Google User Data
Scopes, tokens and data flow
TooBloom requests read-only access to Analytics, Search Console and Tag Manager. OAuth tokens stay in browser sessionStorage and are not sent to the marketing site.
App privacy
It covers Google OAuth scopes, token handling, Search Console queries, any historical keyword data from a now-disabled feature, saved reports, AI features via OpenAI, billing data handled through Stripe, retention, GDPR rights and contact details.
Key points
Google User Data
TooBloom requests read-only access to Analytics, Search Console and Tag Manager. OAuth tokens stay in browser sessionStorage and are not sent to the marketing site.
Stored data
Keyword strings and performance metrics synced while the feature was active (disabled since 2026-07-23, no new syncing), explicitly saved reports and Google property identifiers may be stored in the app database.
AI features
Monthly report generation uses OpenAI. Only data actively submitted to that feature is sent to the API.
Your rights
You can request access, export, correction or deletion, revoke Google access and manage consent from within the app or by contacting support.
Retention
Session data clears when the browser session ends. Account and workspace data is removed after deletion within the operational and fiscal retention limits described in the policy.
Contact
Data controller: Elisabetta Monaco, sole trader.
Address: Via Garibaldi 56, 92013 Menfi (AG), Italy.
VAT number: 02876000841.
Privacy contact: support@toobloom.com.
Data Protection Officer (DPO): not appointed. The conditions of art. 37 GDPR are not met: the processing does not involve regular and systematic large-scale monitoring, nor large-scale processing of special categories of data. The contact above is the reference point for any data protection matter.
TooBloom is the name of the analysis service provided by the controller and is not a separate legal entity.