Legal
Privacy Policy
Your privacy is important to us. This policy explains how Bellio Digital collects, uses, stores, and protects your information when you use our platform.
Google API Services: Bellio Digital’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See for full details.
Table of Contents
Information We Collect
Account Information
- When you register for an account, we collect your name, email address, password (stored in hashed form), and account type (marketing agency, business, freelancer, or other).
- If you sign in through Google or GitHub OAuth, we receive your name, email address, and profile image from those providers. We do not receive or store your Google or GitHub passwords.
- We may collect an invitation code or referral code if provided during registration.
CRM & Client Data
- If you use our CRM features, you may input client and lead information including names, email addresses, phone numbers, company details, websites, addresses, industry, company size, business summaries, and notes.
- You may also store contact information (first name, last name, email, phone, role) for individuals associated with your clients.
- Credentials and access details you choose to store for client accounts (domain, hosting, platform information) are encrypted at rest.
Content & Documents
- Content you create, generate, or upload through our writing system, including article drafts, outlines, keywords, research data, and published documents.
- Images you upload for description or analysis, and any files attached to projects or deliverables.
Automatically Collected Information
- IP address, browser type and version, operating system, referring URLs, pages viewed, and timestamps of your visits.
- Device information and screen resolution for responsive design purposes.
Google Account Data (Reporting Features)
- If you connect your Google account for reporting purposes, we request access to the following specific OAuth scopes based on the features you enable:
- userinfo.email (googleapis.com/auth/userinfo.email) — Your Google account email address, used solely to identify your account during the OAuth connection process and to associate the correct Google account with your reporting integration.
- analytics.readonly (googleapis.com/auth/analytics.readonly) — Read-only access to your Google Analytics 4 (GA4) property data, including website traffic, user behavior, conversions, and audience metrics. This scope is required because our reporting features need to retrieve comprehensive analytics data across multiple GA4 report types (traffic acquisition, engagement, conversions, audience demographics) to generate consolidated white-label reports for your clients. More limited scopes do not provide sufficient access to the full range of GA4 reporting dimensions and metrics needed to produce meaningful, comprehensive reports.
- webmasters.readonly (googleapis.com/auth/webmasters.readonly) — Read-only access to your Google Search Console data, including search queries, impressions, clicks, click-through rates, and average position data. This data is used to generate SEO performance reports showing your clients’ organic search visibility.
- business.manage (googleapis.com/auth/business.manage) — Access to read and manage your Google Business Profile listings, including business information, reviews, Q&A, posts, and performance insights. This scope is required to provide GBP management features and to generate local SEO reports showing listing performance, review activity, and search/map visibility.
- This data is used solely to generate reports and analytics within our platform on your behalf. See Section 4 ("Google API Services — Limited Use Disclosure") for detailed information about how we handle Google user data.
How We Use Your Information
Service Delivery
- To provide, maintain, and improve our platform, including AI-powered content generation, SEO optimization, CRM management, white-label reporting, and project management.
- To personalize your experience, process transactions, and manage your subscription and credits.
- To generate reports using connected Google services data (GA4, GSC, GBP) that you have explicitly authorized.
AI Content Processing
- When you use our content generation features, text inputs (such as topics, keywords, business descriptions, and instructions) are sent to third-party AI providers (OpenAI and Anthropic) for processing. These providers process your inputs to generate content and return results to our platform.
- We may also send content to Originality.ai for plagiarism and readability analysis when you use our originality checking features.
- AI providers process data according to their own privacy policies and data handling practices. We do not send your personal account information (name, email, password) to AI providers — only the content inputs necessary for generation.
Communications
- To send transactional emails including account verification, password resets, magic link sign-ins, two-factor authentication codes, transaction receipts, team invitations, and role update notifications.
- To send service-related communications about your account, subscription, or platform updates.
Security & Compliance
- To detect and prevent fraud, abuse, and security incidents using reCAPTCHA and other security measures.
- To comply with legal obligations and enforce our terms of service.
We may use aggregated, anonymized data to analyze usage trends, improve our AI models and platform features, and conduct internal research. This data cannot be used to identify you personally.
Third-Party Services & Integrations
Our platform integrates with the following categories of third-party services. Each has its own privacy policy governing its use of data:
Authentication & Security
- Google OAuth and GitHub OAuth for single sign-on authentication.
- Google reCAPTCHA v3 for bot detection and abuse prevention on authentication forms.
AI & Content Processing
- OpenAI (GPT-4o, o3-mini, o1 models) — for content generation, web search-augmented generation, and text processing.
- Anthropic (Claude 3.5 and Claude 4 models) — for content generation, agentic writing workflows, and web search-augmented generation.
- Originality.ai — for plagiarism detection and readability scoring of generated content.
SEO & Research
- DataForSEO — for keyword research, SERP analysis, and location data.
- SurferSEO — for content optimization scoring and SEO analysis.
- Firecrawl — for website crawling, site mapping, and content extraction.
- Google Custom Search API — for search volume and competition analysis.
Google APIs (Reporting & Productivity)
- Google Analytics 4 (GA4) API (scope: analytics.readonly) — read-only retrieval of website traffic, engagement, conversion, and audience data for generating white-label analytics reports.
- Google Search Console API (scope: webmasters.readonly) — read-only retrieval of search performance data (queries, impressions, clicks, position) for generating SEO performance reports.
- Google Business Profile API (scope: business.manage) — retrieval and management of business listing data, reviews, Q&A, posts, and performance insights for local SEO reporting and GBP management.
- Google Identity (scope: userinfo.email) — used during OAuth to identify your Google account and associate it with your reporting integration.
- Google Drive, Docs, Sheets, and Slides APIs (via Service Account) — for exporting documents to Google Drive when you explicitly request it.
Payments
- Stripe — for processing credit card payments, managing subscriptions, and handling billing. Stripe receives your payment card details directly; we do not store your full card number on our servers.
- We use SMTP-based email delivery for all transactional emails (verification, password reset, OTP codes, receipts, notifications).
We do not sell your personal information to any third party. We only share data with service providers to the extent necessary to operate our platform, and each provider is contractually or technically limited to using your data solely for the purpose of delivering their service.
Google API Services — Limited Use Disclosure
Bellio Digital's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes We Request & Why
- userinfo.email — To identify which Google account you are connecting and to display your email in our integration settings. This is the minimum scope needed for account identification during OAuth.
- analytics.readonly — To read your Google Analytics 4 property data for generating white-label analytics reports within our platform. We request the readonly scope (rather than full analytics access) because we only need to read data, never modify it. We require analytics.readonly specifically (rather than more limited scopes) because our reporting features pull data across multiple GA4 report types — including traffic acquisition, user engagement, conversion tracking, and audience demographics — to produce comprehensive, consolidated client reports. No narrower scope provides access to this full range of reporting dimensions and metrics.
- webmasters.readonly — To read your Google Search Console data for generating SEO performance reports showing search queries, impressions, clicks, CTR, and average position. We request only readonly access because we never need to modify your Search Console configuration.
- business.manage — To read and manage your Google Business Profile listings for local SEO reporting and GBP management features, including viewing reviews, responding to reviews (with your authorization), managing Q&A, and retrieving performance insights (search views, map views, customer actions). The business.manage scope is required because Google does not offer a more limited read-only GBP scope — this is the only available scope for accessing Business Profile data.
How We Use Google Data
- All data obtained through these scopes is used solely to provide and improve the user-facing reporting and management features you have explicitly enabled within our platform.
- We do not transfer Google user data to third parties except: (a) with your explicit consent, (b) as necessary to provide the service (e.g., displaying your data in a report you generate), (c) for security purposes such as investigating abuse, or (d) to comply with applicable law.
- We do not use Google user data for advertising, retargeting, or interest-based profiling.
- We do not allow humans to read your Google user data unless: (a) you have given affirmative consent to view specific data, (b) it is necessary for security purposes (e.g., investigating a bug or abuse), (c) it is aggregated and anonymized for internal operations, or (d) it is required to comply with applicable law.
- Google OAuth tokens used for reporting integrations are encrypted at rest using AES-256 encryption.
Revoking Access
- You can disconnect your Google account at any time from Settings (Google Connection section). Upon disconnection, we will cease accessing your Google data.
- What we clear when you disconnect: stored OAuth tokens (access and refresh) and connected property IDs (GA4 property, GSC site URL, GBP location) for your report subscriptions.
- What we do not delete: your existing report subscriptions, generated reports, or billing data remain unchanged.
- You can also revoke access directly from your Google Account permissions page at https://myaccount.google.com/permissions.
Data Storage & Security
Infrastructure
- Your data is stored in a PostgreSQL database hosted on secure cloud infrastructure with encryption at rest and in transit.
- File uploads (images, documents) are stored via Vercel Blob Storage (when available) or secure server-side file storage, both protected by access controls.
- Google OAuth tokens for reporting integrations are encrypted using AES-256 encryption with a dedicated encryption key.
- Passwords are hashed using bcrypt before storage; we never store plaintext passwords.
Security Measures
- All data transmission uses TLS/SSL encryption.
- Content Security Policy (CSP), X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, and Permissions-Policy security headers are enforced.
- Two-factor authentication (OTP via email) is available for email/password login.
- reCAPTCHA v3 protects authentication endpoints from automated attacks.
- Rate limiting on OTP attempts prevents brute-force attacks.
- Regular security audits and dependency updates are performed.
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining the highest practical standards and promptly addressing any security incidents.
Your Rights & Data Control
Access & Portability
- You have the right to access all personal data we hold about you. You may request a copy of your data by contacting us.
- You can export your generated documents and reports from the platform at any time.
- If you have connected Google services for reporting, you can view exactly what data is being accessed through your Google Account permissions page.
Correction & Deletion
- You may update your account information at any time through your account settings.
- You may delete your account at any time from Settings (Danger Zone). You must confirm by typing your account email. Upon confirmation, we will immediately revoke your Google OAuth connections, cancel active report subscriptions at Stripe, delete your account and login access, report subscriptions, and generated reports. Payment history and invoices are retained for legal and compliance purposes; Stripe customer records are retained by Stripe.
- You may also request deletion of your account and associated personal data by contacting us. Upon verified request, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as financial records).
- CRM data, client records, and generated content associated with your account will be deleted upon account deletion unless you request a data export first.
Consent Withdrawal
- You may disconnect any linked third-party service (Google, GitHub) at any time without affecting your core account.
- You may revoke Google API access at any time, either through our platform settings or through your Google Account at https://myaccount.google.com/permissions.
EEA/UK/California Residents
- If you are located in the European Economic Area or United Kingdom, you have additional rights under GDPR, including the right to data portability, the right to restrict processing, the right to object to certain types of data processing, and the right to lodge a complaint with a supervisory authority.
- California residents have additional rights under the CCPA/CPRA, including the right to know, the right to delete, and the right to opt-out of the sale of personal information. We do not sell personal information.
Data Retention
Active Accounts
- Your personal information and account data are retained for as long as your account is active.
- Generated content and documents are retained for as long as your account exists or until you delete them.
- Google API data accessed for reporting is processed in real-time and displayed in reports; we do not permanently cache Google API response data beyond what is necessary for report generation.
- AI usage logs (tracking which AI models were used and credit consumption) are retained for billing and audit purposes.
After Account Deletion
- Upon account deletion request, personal data is removed within 30 days.
- Financial transaction records (Stripe payment history, credit transactions) are retained as required by applicable tax and accounting regulations (typically 7 years).
- Anonymized, aggregated usage data may be retained indefinitely for service improvement purposes.
- Backups containing your data are automatically purged within 90 days of account deletion.
White-Label & Agency Partner Data
If you are an agency partner using our white-label features:
Your Responsibilities
- You are the data controller for any end-client data you input into our platform through the CRM, reporting, or content generation features.
- You are responsible for obtaining appropriate consent from your end-clients before inputting their data into our platform or connecting their Google accounts for reporting.
- You must maintain your own privacy policy that discloses your use of third-party platforms (including ours) to process end-client data.
Our Responsibilities
- We act as a data processor for end-client data you input into our platform.
- We will not contact your end-clients directly or use their data for any purpose other than providing our services to you.
- White-label reports and deliverables are branded under your identity and do not expose our platform branding to your end-clients unless you choose to do so.
Children’s Privacy
Our services are intended for business professionals and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us immediately at scheduling@belliodigital.com.
Email Communications
We send the following types of emails, all of which are transactional or service-related:
Account & Security Emails
- Email verification upon registration.
- Password reset links.
- Magic link sign-in links.
- Two-factor authentication (OTP) codes.
- Role update and team invitation notifications.
Billing & Transaction Emails
- Transaction receipts for credit purchases and subscription payments.
- Thank-you confirmations for purchases.
Service Emails
- Package and project status notifications.
- Report-ready notifications when automated reports are generated.
- Deliverable feedback notifications.
We do not send marketing or promotional emails without your explicit opt-in consent. All transactional emails are necessary for the operation of your account.
International Data Transfers
Our platform infrastructure and third-party service providers may process data in various countries, including the United States. By using our platform, you consent to the transfer of your data to these locations.
Where required by law, we ensure appropriate safeguards are in place for international data transfers, such as Standard Contractual Clauses for transfers from the EEA/UK.
Our AI providers (OpenAI and Anthropic) are US-based companies. Content you generate through our platform is processed on their servers and is subject to their respective data handling policies.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or service offerings.
Material changes will be communicated via email to your registered address and by posting a prominent notice on our platform. The "Effective Date" at the top of this page will be updated.
If we change how we use Google user data, we will notify you and obtain your consent before making use of Google user data in any new way not originally disclosed.
Your continued use of our services after such changes constitutes acceptance of the updated policy. If you do not agree to the changes, you should stop using the service and may request account deletion.
Contact Us
If you have any questions or concerns about this privacy policy, our data practices, or wish to exercise any of your data rights, please contact us:
Contact Details
- Email: scheduling@belliodigital.com
- Contact Page: /contact
For Google-specific data concerns, you may also review and manage your Google Account permissions directly at https://myaccount.google.com/permissions.
We aim to respond to all privacy-related inquiries within 5 business days.
Questions About Our
Privacy Practices?
We’re happy to answer any questions about how we handle your data. Reach out to our team anytime.
Contact Us