Legal

Privacy Policy

Last updated

Who this covers

This policy covers the AIOptimization.ca website and its current features: the browser-only Vibe Build Optimizer, live website readiness scan, OpenAI discovery snapshot, private accounts, subscription monitoring, and early-access list. AIOptimization.ca is operated by NAIBIC, 123 March St, Sault Ste. Marie, ON P6A 2Z5, Canada. Our published contact address is info@naibic.com.

Accounts, monitoring, and billing

If you create an account, our managed authentication and database provider stores your account identity and the site settings, monitoring history, and recommendations associated with your workspace. We also store the Stripe customer and subscription identifiers, plan, billing status, renewal timing, and cancellation status needed to provide paid access. We do not store complete card numbers or card security codes.

Stripe receives and processes the billing and payment details you enter at checkout or in its customer portal. Stripe sends signed subscription status events to our server so we can grant, update, or remove paid access. We keep account and billing records while the account is active and as reasonably required for security, support, accounting, and legal obligations. You may request deletion of eligible account data by emailing info@naibic.com.

Website URLs you submit

When you run a readiness scan, the address you enter is sent to our server, checked against our safety rules, and used to make one read-only GET request for that page. If the page returns an HTTP redirect we make one further read-only GET request for each hop, up to three redirects and four page requests in total, revalidating safety rules at every hop. We read the HTML that is returned and produce your report in the same request. We never fetch other pages, assets, sitemaps, or robots.txt.

Submitted URLs and scan results are processed transiently. We do not save them to our database and they are not retained after the response is returned to your browser. To measure whether scans actually work, we keep one anonymous aggregate record per scan containing only an event type (scan succeeded, failed, or was rate limited), a short outcome code, a coarse duration bucket rather than an exact duration, and a timestamp. That record contains no domain, URL, IP address, header, page content, or scan finding, no email address, and no identifier or hash of any kind, and we set no tracking cookie for it. Ordinary short-lived operational logs from our hosting provider may briefly record that a request occurred.

Business details you submit for a discovery snapshot

If you run an OpenAI discovery snapshot, the business name, public website address, category, offering, market, and any competitor names you enter are sent to our server and used only to build your result in that same request. We then send three buyer questions from our server through the Lovable AI gateway, which routes them to the OpenAI model gpt-5.4-mini. Those questions contain only your category, offering, and market, but never your business name, domain, or a competitor name, so the model is not primed toward a result. Requests are made with our own server-side gateway credential, include the Responses API setting store: false, and are never made from your browser. That setting tells the API not to store the generated response for later retrieval through the API. The gateway and the model provider may otherwise retain API data under their applicable service policies.

Your inputs, the questions, the answer text, the returned source links, and the resulting counts are processed transiently. None of it is written to our database or retained after the response reaches your browser. As with scans, we keep one anonymous aggregate record per snapshot containing only an event type (snapshot started, succeeded, or failed), a short outcome code, a coarse duration bucket, and a timestamp. It contains no business name, domain, category, location, question, answer, source link, competitor, IP address, or email address, and no tracking cookie.

If you deliberately choose a paid monitoring plan after a free result, we copy only the public business setup and selected plan into temporary storage in that browser tab. This lets the account setup form start with the information you already entered. It is cleared after you save the setup, expires after two hours, and is not sent to our server unless you review and save it.

Vibe Build Optimizer content

The initial Vibe Build Optimizer runs in your browser. The outcome, current-state notes, preservation rules, constraints, platform choice, task type, and generated instruction pack are not sent to our server when you generate the local pack. We record whether an instruction pack was generated. No form value is included in that event.

If you explicitly select Review this brief with AI, the generated instruction pack is sent once to our server and to DeepSeek, whose deepseek-flash model drafts that review. We do not save the instruction pack or review in our database. The request uses our own server-side credential, sends no identifier for you, and is bounded in length and time. DeepSeek may retain API data under its applicable service policies. This review analyses the words of your brief only; it is drafting help, not a measurement of any AI assistant. We keep only a content-free aggregate event and the UTC date with a daily reservation count. Neither record contains the brief, result, project detail, identity, IP address, URL, email address, cookie, or tracking identifier.

Early-access details you give us

If you join early access we store your email address, the time you gave consent, the plan interest you select (free snapshot, Monitor, Compete, or not sure), and a short non-sensitive source label such as the page you signed up from. We use these only to contact you about AIOptimization.ca early access and launch updates. We do not sell or rent this information, and we do not share it for advertising.

The early-access table is not readable from the browser. Only our server-side code can read or write it. You can ask us to correct or delete your record at any time by emailing info@naibic.com.

What we never ask for

We do not ask for and cannot accept website credentials: no CMS, hosting, DNS, GitHub, analytics, or advertising logins. We never modify, publish to, or connect into your website. Every change to your site remains yours to make.

Service providers

Third-party providers process data on our behalf so this service can run: an application hosting and edge network provider whose outbound-request controls keep scans on the public internet, a managed database and authentication provider that stores account and early-access records, Stripe, which processes subscriptions and payment details, OpenAI, which receives the three buyer questions used for a discovery snapshot and performs the web search behind them, and DeepSeek, which receives a generated build brief only after an explicit AI review request. These providers may process data outside Canada.

Analytics and tracking

This release does not run third-party advertising or analytics trackers, and it does not use cookies to profile you across sites. Product measurement consists of the anonymous aggregate scan, snapshot, monitoring-interest, build-generation, and AI brief-review events described above. They are written on our server and are not readable from the browser.

Accuracy of results

Readiness results are informational. They describe the HTML one page returned at one moment in time and are not a guarantee of search placement, AI recommendation, or business outcome.

Contact

Email privacy requests to info@naibic.com, or write to NAIBIC, 123 March St, Sault Ste. Marie, ON P6A 2Z5, Canada.

Read the Terms of Service