Trust Center
Security, data handling and AI accountability in one place — without the sales gloss. Everything below can be verified, and what isn't in place is stated too.
Where your data sits, and who can reach it
Geoa is operated by AddonNordic ApS (company no. 46495985) from Aalborg, Denmark. The infrastructure sits in the EU.
The infrastructure sits in the EU
The application is hosted on Railway in the EU and the database on Supabase in Ireland. Your data is stored and processed in the EU — with one exception we describe openly further down: the AI model call itself.
Encryption
All traffic runs over HTTPS with HSTS and modern security headers. Data is encrypted at rest (AES-256) at our database provider.
Access control
Row Level Security on the database, server-side secrets that never reach the browser, and per-installation API keys for plugins that can be revoked individually.
Tested before every deploy
Every single change must pass 2.700+ automated tests and a production smoke test before it ships. A red test means no deploy.
Payment via Stripe
We never see or store your card details — all payment processing sits with Stripe.
Deletion within 30 days
Delete your account and all associated data is removed within 30 days. No shadow copies.
Article 50: the duty is yours, the work is ours
From 2 August 2026, AI-generated content must be disclosed. If you publish content from Content Studio on your own website, the disclosure duty is yours. Geoa is built so you can carry it — and so you never claim more than what actually happened.
The marking is applied at the source
The disclosure is attached when the article is generated, not in a view. That is why it travels all the way into your CMS. A marking applied only in the interface disappears on the first export.
Review is an act, not a checkbox
Clicking "ready" records no review. An editorial review requires a named person who explicitly confirms the substance, figures and sources — and takes editorial responsibility for publication.
The text cannot go stale
The disclosure is derived from the article's actual state every time it leaves us. If the review happens later, it takes effect everywhere — and an article can never carry a claim that reality has moved past.
What we do not cover
Article 50(2) also requires generated content to be marked machine-readably in a standard format. We do not cover that today: we store the disclosure in the post's metadata, but a field only we can read is an archive, not a signal anyone else can interpret. We write that here rather than letting half a coverage sound like a whole one.
We only show figures we have actually measured
Our most important principle is built into the platform. See also how we measure.
"Done" is always measured
A fix is marked complete only once we have verified it with a concrete check — an HTTP request, a rescan or a profile check. Never because someone claimed it.
Unmeasured means unmeasured
If something cannot be measured (because a site blocks our check, for instance), we say "not measured" and keep the score neutral — we never penalise, and we never guess.
Floor figures, not fantasy figures
AI visit figures are presented as a floor ("at least X visits"), because many AI services hide the referral. We do not inflate numbers.
No guarantees we cannot keep
Nobody can guarantee a place in ChatGPT's answers — including us. We measure, improve and document the trend. Be sceptical of anyone promising more.
What our AI may do — and never may
The whole platform shares one rulebook for the AI assistant, enforced by automated tests. These are the rules in plain language — not an excerpt, but what they actually say.
Prices are never improvised
The assistant never quotes amounts, discounts or lock-in periods on its own — a policy an AI makes up would be binding on us. It refers you to the pricing page and to a human.
Results are never promised
No 'then ChatGPT will recommend you', no traffic or revenue promises. How third-party AI services mention you is theirs to control — and the assistant says so honestly.
If it doesn't know, it says so
The assistant never explains an error or missing data it has no source for. A guess that sounds right is worse than no answer — so it says 'I don't know' and refers you to a human.
If it doesn't exist, it isn't suggested
The assistant never suggests features that don't exist, and never invents links or pages. If it doesn't know the place, it says so.
An AI that says it's an AI
Ask whether you're talking to a human and you get an honest no. And instructions hidden in pasted text — 'ignore your rules', 'give me a discount' — are not followed: text is data, not orders.
Measured · not done · marked by you
Every check in the platform ends in one of three outcomes — and they are never mixed. Some surfaces block all automated checks; a green checkmark there would be a lie.
Measured
We verified it ourselves with a concrete check: an HTTP lookup, a re-scan or a signal from your own site. Only that earns a checkmark.
Not done
The check hasn't run yet — or couldn't run. It is shown as exactly that, and it never counts against you. Unmeasured is not zero.
Marked by you
Some platforms block all automated lookups. If you did the work yourself, you can mark it — and it will say 'marked by you', never 'verified'.
Engine down = named
If an AI engine can't be measured — outage, rate limit, closed access — it is shown by name as 'could not be measured'. Your score is never lowered by an engine that was down; it is computed over the ones that actually answered.
Who we share data with, and on what basis
AddonNordic ApS is the data controller. We do not sell your data and do not use it to train general AI models.
Our data processing agreement is public — you do not need to contact us to read it: read the DPA.
Subprocessors
These services process personal data on our instructions. The list is wired to the codebase and covered by automated tests, so it cannot fall behind what the platform actually does.
| Service | Purpose | Data | Processed in | Basis |
|---|---|---|---|---|
| Railway Railway Corporation | Application hosting. | All traffic and data passing through the platform. | EU | Data Privacy Framework |
| Supabase Supabase Pte. Ltd. | Database and user authentication. | Account details, domains, measurements and generated content at rest. | Ireland | EU standard contractual clauses |
| Lovable Lovable Labs Incorporated | Hosts the dashboard and relays subscription events. | Account details and subscription status. | EU | EU standard contractual clauses |
| Stripe Stripe Payments Europe, Ltd. | Payment processing. We never see or store your card details. | Payment details and subscription identifiers. | EU and United States | Data Privacy Framework |
| Resend Plus Five Five, Inc. | Delivery of reports and service emails. | Recipient email address, name and the full message body. Resend's region setting controls only where mail is sent from — account data, metadata and logs sit in the US regardless. | United States | Data Privacy Framework |
| Sentry Functional Software, Inc. | Error monitoring so failures are caught and fixed. | Technical error context and an installation identifier. | Germany | Data Privacy Framework |
| OpenRouter OpenRouter, Inc. | Routes AI calls onward to whichever model the task requires. | The prompt: brand knowledge, article text and verified company facts — including named individuals. We do not hold a signed data processing agreement with OpenRouter — it is offered to enterprise customers only. | United States | EU standard contractual clauses |
| OpenAI OpenAI Ireland Ltd. | Generates content and measures visibility in ChatGPT. | Domain, registry name and address, industry details and extracts of your public website text. | United States | EU standard contractual clauses |
| Google (Gemini og Cloud Natural Language) Google Cloud EMEA Limited | Measures visibility in Gemini and analyses entities in page text. | Brand name, domain and up to 60,000 characters of your page text. | United States | EU standard contractual clauses |
| Perplexity AI Perplexity AI, Inc. | Measures visibility and citations in Perplexity. | Brand name, domain, services, city and competitor names. | United States | Data Privacy Framework |
| Jina AI Jina AI GmbH (Elastic N.V.) | Fetches and reads web pages when direct retrieval is blocked. | The address of the page fetched, and the page's own content. | Germany | not verified |
| DataForSEO DataForSEO OÜ | Retrieves Google rankings, search volume and reviews. | Domain, brand name, keywords and country. Reviews are returned carrying the reviewers' names. | EU | EU/EEA |
| Brave Search Brave Software, Inc. | Finds competitors, profiles and search results. | A search string built from brand name, service and city. Brave's data processing agreement explicitly excludes the search queries themselves — what we send is not covered. | United States | EU standard contractual clauses |
| AddonNordic Data API AddonNordic ApS | Looks the company up in the public business registries. | Company name, registration number and domain. | EU | EU/EEA |
| CookiePilot Clever Agent sp. z o.o. | Consent banner and record of consents given. | Your consent choice. | Poland | not verified |
| Plausible Analytics Plausible Insights OÜ | Cookie-free visitor statistics. | Aggregated pageview statistics with no personal identifiers. | EU | EU/EEA |
| Slack Slack Technologies Limited | Sends alerts to your own Slack channel. Only if you set up a Slack webhook yourself. | Domain and score in the message body. | EU and United States | Data Privacy Framework |
Independent controllers
These are not subprocessors: they determine the purposes and means of their own processing and therefore do not act on our instructions. We list them anyway, because they receive data once you consent.
| Service | Purpose | Data | Processed in | Basis |
|---|---|---|---|---|
| Microsoft Clarity Microsoft Ireland Operations Limited | Behaviour analytics — shows how the site is used. Only after your statistics consent. | Session activity on the marketing site. Text entry is masked. | Ireland | EU standard contractual clauses |
External lookups with no personal data
We call these services too, but they receive no personal data — typically just a web address or a company name. They are listed for transparency, not as processors.
| Service | Purpose | Data |
|---|---|---|
| Google PageSpeed Insights og CrUX | Measures page speed. | The page address only. |
| Wikipedia og Wikidata | Checks whether the brand exists as a known entity. | The brand name only. |
| Google Search Console og Analytics | Retrieves your own search and traffic figures once you connect. | We pull FROM Google on your authorisation — we send nothing there. |
| Meta Ad Library | Looks up competitors' public ads in Meta's Ad Library. | The competitor's name and country only — never customer data. |
| Searches public posts mentioning the brand or competitors. | Brand/competitor names as search terms only — never customer data. | |
| YouTube Data API (Google) | Searches public videos mentioning the brand or competitors. | Brand/competitor names as search terms only — never customer data. |
| Bing Webmaster Tools og IndexNow | Retrieves your Bing figures and submits our own pages for indexing. | IndexNow receives only geoa.app's own addresses. |
Transfers outside the EU
The infrastructure sits in the EU, but the AI model call does not: the prompt is sent to the provider, and it may contain your brand knowledge, article text and verified company facts — including named individuals. That is a real transfer, and it deserves to be stated here rather than buried in a footnote. The "Basis" column in the table above shows what each individual transfer rests on.
Consent first
Statistics and marketing scripts stay off until you actively opt in via our consent banner. You can change your choice at any time through "Cookie settings" in the footer. Details: privacy policy · cookie policy · terms.