Privacy Policy
Effective date: 22 September 2026
ALL1.AI ("ALL1.AI", "the Service", "we", "us", "our") is operated by [Company legal name], [Registered business address]. ALL1.AI is available at https://all1.ai.
This policy explains, in plain language, what information ALL1.AI collects, why we collect it, who it is shared with, how long we keep it, and how you can get rid of it. It covers the Google account data we receive when you choose to connect Google Search Console.
Our Terms of Service sit alongside this policy.
1. What ALL1.AI does
You give ALL1.AI a website address. ALL1.AI looks at that website the way anyone on the public internet can look at it — its pages, its DNS records, its TLS certificate, its public registration record, its response headers, its speed — and turns what it finds into a scored report with a plan of suggested improvements. An AI assistant can answer questions about that report.
If you want figures that are not public — how your own site actually performs in Google Search, for example — you can connect your Google account. That is optional. Everything else works without it.
2. Information we collect
2.1 Information you give us
- Account details. Your name and email address, and a password (stored only as a one-way hash) if you set one. If you sign in with Google or another provider, we receive your name, email address and the provider's account identifier from that provider instead.
- Website addresses you submit for analysis, and any claim you make that you own one of them.
- Assistant conversations. The questions you type into the AI assistant and the answers it returns are stored so the conversation has a history and so we can count usage against your plan. If you use the assistant before signing in, the conversation is stored against your browser session rather than a named account.
- Anything you send us by email when you contact support.
2.2 Google account data, if you connect Google
Only collected if you explicitly connect a Google account for Search Console. See section 3.
2.3 Other connected services
If you connect a service such as Cloudflare, we store the API token you supply, encrypted, so the Service can read the settings you have given it permission to read.
2.4 Information about the websites you analyse
Public information about the website itself: its pages and HTML, DNS records, mail records (SPF, DKIM, DMARC, MX), TLS certificate details, public domain registration (RDAP/WHOIS) records, HTTP response headers, hosting and network details, a rendered screenshot of the site, measured performance, and public mentions of the site in search results.
This is information anyone can retrieve about a publicly reachable website. We do not sign in to the site, we do not attempt to access anything behind a login, and we do not bypass any access control.
2.5 Technical information
Standard server logs: IP address, browser user agent, the pages requested and when. These are used to keep the Service running, to apply rate limits, and to investigate abuse.
3. Google user data: exactly what we request and why
Connecting Google is optional and you are shown what you are agreeing to before Google asks you to approve it.
3.1 Signing in with Google (optional)
If you choose "Sign in with Google", we receive your basic profile information — your name, email address, profile picture and Google account identifier (openid, email, profile). We use it only to create and identify your ALL1.AI account. We do not use it for anything else.
3.2 Google Search Console (optional)
| Scope requested | What it lets us read | Why we ask for it |
|---|---|---|
https://www.googleapis.com/auth/webmasters.readonly |
The list of Search Console properties on your Google account; search performance data (clicks, impressions, average position, queries and pages); submitted sitemaps; and the URL Inspection result for a URL on a property you own | To show you, inside your own ALL1.AI report, how the website you asked us to analyse actually performs in Google Search — which pages and queries bring visits, whether your sitemap is registered, and whether Google can index a given page |
This scope is read-only. It does not permit ALL1.AI to change anything in your Search Console account, submit or remove sitemaps, request indexing, or add or remove users.
We ask Google for offline access (a refresh token) so that your report can be refreshed on a schedule without making you sign in to Google again every time. You can end that access at any time — see section 8.
3.3 Google Business Profile
ALL1.AI does not request access to Google Business Profile today. If we add it, we will ask for your permission separately at that time, describe the scope here before it is requested, and use it only to show your own business listing information inside your own report.
3.4 Google data that reaches ALL1.AI without an account connection
ALL1.AI uses the Google PageSpeed Insights API to measure the speed of the website you asked us to analyse. This call sends the public address of that website to Google. It sends no information about you and requires no Google account.
4. How we use Google user data
We use the Search Console data described above only to:
- show you the search performance of the website you asked us to analyse, inside your own report;
- work out findings and suggested improvements for that website in that report;
- answer your questions about your own report in the AI assistant;
- refresh those figures when your report is updated.
We do not:
- use Google user data for advertising of any kind, or to build advertising profiles;
- sell, rent or trade Google user data;
- make Google user data available to other ALL1.AI users, or include it in any public or shared page;
- allow anyone to read your Google user data except a small number of our staff, and then only when you ask us for support or when we must do so to fix a fault or meet a legal obligation;
- use Google user data to train machine learning or AI models.
When the AI assistant writes the summary of your report or answers your question, figures drawn from your Search Console data may be included in that request to the AI provider that generates the text (see section 6). We never send your Google access token or refresh token to an AI provider, and we do not authorise any AI provider to use your content to train their models.
5. Where your data is stored and how it is protected
- Access tokens, refresh tokens and API keys for connected services are encrypted before they are written to our database. They are never returned to the browser, never placed in page state, and never written to our logs.
- Records of connection attempts store only the status, the timing and an error code — never the credential itself.
- Proof that a connection is working expires within 24 hours (or at the token's own expiry, whichever is sooner) and must be re-checked against the provider, so a stale grant cannot keep a door open.
- A scheduled job erases expired connection material.
- Private data obtained through a connected account — your Search Console figures, for example — is kept in a per-account private store and is not written into the public analysis records that describe a website.
- Access to production systems is limited to the people who operate the Service.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and any regulator we are required to notify.
6. Who we share your information with
We do not sell your personal information, and we do not share it for anyone else's advertising.
We share information only with the service providers that make ALL1.AI work, and only as far as each needs:
| Purpose | Provider |
|---|---|
| Hosting, databases and backups | [Hosting provider] |
| Generating written summaries and answering assistant questions | Groq, Anthropic and OpenAI. Additional model providers may be enabled over time; the current list is always available from us on request |
| Measuring page speed for the site being analysed | Google (PageSpeed Insights API) |
| Reading your own search performance, if you connect it | Google (Search Console API) |
| Reading your own DNS or CDN settings, if you connect it | Cloudflare |
| Finding public mentions of the site being analysed | Brave Search |
| Public domain registration and network lookups for the site being analysed | RDAP and WHOIS registries; Team Cymru IP-to-network lookup |
| Sending email such as password resets | [Email delivery provider] |
We may also disclose information if we are legally required to, or where it is necessary to protect our rights, our users or the public — for example when investigating fraud or abuse of the Service.
If ALL1.AI is ever sold or merged, your information may transfer to the buyer. We will tell you before that happens and the buyer will be bound by this policy or one no less protective.
7. How long we keep things
| What | Kept for |
|---|---|
| Account details | Until you delete your account |
| Connected-account tokens and API keys | Until you disconnect the service or delete your account, whichever comes first; expired material is erased automatically |
| Search performance data pulled from your Google account | Until you disconnect Google or delete your account; it is deleted when you do |
| Reports and scores about a public website | Retained so the report can show change over time, and so the site's history is not lost when one person stops using the Service |
| Assistant conversations | Until you delete them or delete your account. Conversations started before you sign in are kept against your browser session and expire with it |
| Server and security logs | Up to 12 months |
When you delete your account we delete or anonymise your personal information within 30 days, except where we must keep something to meet a legal obligation.
8. Your choices, and how to switch Google access off
Disconnect inside ALL1.AI. Go to your account's connections page and disconnect the service. This deletes our copy of the credential and stops ALL1.AI from using it.
Revoke at Google. Disconnecting inside ALL1.AI removes our copy of the token but does not itself cancel the grant recorded in your Google account. To remove ALL1.AI's access at Google as well, open https://myaccount.google.com/permissions, select ALL1.AI and choose "Remove access". We recommend doing both.
Delete your account. You can delete your ALL1.AI account from your profile settings, which removes your account data as described in section 7.
Access, correction, export and complaint. Depending on where you live, you may have the right to ask for a copy of the personal information we hold about you, to have it corrected, to have it deleted, to object to or restrict certain processing, and to complain to your local data protection authority. Write to privacy@all1.ai and we will respond within the time the law allows. We will not treat you differently for exercising these rights.
9. Cookies and browser storage
ALL1.AI does not use advertising cookies and does not run third-party advertising or analytics trackers.
Cookies we set:
| Cookie | Purpose |
|---|---|
| Session cookie | Keeps you signed in and keeps your session together. Required |
XSRF-TOKEN |
Protects forms against cross-site request forgery. Required |
a1_device |
Records whether your screen is phone-sized or desktop-sized, so the right layout is served on the first paint |
a1_shell |
Remembers it if you override that choice yourself (Auto, Phone or Desktop) |
a1_cuba |
Remembers the desktop layout you picked in the Customize panel |
googtrans |
Set by the Google Website Translate widget if you choose a language. Only present if you use it |
Browser storage (localStorage and sessionStorage). ALL1.AI keeps your display preferences in your own browser rather than on our servers. These are stored under keys beginning a1. and cover things such as the theme, language, layout, fonts, colour palette, background, loading style, performance mode, and whether you have seen a particular notice. A separate group records what belongs to you in the Service — your cart, chosen plan, domain claims, recorded connections, usage and notifications.
These values stay in your browser, are never transmitted to advertisers, and can be cleared at any time using Forget my settings in the Customize panel, or by clearing site data in your browser. Clearing them does not delete your account.
Guest use. You can use parts of ALL1.AI without an account. A guest is identified by a pass held in your own browser storage, plus the session cookie. If you later supply an email address to raise a guest limit, that email is treated as personal information under this policy.
10. Google API Services User Data Policy
ALL1.AI's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
That policy is published at https://developers.google.com/terms/api-services-user-data-policy.
11. Children
ALL1.AI is a tool for people who run websites and businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 16 (or under 13 where that is the applicable age). If you believe a child has given us personal information, write to privacy@all1.ai and we will delete it.
12. International transfers
ALL1.AI and the providers listed in section 6 may process information in countries other than your own, including the United States. Where the law requires it, we rely on appropriate safeguards such as the European Commission's standard contractual clauses for those transfers.
13. Changes to this policy
If we change this policy we will update the effective date at the top and, where the change materially affects how we handle your information, tell you by email or with a notice in the Service before it takes effect. If a change means we need to request additional Google scopes, we will publish the change here first and ask for your consent separately.
14. Contact us
[Company legal name]
[Registered business address]
Privacy questions and data requests: privacy@all1.ai
Everything else: support@all1.ai