Effective date: May 14, 2026
Last updated: September 6, 2026
Who we are
Bostic.ai is operated by Volkan Koroglu, an individual based in Massachusetts, United States.
Information we collect
We may collect account information, workspace settings, billing metadata, support messages, device and usage data, consent preferences, crawl configuration and content submitted to the platform.
How we use information
- We provide, secure and maintain the service.
- We run crawls, audits, reports and AI-assisted workflows requested by users.
- We process payments and manage subscriptions.
- We improve reliability, usability and product quality.
- We communicate service updates and support responses.
Customer content
Customer prompts, crawl data, generated artifacts and reports are processed to deliver the requested service. Available account controls may support export, retention and deletion workflows.
Google sign-in and connected Google services
If you choose Google sign-in, we process your Google account identifier, email address, email-verification status, name when available, and Workspace domain when provided. We use this information to authenticate you, create or securely link your Bostic.ai account, and protect account access. We retain the account information and identity link needed for sign-in. We do not request your Google password.
Google sign-in is separate from connecting Google Search Console or Google Analytics. Those optional connections require additional authorization and serve the website associated with your Bostic.ai project.
Google Search Console (GSC)
We request read-only access to property information and search-performance data. Imported information can include search queries, page paths, clicks, impressions, click-through rates, average search positions, and country and device breakdowns. We use it to display search performance and support SEO analysis.
Google Analytics 4 (GA4)
We request read-only access to account, property and stream information needed for the connection and to aggregate reports. Imported information can include users, sessions, engagement, key events, landing pages, and country, device and channel breakdowns. We use it to display traffic performance and support project analysis. These integrations do not request permission to edit your Search Console or Analytics data. Connecting your own Analytics property is separate from consenting to analytics on Bostic.ai's marketing website.
Google data in AI generations
When AI assistance and the relevant Google sharing permission are enabled, selected GSC search-query and page-path summaries with performance metrics and GA4 landing-page and traffic summaries may be sent to OpenAI with relevant project context to produce the requested content opportunities or recommendations. Each Google source is included only if you have enabled it for that project. These summaries remain Google-derived data even when aggregated. Google connection credentials are not sent as AI prompt evidence.
Manage your choices in Settings > Privacy & AI. AI assistance and Google sharing start off and are not accepted automatically when you register or connect Google. AI assistance allows OpenAI processing of your submitted messages, business answers and selected SEO evidence. Search Console and GA4 sharing are separate, optional choices for each project and your own requests. Saved choices apply to future requests until you change them; we do not ask again for every generation. Turning a permission off blocks future transmissions that have not already been sent, including pending work.
Google sign-in and viewing reports from connected Google services do not require AI sharing. Leaving the choice off does not recall earlier transmissions or delete saved results.
We do not opt in to sharing Google data with OpenAI for model improvement. We do not use Google data to train general-purpose AI models.
OpenAI may retain data for security and abuse prevention under its applicable terms. This is not a zero-retention promise. See OpenAI API data controls.
Google data storage, disconnection and deletion
We store the connection information and imported reports needed for the connected features. Stored Google integration credentials are encrypted, and access to project data is checked against organization and project permissions. Our infrastructure providers process connection records and imported information to host, store and operate these features.
An authorized project administrator can disconnect Search Console or Analytics using the relevant connection controls. If a refresh is active, it must finish before disconnection can complete. Successful disconnection removes the local connection, its encrypted credentials and directly associated imported metrics, and we attempt to revoke the Google authorization. You can also revoke Bostic.ai access through your Google Account's third-party connections settings.
Previously generated content opportunities, recommendations and supporting evidence may be stored separately from a live Google connection. Disconnection does not retract data already processed by OpenAI, delete your Bostic.ai account, or automatically delete saved AI evidence, generated results or database backups.
For a deletion request covering those records, contact privacy@bostic.ai and specify the affected account or project. Do not include passwords or active tokens in a request.
Google API data use restrictions
Our use of information received from Google APIs, including transfers to service providers, adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data and derived information are used for the user-facing features described here, with transfers and human access restricted to what those requirements permit.
We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models. These restrictions also apply to information aggregated or derived from Google data.
Cookies and tracking
Necessary storage supports security, consent and core preferences. Optional storage follows your choices. The public website can send cookieless measurement and consent-state requests to Google before you choose, or when Analytics storage is off. Choosing necessary storage only does not block those requests. Read the Cookie Policy for details and controls.
Sharing
We may share information with service providers needed for hosting, storage, payments, email, support, measurement and AI processing. Public-site measurement follows the behavior described in the Cookie Policy; optional AI and Google-source sharing follow the separate permissions described above. See Subprocessors.
Your choices
You may request access, correction, deletion or export where applicable. Organization administrators may manage workspace-level data requests for their members.
Contact
Privacy questions may be sent to privacy@bostic.ai.