acting on a request that concerns sensitive changes or deletion.

You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), at www.dataprotection.ro, or with the authority in your own country of residence.

9. Security

We protect your data with encrypted connections (HTTPS), payment handling delegated entirely to Stripe, row-level security policies on database tables so that each account reads only its own rows, restricted access to production data, and regular review of the code that touches personal data.

No system is completely secure, and we cannot guarantee absolute security.

10. Children

IvaBot is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, write to [email protected] and we will delete it.

11. Changes to this policy

We update this policy when the service or the law changes. The date at the top always shows the current version. Where a change materially affects your rights, we will tell you by email before it takes effect.