1. Who we are
Be1st.ai is operated by Brand 360 s.r.o., a company registered in the Slovak Republic.
Contact: our contact form
2. What data we collect
A) Account data
- email address
- name / display name
- profile picture if provided by Google
- Google account identifier used for authentication
B) Website audit data
- URLs and domains submitted by the user
- technical audit results (SEO, security, performance)
- AI readiness and AI visibility results
- sitemap, robots.txt, llms.txt and metadata checks
- timestamps and usage history
C) Billing data (when payments are enabled)
- subscription plan, status, and billing cycle
- customer identifier from our payment provider (Stripe)
- billing address required for invoicing and VAT compliance
We do not store full credit card numbers, CVV codes, or other complete payment-card details. Card data is handled directly by our payment provider, which is PCI-DSS compliant.
D) Technical data
- IP address, browser type, device data
- application logs and error traces
- cookies, local storage, and similar technologies used for login, security, and basic analytics
- security and abuse-prevention logs
3. How we use Google user data
Be1st.ai uses Google user data only to authenticate users, create and manage user accounts, display basic profile information inside the application, and secure access to the service.
We request the following Google OAuth scopes:
openiduserinfo.emailuserinfo.profile
We do not request access to Gmail, Google Drive, Google Calendar, Google Ads, Google Analytics, Search Console, or any other restricted Google scopes. We do not use Google user data for advertising, profiling, or any purpose unrelated to authentication and providing the service.
4. How we use other data
We use the data described above to:
- provide website audits and related features you have requested
- store the history of your audits and account configuration
- improve, maintain, and develop the service
- detect, prevent, and respond to fraud, abuse, and security incidents
- provide customer support
- process payments and issue invoices
- comply with legal obligations (such as tax and accounting laws)
5. Data sharing
We do notsell users' personal data. We only share data with service providers necessary to operate the service, such as:
- hosting provider
- database and authentication provider
- analytics provider (basic, privacy-respecting analytics)
- payment provider
- email delivery provider
- AI / LLM providers used to process audit requests, where applicable
These providers are contractually bound to protect personal data and may only process it on our instructions for the purposes described above.
6. Google API Limited Use statement
Be1st.ai's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Data retention
- Account data: retained while the account exists. When you delete your account, we remove or anonymize personal data within a reasonable period, except for records we must keep for legal or accounting reasons.
- Audit data: retained as long as needed to provide the service and maintain your audit history.
- Logs: retained for a limited period for security, debugging, and abuse prevention.
- Billing records: retained for the period required by applicable tax and accounting laws.
You can request deletion of your data at any time by contacting us.
8. User rights
If you are located in the EU/EEA, you have the following rights under the GDPR:
- right of access
- right to rectification
- right to erasure ("right to be forgotten")
- right to restrict processing
- right to data portability
- right to object to processing
- right to withdraw consent where processing is based on consent
- right to lodge a complaint with a supervisory authority
To exercise any of these rights, contact us at our contact form.
9. Cookies and tracking
Be1st.ai may use cookies, local storage, and session cookies for the following purposes: login and session management, security (CSRF protection, abuse prevention), basic analytics, and improving the service. We do not use third-party advertising cookies.
10. Security
We apply reasonable technical and organizational measures to protect your data, including:
- encrypted transport via HTTPS / TLS
- access controls on production systems
- authentication and session management
- application and security logging
- restricted access to production data on a need-to-know basis
No method of transmission or storage is 100 % secure. While we work to protect your data, we cannot guarantee absolute security.
11. Children
Be1st.ai is not directed to or intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective date" at the top of this page. Material changes will be communicated through the service or by email where appropriate.
13. Contact
For questions about this Privacy Policy, contact us at our contact form.