Skip to content

Backend API · Data Processing

Data Processing Map — Backend API

A technical map of what `api.toobloom.com` stores, processes, and forwards — derived from the backend repository.

This page is a structured transparency document. It describes the data flows the codebase demonstrates, including gaps and dependencies on production configuration where relevant.

Inbound flows

Data the backend receives and stores

These flows are supported by specific controllers and models in the repository.

Authentication

Account creation and login

POST /api/auth/register and /api/auth/login. Stores name, email (normalized), bcrypt password, plan, status, role. Issues time-limited Sanctum bearer tokens (8 hours).

Consent recording

GDPR consent at registration

A consent record is created at registration with consent date, policy version, and a hashed IP address. Required by GDPR Art. 7. Included in user data exports.

Workspace configuration

Site and property identifiers

POST/PUT /api/sites. Stores site name, URL, GA4 property ID, Search Console site URL, GTM container ID, and optional IDs for Business Profile and Ads.

Historical data

Keyword strings and GSC performance metrics (historical)

POST /api/keywords/sync — DISABLED since 2026-07-23: the endpoint returns 410 and no longer reads or writes any data. Historical rows already saved (keyword strings, clicks, impressions, CTR, position, originating from the user's Search Console) remain in the database until the user deletes their account.

Reports

Explicitly saved report snapshots

POST /api/sites/{site}/reports. Stores period dates, generated_at timestamp, and content_json (aggregated analytics/SEO metrics). Immutable once saved.

Billing

Invoices and payment logs

Managed by admin workflows and payment provider callbacks. Stores invoice records (plan, amount, status, dates) and payment event logs. Retained per Italian fiscal law.

Outbound flows

Data the backend sends to third parties

External systems that receive data from the TooBloom backend.

Email / SMTP

Transactional notifications

Email verification, password reset, plan request confirmation, and admin notifications are sent via Laravel's mailer to a configured SMTP provider. Email addresses and notification content are transmitted.

OpenAI API

AI feature proxy

POST /api/ai/reports/monthly forwards aggregated performance metrics and user-composed prompts to OpenAI's Chat Completions API. No OAuth credentials are included. POST /api/ai/keyword-clusters and /api/ai/keyword-trend-analysis are DISABLED since 2026-07-23 (410, no call to OpenAI). Governed by OpenAI's API terms.

Payment provider

Stripe (sole active provider)

Payment processing involves transmitting invoice and transaction data to Stripe, the sole active payment provider. PayPal has been permanently decommissioned and no longer receives any data: invoices issued while it was active retain only the historical transaction identifiers (paypal_order_id, paypal_payment_id), kept solely for the 10-year fiscal retention obligation, with no new transmissions to PayPal.

Data rights implementation

Rights implemented in the codebase