Privacy Policy
Last updated: September 2026
1. Introduction
Visibilio Ltd. ("Visibilio", "we", "us", or "our") is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable EU data protection laws.
This policy covers both of our properties:
- The website at visibilio.ai — our public marketing site and Content Hub.
- The application at app.visibilio.ai — the Visibilio content operating system, available to customers under a subscription.
Where a section applies to only one of the two, it says so. Section 4 deals specifically with data we receive from Google APIs on your instruction.
2. Data Controller
Visibilio Ltd.
Alexander Malinov 31 Blvd.
Sofia 1729, Bulgaria
EU VAT: BG208031576
team@visibilio.ai
For personal data contained in content and analytics that a customer connects to the application, Visibilio acts as a processor and the customer is the controller. Our data processing agreement governs that relationship.
3. Information We Collect
Information You Provide Directly
- Name, email address, and company name when you submit contact forms
- Communication data when you correspond with us
- Email address when you subscribe to our newsletter
- Account details when you register for the application — name, work email address, organisation, and authentication credentials
- Content you create, upload, or publish through the application
- Billing and company details where you hold a paid subscription
Information Collected Automatically
- Browser type and operating system details
- Usage patterns and pages visited
- IP addresses (anonymised where possible)
- Country-level location data
- Application event logs — sign-in times, feature usage, and errors, used to operate and secure the service
Cookies
We use cookies as described in Section 10 of this policy.
4. Google User Data
The application can connect to Google services on your instruction, so that Visibilio can report on how your content performs in Google Search and on your website. This section explains exactly what that involves. It applies only to app.visibilio.ai, and only once you have connected a Google account.
4.1 Connecting is optional and always your choice
Visibilio never accesses a Google account unless you explicitly connect one through Google's own OAuth consent screen. You see the exact permissions requested before you approve them, and you can disconnect at any time (see Section 4.7). The rest of the application works without a Google connection.
4.2 What we access
We request read-only access. We do not request permission to modify, create, or delete anything in your Google account.
| Google service | What we read | Why |
|---|---|---|
| Google Search Console | Search performance data for the properties you select — queries, impressions, clicks, click-through rates, average positions, and indexed URLs | To show which of your pages and topics earn visibility in Google Search, and to recommend what to publish next |
| Google Analytics | Aggregated traffic and engagement reports for the properties you select — sessions, page views, acquisition channels, and engagement metrics | To connect published content to the traffic and engagement it produces |
| Google account basics | Your name, email address, and profile picture, where you sign in with Google | To create and identify your Visibilio account |
We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google service.
4.3 How we use it
We use Google user data solely to provide and improve the user-facing features described above and visible in the application's interface. Specifically, we use it to render your reports and dashboards, to generate content recommendations for you, and to diagnose faults you report to us.
We do not:
- Sell Google user data, or transfer it to advertising platforms, data brokers, or information resellers
- Use it for advertising, remarketing, credit assessment, or lending purposes
- Use it to build profiles of individuals unrelated to the service you asked us to provide
- Use it to develop, improve, or train generalised artificial intelligence or machine learning models
- Allow humans to read it, except in the narrow cases set out in Section 4.5
4.4 How we store it
Google user data is encrypted in transit using HTTPS/TLS and encrypted at rest. Access tokens are held in encrypted storage and are never exposed to the browser or written to logs. We retain Google user data only while your connection is active, and we cache report data no longer than necessary to keep the application responsive.
When you disconnect a Google account or close your Visibilio account, we delete the associated tokens immediately and remove the cached Google data within 30 days.
4.5 How we share it
We do not share Google user data with third parties, except:
- Infrastructure providers who host or process the data strictly on our behalf under contract, listed in Section 7
- Where you direct us to, for example when you export a report
- Where the law requires it, or where it is necessary to investigate a security incident or prevent fraud or abuse
Our staff do not read your Google user data unless you give affirmative agreement for us to view specific data (for example, when you ask us to investigate a support issue), it is necessary for security purposes, it is required by law, or the data has been aggregated and anonymised for internal operations.
4.6 Limited Use disclosure
Visibilio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.7 How to revoke access
You can disconnect Google at any time, in either of two ways:
- In the application, from your integration settings
- In your Google account, at myaccount.google.com/permissions, by removing access for Visibilio
Revoking access stops all future data collection immediately. To have data already collected deleted, contact us at team@visibilio.ai.
5. How We Use Your Data
- Providing the application and its features to you (contract performance)
- Responding to inquiries (legitimate interest or contract performance)
- Service improvement through analytics (legitimate interest)
- Securing the service and preventing abuse (legitimate interest)
- Marketing communications (consent or legitimate interest)
- Newsletter delivery (consent-based)
- Billing and account administration (contract performance)
- Legal compliance (legal obligation)
6. Automated Decision-Making
The application uses AI models to generate content drafts and recommendations. These are suggestions for you to review, edit, and approve. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
7. Data Sharing
We work with the following service providers:
- Cloudflare — form processing, hosting, security
- Vercel — application hosting
- Supabase — application database and authentication
- Resend — email delivery
- Google Analytics — website analytics
- Microsoft Clarity — session recording, heatmaps
- Meta Pixel — marketing analytics
Each provider operates under their own privacy policy and data protection standards, and processes data on our instructions under a written agreement. We do not sell personal data.
8. International Data Transfers
When we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including adequacy decisions, Standard Contractual Clauses, or other approved transfer mechanisms.
9. Data Retention
As a rule, we keep customer data for as long as the customer relationship lasts, and then delete it. Where a period is fixed by law, or by a commitment we have made to a third party, that period governs instead. The table below states, for each category, either the period or the criterion we use to determine it.
| Data Type | Retention Period |
|---|---|
| Account and content data | For the duration of the customer relationship, then 90 days |
| Google access tokens | Deleted immediately on disconnection or account closure |
| Cached Google Search Console and Analytics data | Kept while the connection is active; deleted within 30 days of disconnection or account closure |
| Application event logs | 12 months |
| Billing and accounting records | For the period required by Bulgarian accounting and tax law, which outlives the customer relationship |
| Contact form submissions | 3 years |
| Google Analytics data | 26 months |
| Microsoft Clarity data | 30 days |
| Marketing data | Until consent withdrawn |
| Newsletter subscription data | Until unsubscribe |
Two categories are deliberately shorter than the relationship. Google user data is deleted when you disconnect the account, even if you remain a customer, because the Google API Services User Data Policy requires it and because our access exists only to serve a connection you chose to make. Event logs age out at 12 months because keeping security logs indefinitely creates risk rather than reducing it.
One category is deliberately longer. We cannot delete invoices and accounting records at the end of the relationship, because Bulgarian law requires us to keep them.
10. Cookies & Tracking Technologies
Essential Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| Session ID | Session management | Session |
| CSRF Token | Security | Session |
| vis_lang | Remembers your language choice | 1 year |
Analytics Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Google Analytics | 2 years |
| _ga_* | Google Analytics | 1 year |
| _clck | Microsoft Clarity | 1 year |
| _clsk | Microsoft Clarity | 1 day |
Marketing Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| _fbp | Meta Pixel | 3 months |
| _fbc | Meta Pixel | 3 months |
You can manage cookies through your browser settings. Instructions are available for Chrome, Firefox, Safari, and Edge in their respective help documentation.
11. Your Rights Under GDPR
Under GDPR you have the right to:
- Access copies of your personal data
- Rectification of inaccurate information
- Erasure (the "right to be forgotten")
- Restriction of processing
- Data portability in machine-readable format
- Object to legitimate interest processing
- Withdraw consent at any time
To exercise any of these rights, contact us at team@visibilio.ai. We will respond within one month, extendable by two additional months for complex requests.
12. Security Measures
We implement appropriate technical and organisational measures to protect your data, including HTTPS/TLS encryption for data in transit, encryption at rest, secure data storage with role-based access controls, regular security assessments, and staff training on data protection.
While we strive to protect your data, no method of transmission over the Internet is 100% secure.
13. Children's Privacy
Our website and services are not directed at individuals under the age of 16.
14. Third-Party Links
Our website may contain links to external sites. We are not responsible for the privacy practices or content of third-party websites.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Where a change materially affects how we handle Google user data, we will notify connected users before it takes effect. Your continued use of our website and services after changes are posted constitutes acceptance of the updated policy.
16. Supervisory Authority
You have the right to lodge a complaint with the Bulgarian supervisory authority:
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd.
Sofia 1592, Bulgaria
cpdp.bg
You may also contact the supervisory authority in your country of residence within the EU.
17. Contact Us
Visibilio Ltd.
Alexander Malinov 31 Blvd.
Sofia 1729, Bulgaria
team@visibilio.ai