Account
Name, email, hashed password, plan, status
Created at registration. Used for authentication (Laravel Sanctum), email verification, password reset, and account management.
Backend API · Privacy Policy
The backend stores account data, consent records, workspace configuration, keyword performance data, report snapshots, billing records, and audit logs. It also proxies AI requests to OpenAI.
Data Controller
Data controller: Elisabetta Monaco, sole trader.
Address: Via Garibaldi 56, 92013 Menfi (AG), Italy.
VAT number: 02876000841.
Privacy contact: support@toobloom.com.
Data Protection Officer (DPO): not appointed. The conditions of art. 37 GDPR are not met: the processing does not involve regular and systematic large-scale monitoring, nor large-scale processing of special categories of data. The contact above is the reference point for any data protection matter.
TooBloom is the name of the analysis service provided by the controller and is not a separate legal entity.
What the backend stores
Account
Created at registration. Used for authentication (Laravel Sanctum), email verification, password reset, and account management.
Consent record
Recorded at registration as required by GDPR Art. 7. Included in account data export. Never shared with third parties.
Workspace configuration
Stored when you configure your TooBloom workspace. These are identifiers — not OAuth credentials, not raw analytics data.
Historical data
Historical data retained from when the keyword sync feature was active (disabled since 2026-07-23 — no new syncing occurs). Source data originated from your Search Console.
Reports
Stored when you explicitly save a report. Content may include GA4 and Search Console metrics for the selected period.
Billing
Retained as required by Italian fiscal law. Shared with Stripe, the sole active payment provider, only to the extent necessary to process the transaction. PayPal has been permanently decommissioned: it no longer receives any data, and legacy invoices retain only the historical transaction identifiers (paypal_order_id, paypal_payment_id) under the same fiscal obligation.
Audit logs
Recorded for internal security and fraud prevention. Not exposed to users via API. Reviewed periodically and pruned according to operational policy.
AI proxy
When you use the monthly AI report generation feature, the backend forwards the relevant data to OpenAI's API. No raw Google credentials are included.
Your rights
You can export all your account data from the app (Settings → Export Data). You can delete your account from Settings → Delete Account. Deletion is soft-deleted immediately and permanently removed within 30 days.