Authentication
Account creation and login
POST /api/auth/register and /api/auth/login. Stores name, email (normalized), bcrypt password, plan, status, role. Issues time-limited Sanctum bearer tokens (8 hours).
Backend API · Data Processing
This page is a structured transparency document. It describes the data flows the codebase demonstrates, including gaps and dependencies on production configuration where relevant.
Inbound flows
Authentication
POST /api/auth/register and /api/auth/login. Stores name, email (normalized), bcrypt password, plan, status, role. Issues time-limited Sanctum bearer tokens (8 hours).
Consent recording
A consent record is created at registration with consent date, policy version, and a hashed IP address. Required by GDPR Art. 7. Included in user data exports.
Workspace configuration
POST/PUT /api/sites. Stores site name, URL, GA4 property ID, Search Console site URL, GTM container ID, and optional IDs for Business Profile and Ads.
Historical data
POST /api/keywords/sync — DISABLED since 2026-07-23: the endpoint returns 410 and no longer reads or writes any data. Historical rows already saved (keyword strings, clicks, impressions, CTR, position, originating from the user's Search Console) remain in the database until the user deletes their account.
Reports
POST /api/sites/{site}/reports. Stores period dates, generated_at timestamp, and content_json (aggregated analytics/SEO metrics). Immutable once saved.
Billing
Managed by admin workflows and payment provider callbacks. Stores invoice records (plan, amount, status, dates) and payment event logs. Retained per Italian fiscal law.
Outbound flows
Email / SMTP
Email verification, password reset, plan request confirmation, and admin notifications are sent via Laravel's mailer to a configured SMTP provider. Email addresses and notification content are transmitted.
OpenAI API
POST /api/ai/reports/monthly forwards aggregated performance metrics and user-composed prompts to OpenAI's Chat Completions API. No OAuth credentials are included. POST /api/ai/keyword-clusters and /api/ai/keyword-trend-analysis are DISABLED since 2026-07-23 (410, no call to OpenAI). Governed by OpenAI's API terms.
Payment provider
Payment processing involves transmitting invoice and transaction data to Stripe, the sole active payment provider. PayPal has been permanently decommissioned and no longer receives any data: invoices issued while it was active retain only the historical transaction identifiers (paypal_order_id, paypal_payment_id), kept solely for the 10-year fiscal retention obligation, with no new transmissions to PayPal.
Data rights implementation