Legal

FaqFlo Privacy Policy

Last updated: August 11, 2026

This Privacy Policy explains how FaqFlo (“FaqFlo,” “we,” “us,” or “our”) collects, uses, and shares information through the FaqFlo website, web application, and related services (the “Services”).

FaqFlo is an Answer Engine Optimization (AEO) service. It audits websites for AI visibility, generates FAQ content, produces publish-ready HTML for you to place on your own website, and tracks whether your business is cited by AI answer engines such as ChatGPT, Perplexity, and Gemini.

By using the Services, you agree to this Privacy Policy. If you are in the EEA, UK, or Switzerland, see GDPR Rights; if you are a California resident, see California Rights.

1. Who We Are

FaqFlo is the data controller for information processed through the Services. You can contact us any time at [email protected].

2. Information We Collect

Information you provide

  • Accountyour name, email, and login credentials (passwords are managed by our authentication provider and stored hashed; we never see your plaintext password).
  • Billinghandled by our payment processor. We do not store full card numbers; we receive limited details such as card brand, last four digits, expiration, and subscription status.
  • Content you submitwebsite URLs, business details, topics, and the FAQ questions and answers you create or generate.
  • Communicationssupport requests, demo and intake forms, and anything else you send us.

Information we collect automatically

  • Usage dataaudits run, FAQs generated, features used, pages viewed, and timestamps.
  • Device and log dataIP address, browser and device type, and diagnostic/error logs used to keep the Services secure and working.

Cookies and similar technologies — see Section 3.

Information from websites you submit

A core function of the Services is to fetch and analyze the URLs you submit, including their public HTML, robots.txt, and structured data. You are responsible for having the right to submit any URL you enter.

Information from third parties

Our authentication provider, payment processor, and analytics partners may share account, billing, or attribution information, and the AI and search engines we query on your behalf return results that may reference your business or competitors.

3. Cookies

We use cookies and similar technologies that are strictly necessary (for login and security), functional (to remember preferences), and for analytics and marketing measurement. Where required by law, we ask for your consent before setting non-essential cookies and provide a way to manage them; you can also control cookies in your browser. We do not respond to browser “Do Not Track” signals but honor recognized opt-out signals (such as Global Privacy Control) where legally required.

4. How We Use Information

We use information to provide and operate the Services (running audits, generating FAQ content, producing HTML and schema, and tracking citations); to create and secure your account; to process payments and manage subscriptions; to communicate with you, including service, billing, and — where permitted — marketing messages; to improve the Services and develop new features; to prevent fraud and abuse; and to comply with legal obligations.

Use of AI

To deliver the Services, the content you submit may be processed by third-party AI providers to generate FAQ content, and we send queries to third-party AI and search engines to track citations. We do not use your submitted content to train our own AI models and contractually seek to limit our providers from doing so, though those providers operate under their own terms.

Legal bases (EEA/UK/Switzerland)

We process personal data to perform our contract with you, for our legitimate interests (securing and improving the Services, preventing abuse, and marketing to existing customers), with your consent (for example, certain cookies and marketing), and to comply with legal obligations.

5. How We Share Information

We do not sell your personal information. We share it only:

  • with service providers who work on our behalf — hosting, authentication, payment processing, email delivery, error monitoring, analytics, and the AI and search engines used for generation and tracking;
  • for legal and safety reasons, when required by law or to protect our rights, users, or the public;
  • in a business transfer, such as a merger, acquisition, or sale of assets;
  • at your direction or with your consent; and
  • as aggregated or de-identified data that cannot reasonably identify you.

A list of our key subprocessors is available on request at [email protected].

6. Data Retention and Security

We keep personal information for as long as your account is active and as needed to provide the Services, then for as long as necessary to meet legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. We use reasonable safeguards such as encryption in transit, access controls, and reputable infrastructure and payment providers, but no system is completely secure. You are responsible for keeping your credentials confidential.

7. International Transfers

We are based in the United States and may process information there and in other countries whose laws may differ from yours. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses. Request details at [email protected].

8. Your Privacy Rights

We will not discriminate against you for exercising any right below. To make a request, email [email protected]; we may need to verify your identity first.

GDPR Rights (EEA/UK/Switzerland)

You may request access, correction, deletion, restriction, or portability of your personal data; object to certain processing; withdraw consent; and lodge a complaint with your local supervisory authority.

California Rights (CCPA/CPRA)

You may request to know, access, delete, or correct your personal information, and to opt out of the sale or sharing of it. We do not sell your personal information or share it for cross-context behavioral advertising. In the past twelve months we may have collected the categories described in Section 2 (identifiers, customer and commercial records, internet activity, approximate location from IP, and the contents of your communications and inputs) for the purposes in Section 4. You may use an authorized agent, subject to verification.

Other U.S. states

Residents of states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and New Hampshire may have similar rights to access, correct, delete, and port their data and to opt out of targeted advertising and sale — none of which we engage in. Contact [email protected] to exercise them.

9. Children’s Privacy

The Services are for business users who are at least 18. We do not knowingly collect information from anyone under 16. If you believe a child has provided us information, contact [email protected] and we will delete it.

11. Changes and Contact

We may update this Privacy Policy and will revise the “Last updated” date, providing additional notice if the changes are material. Continued use after changes take effect means you accept them.

FaqFlo Email: [email protected]