Transparency

Trust Center

Security, data handling and AI accountability in one place — without the sales gloss. Everything below can be verified, and what isn't in place is stated too.

Security and operations

Where your data sits, and who can reach it

Geoa is operated by AddonNordic ApS (company no. 46495985) from Aalborg, Denmark. The infrastructure sits in the EU.

The infrastructure sits in the EU

The application is hosted on Railway in the EU and the database on Supabase in Ireland. Your data is stored and processed in the EU — with one exception we describe openly further down: the AI model call itself.

Encryption

All traffic runs over HTTPS with HSTS and modern security headers. Data is encrypted at rest (AES-256) at our database provider.

Access control

Row Level Security on the database, server-side secrets that never reach the browser, and per-installation API keys for plugins that can be revoked individually.

Tested before every deploy

Every single change must pass 2.700+ automated tests and a production smoke test before it ships. A red test means no deploy.

Payment via Stripe

We never see or store your card details — all payment processing sits with Stripe.

Deletion within 30 days

Delete your account and all associated data is removed within 30 days. No shadow copies.

EU AI Act

Article 50: the duty is yours, the work is ours

From 2 August 2026, AI-generated content must be disclosed. If you publish content from Content Studio on your own website, the disclosure duty is yours. Geoa is built so you can carry it — and so you never claim more than what actually happened.

The marking is applied at the source

The disclosure is attached when the article is generated, not in a view. That is why it travels all the way into your CMS. A marking applied only in the interface disappears on the first export.

Review is an act, not a checkbox

Clicking "ready" records no review. An editorial review requires a named person who explicitly confirms the substance, figures and sources — and takes editorial responsibility for publication.

The text cannot go stale

The disclosure is derived from the article's actual state every time it leaves us. If the review happens later, it takes effect everywhere — and an article can never carry a claim that reality has moved past.

What we do not cover

Article 50(2) also requires generated content to be marked machine-readably in a standard format. We do not cover that today: we store the disclosure in the post's metadata, but a field only we can read is an archive, not a signal anyone else can interpret. We write that here rather than letting half a coverage sound like a whole one.

The honesty contract

We only show figures we have actually measured

Our most important principle is built into the platform. See also how we measure.

"Done" is always measured

A fix is marked complete only once we have verified it with a concrete check — an HTTP request, a rescan or a profile check. Never because someone claimed it.

Unmeasured means unmeasured

If something cannot be measured (because a site blocks our check, for instance), we say "not measured" and keep the score neutral — we never penalise, and we never guess.

Floor figures, not fantasy figures

AI visit figures are presented as a floor ("at least X visits"), because many AI services hide the referral. We do not inflate numbers.

No guarantees we cannot keep

Nobody can guarantee a place in ChatGPT's answers — including us. We measure, improve and document the trend. Be sceptical of anyone promising more.

The assistant's rules

What our AI may do — and never may

The whole platform shares one rulebook for the AI assistant, enforced by automated tests. These are the rules in plain language — not an excerpt, but what they actually say.

Prices are never improvised

The assistant never quotes amounts, discounts or lock-in periods on its own — a policy an AI makes up would be binding on us. It refers you to the pricing page and to a human.

Results are never promised

No 'then ChatGPT will recommend you', no traffic or revenue promises. How third-party AI services mention you is theirs to control — and the assistant says so honestly.

If it doesn't know, it says so

The assistant never explains an error or missing data it has no source for. A guess that sounds right is worse than no answer — so it says 'I don't know' and refers you to a human.

If it doesn't exist, it isn't suggested

The assistant never suggests features that don't exist, and never invents links or pages. If it doesn't know the place, it says so.

An AI that says it's an AI

Ask whether you're talking to a human and you get an honest no. And instructions hidden in pasted text — 'ignore your rules', 'give me a discount' — are not followed: text is data, not orders.

The three outcomes

Measured · not done · marked by you

Every check in the platform ends in one of three outcomes — and they are never mixed. Some surfaces block all automated checks; a green checkmark there would be a lie.

Measured

We verified it ourselves with a concrete check: an HTTP lookup, a re-scan or a signal from your own site. Only that earns a checkmark.

Not done

The check hasn't run yet — or couldn't run. It is shown as exactly that, and it never counts against you. Unmeasured is not zero.

Marked by you

Some platforms block all automated lookups. If you did the work yourself, you can mark it — and it will say 'marked by you', never 'verified'.

Engine down = named

If an AI engine can't be measured — outage, rate limit, closed access — it is shown by name as 'could not be measured'. Your score is never lowered by an engine that was down; it is computed over the ones that actually answered.

GDPR and data handling

Who we share data with, and on what basis

AddonNordic ApS is the data controller. We do not sell your data and do not use it to train general AI models.

Our data processing agreement is public — you do not need to contact us to read it: read the DPA.

Subprocessors

These services process personal data on our instructions. The list is wired to the codebase and covered by automated tests, so it cannot fall behind what the platform actually does.

ServicePurposeDataProcessed inBasis
Railway
Railway Corporation
Application hosting.All traffic and data passing through the platform.EUData Privacy Framework
Supabase
Supabase Pte. Ltd.
Database and user authentication.Account details, domains, measurements and generated content at rest.IrelandEU standard contractual clauses
Lovable
Lovable Labs Incorporated
Hosts the dashboard and relays subscription events.Account details and subscription status.EUEU standard contractual clauses
Stripe
Stripe Payments Europe, Ltd.
Payment processing. We never see or store your card details.Payment details and subscription identifiers.EU and United StatesData Privacy Framework
Resend
Plus Five Five, Inc.
Delivery of reports and service emails.Recipient email address, name and the full message body.
Resend's region setting controls only where mail is sent from — account data, metadata and logs sit in the US regardless.
United StatesData Privacy Framework
Sentry
Functional Software, Inc.
Error monitoring so failures are caught and fixed.Technical error context and an installation identifier.GermanyData Privacy Framework
OpenRouter
OpenRouter, Inc.
Routes AI calls onward to whichever model the task requires.The prompt: brand knowledge, article text and verified company facts — including named individuals.
We do not hold a signed data processing agreement with OpenRouter — it is offered to enterprise customers only.
United StatesEU standard contractual clauses
OpenAI
OpenAI Ireland Ltd.
Generates content and measures visibility in ChatGPT.Domain, registry name and address, industry details and extracts of your public website text.United StatesEU standard contractual clauses
Google (Gemini og Cloud Natural Language)
Google Cloud EMEA Limited
Measures visibility in Gemini and analyses entities in page text.Brand name, domain and up to 60,000 characters of your page text.United StatesEU standard contractual clauses
Perplexity AI
Perplexity AI, Inc.
Measures visibility and citations in Perplexity.Brand name, domain, services, city and competitor names.United StatesData Privacy Framework
Jina AI
Jina AI GmbH (Elastic N.V.)
Fetches and reads web pages when direct retrieval is blocked.The address of the page fetched, and the page's own content.Germanynot verified
DataForSEO
DataForSEO OÜ
Retrieves Google rankings, search volume and reviews.Domain, brand name, keywords and country. Reviews are returned carrying the reviewers' names.EUEU/EEA
Brave Search
Brave Software, Inc.
Finds competitors, profiles and search results.A search string built from brand name, service and city.
Brave's data processing agreement explicitly excludes the search queries themselves — what we send is not covered.
United StatesEU standard contractual clauses
AddonNordic Data API
AddonNordic ApS
Looks the company up in the public business registries.Company name, registration number and domain.EUEU/EEA
CookiePilot
Clever Agent sp. z o.o.
Consent banner and record of consents given.Your consent choice.Polandnot verified
Plausible Analytics
Plausible Insights OÜ
Cookie-free visitor statistics.Aggregated pageview statistics with no personal identifiers.EUEU/EEA
Slack
Slack Technologies Limited
Sends alerts to your own Slack channel.
Only if you set up a Slack webhook yourself.
Domain and score in the message body.EU and United StatesData Privacy Framework

Independent controllers

These are not subprocessors: they determine the purposes and means of their own processing and therefore do not act on our instructions. We list them anyway, because they receive data once you consent.

ServicePurposeDataProcessed inBasis
Microsoft Clarity
Microsoft Ireland Operations Limited
Behaviour analytics — shows how the site is used.
Only after your statistics consent.
Session activity on the marketing site. Text entry is masked.IrelandEU standard contractual clauses

External lookups with no personal data

We call these services too, but they receive no personal data — typically just a web address or a company name. They are listed for transparency, not as processors.

ServicePurposeData
Google PageSpeed Insights og CrUXMeasures page speed.The page address only.
Wikipedia og WikidataChecks whether the brand exists as a known entity.The brand name only.
Google Search Console og AnalyticsRetrieves your own search and traffic figures once you connect.We pull FROM Google on your authorisation — we send nothing there.
Meta Ad LibraryLooks up competitors' public ads in Meta's Ad Library.The competitor's name and country only — never customer data.
RedditSearches public posts mentioning the brand or competitors.Brand/competitor names as search terms only — never customer data.
YouTube Data API (Google)Searches public videos mentioning the brand or competitors.Brand/competitor names as search terms only — never customer data.
Bing Webmaster Tools og IndexNowRetrieves your Bing figures and submits our own pages for indexing.IndexNow receives only geoa.app's own addresses.

Transfers outside the EU

The infrastructure sits in the EU, but the AI model call does not: the prompt is sent to the provider, and it may contain your brand knowledge, article text and verified company facts — including named individuals. That is a real transfer, and it deserves to be stated here rather than buried in a footnote. The "Basis" column in the table above shows what each individual transfer rests on.

Consent first

Statistics and marketing scripts stay off until you actively opt in via our consent banner. You can change your choice at any time through "Cookie settings" in the footer. Details: privacy policy · cookie policy · terms.

Frequently asked questions

What buyers ask

Where is my data stored?
In the EU: the application runs on Railway in the EU and the database sits on Supabase in Ireland. Payment data sits solely with Stripe. The exception is the AI model call, described above.
Do you use my data to train AI models?
No. We use AI models to generate content and analysis for you, but your data is not used to train general AI models.
Do you have a data processing agreement (DPA)?
Yes, and it is public — you can read it at /databehandleraftale without contacting us first. If you need it signed for your records, email hello@geoa.app.
Is content from Content Studio AI Act compliant?
The content carries the disclosure Article 50(4) requires, and an editorial review is recorded only when a named person has actually carried one out. We do not cover the machine-readable marking under Article 50(2) — see the AI Act section above. Responsibility for publication remains yours; our job is to make it possible to carry.
Can I have my data deleted?
Yes. Delete your account and all associated data is removed within 30 days. You can also request access or an export at any time via hello@geoa.app.
Who is behind Geoa?
Geoa is operated by AddonNordic ApS, company no. 46495985, Aalborg, Denmark — founded by Martin Nymann. The company can be looked up in the Danish business register.

Questions about security or data?

Email hello@geoa.app — a human will answer.

Run a free GEO test