Skip to content

Backend API · Privacy Policy

Privacy Policy — Backend API

This page applies to `api.toobloom.com`, the Laravel backend that powers the TooBloom app.

The backend stores account data, consent records, workspace configuration, keyword performance data, report snapshots, billing records, and audit logs. It also proxies AI requests to OpenAI.

Data Controller

Who is responsible for this data

Data controller: Elisabetta Monaco, sole trader.
Address: Via Garibaldi 56, 92013 Menfi (AG), Italy.
VAT number: 02876000841.
Privacy contact: support@toobloom.com.
Data Protection Officer (DPO): not appointed. The conditions of art. 37 GDPR are not met: the processing does not involve regular and systematic large-scale monitoring, nor large-scale processing of special categories of data. The contact above is the reference point for any data protection matter.

TooBloom is the name of the analysis service provided by the controller and is not a separate legal entity.

What the backend stores

Categories of data processed by the API

Each category below is supported by the backend repository.

Account

Name, email, hashed password, plan, status

Created at registration. Used for authentication (Laravel Sanctum), email verification, password reset, and account management.

Consent record

Consent date, policy version, IP hash

Recorded at registration as required by GDPR Art. 7. Included in account data export. Never shared with third parties.

Workspace configuration

Site name, URL, GA4 property ID, Search Console URL, GTM container ID

Stored when you configure your TooBloom workspace. These are identifiers — not OAuth credentials, not raw analytics data.

Historical data

Keyword strings, clicks, impressions, CTR, position

Historical data retained from when the keyword sync feature was active (disabled since 2026-07-23 — no new syncing occurs). Source data originated from your Search Console.

Reports

Period, generated_at, content_json (aggregated metrics)

Stored when you explicitly save a report. Content may include GA4 and Search Console metrics for the selected period.

Billing

Invoices, payment logs, plan request history

Retained as required by Italian fiscal law. Shared with Stripe, the sole active payment provider, only to the extent necessary to process the transaction. PayPal has been permanently decommissioned: it no longer receives any data, and legacy invoices retain only the historical transaction identifiers (paypal_order_id, paypal_payment_id) under the same fiscal obligation.

Audit logs

Admin actions, target user, change summary, IP hash

Recorded for internal security and fraud prevention. Not exposed to users via API. Reviewed periodically and pruned according to operational policy.

AI proxy

Keywords, metrics, and prompts forwarded to OpenAI

When you use the monthly AI report generation feature, the backend forwards the relevant data to OpenAI's API. No raw Google credentials are included.

Your rights

How to access, correct, or delete your data

You can export all your account data from the app (Settings → Export Data). You can delete your account from Settings → Delete Account. Deletion is soft-deleted immediately and permanently removed within 30 days.