Privacy Policy
Privacy Policy
U&AI Labs, Co.
Effective date: July 28, 2026 Last updated: July 28, 2026
1. Who we are
U&AI Labs, Co. ("U&AI," "we," "us," or "our") operates the websites uandai.co and helloagentcy.com and the U&AI platform available at app.uandai.co (together, the "Service").
The Service is a business-to-business marketing platform. Agencies and brands use it to measure how their brand appears in AI assistants and search engines, to plan and produce content, to run digital PR outreach, and to analyze the performance of their own websites.
Contact
U&AI Labs, Co. 145 S Fairfax Ave. STE 200 Los Angeles, CA 90036 United States office@uandai.co
2. Scope of this policy
This policy explains what information we collect, why we collect it, who we share it with, and what choices you have.
It covers:
Our public websites (uandai.co, helloagentcy.com).
The U&AI platform (app.uandai.co), including the accounts of our customers and their users.
Data our customers authorize us to retrieve from their connected accounts — including Google Analytics, Google Search Console, and Google Business Profile via Google OAuth.
The optional U&AI measurement snippet that a customer may install on its own website.
3. Our two roles
We are a controller for information about our own users and prospects: account records, billing details, support correspondence, and analytics about how the Service itself is used.
We are a processor (a "service provider" under California law) for the data we handle on a customer's behalf. This includes analytics and search data pulled from that customer's Google properties, and any end-user data collected by the U&AI snippet installed on that customer's website. In those cases the customer is the controller: the customer decides what is collected, configures retention, and is responsible for giving notice to and obtaining consent from its own website visitors. We process that data only on the customer's documented instructions and as described in our agreement with them.
If you are a visitor to one of our customers' websites and want your data deleted, contact that website's operator. You may also contact us at office@uandai.co and we will route the request to the relevant customer and assist with fulfilling it.
4. Information we collect
4.1 Account and user data
When an account is created for you, or you are invited to an organization, we store:
Email address (this is your login identifier)
An optional display name
A password, stored only as a salted hash — we never store or have access to your plaintext password
Your user type (agency/admin user or client user) and role
For agency users: which client workspaces you are permitted to see
Session cookies that keep you signed in, and a CSRF token cookie that protects form submissions
We also store records of actions taken in the Service (for example, who approved a piece of content, who connected an integration, and when), so that our customers have an audit trail of work done in their workspace.
4.2 Customer and brand profile data
Customers provide business information about the brands they manage, including: company name, website URL, business contact email and phone, communication preferences, industry verticals, target markets and regions, competitor names and domains, brand guidelines and tone-of-voice documents, ideal customer profile, keywords, imagery guidelines, KPI targets, plan tier and limits, and — where a named spokesperson is used for PR — that person's first name, last name, job title, and public profile link.
4.3 Google account data (Google OAuth)
This section describes exactly what we access through Google OAuth and what we do with it. It applies whenever a customer clicks "Connect Google" in the Service.
Scopes we request
Scope | Why we request it |
|---|---|
| To list the Google Analytics 4 properties the connecting account can see, so the customer can choose one, and to read aggregated report data for the selected property. |
| To list the Search Console properties the connecting account can see, and to read Search Analytics performance data for the selected property. |
| To list the Google Business Profile accounts and locations the connecting account can see, and to read daily Business Profile performance metrics for the selected location. This is the only scope Google publishes for the Business Profile Performance API; we use it read-only. |
What we store from the sign-in itself
The Google account email address and the Google subject identifier (
sub) from the ID token, so the customer can see which Google account is connected and so we can detect when a different account is connected later.An OAuth refresh token, stored encrypted at rest, so we can refresh data on a schedule without asking the customer to sign in again.
A short-lived access token, its expiry time, and the list of scopes that were actually granted.
What we read through these scopes
Google Analytics 4 (Analytics Data API and Analytics Admin API)
The list of GA accounts and properties visible to the connected account (names and IDs), shown so the customer can pick the right property.
Aggregated report rows for the selected property only: sessions, users, key events and conversions, engagement metrics, page paths (including query strings), landing pages, page referrers, traffic source and medium, channel groupings, device category, country/region/city, date, and Google's aggregated age-bracket and gender dimensions where the customer's property has Google Signals enabled.
We request aggregated report rows. We do not request or receive individual GA user identifiers, and we do not attempt to re-identify individuals from GA data.
Google Search Console
The list of verified sites and the permission level the connected account holds on each.
Search Analytics rows for the selected site: search query, page URL, date, clicks, impressions, click-through rate, and average position. Google itself withholds low-volume queries; we receive only what Google returns.
Google Business Profile
The list of accounts and locations (resource name, title, store code).
Daily performance metric time series for the selected location, such as searches, views, and customer actions.
What we do not do with Google data
We do not write, create, edit, delete, or post anything to Google Analytics, Search Console, or Business Profile. Every call we make is a read.
We do not request or access Gmail, Google Drive, Google Contacts, Google Calendar, YouTube, or Google Ads data through this connection. (Separately, a customer may paste a public or link-shared Google Drive folder URL into the Service to import brand images; that uses a public Drive API key and is not part of the OAuth grant.)
We do not sell, rent, or share Google user data, and we do not use it for advertising or ad targeting.
We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
We do not transfer Google user data to third parties except: the infrastructure sub-processors listed in Section 7 that host and process it on our behalf; where necessary to provide or improve the user-facing features the customer requested; where required by law; or as part of a merger or acquisition after obtaining the customer's explicit consent.
No U&AI employee reads Google user data except where the customer asks us to for support, where it is necessary for security purposes, or where required by law.
Limited Use
U&AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting
A customer can disconnect Google at any time in the Service. When a connection is removed we delete the stored refresh token, access token, and account identifiers for that integration. You can also revoke access at any time directly at myaccount.google.com/permissions; once revoked, our scheduled syncs stop and the integration is marked as needing reconnection. Metrics already imported and stored in the customer's workspace remain until the customer deletes them or the workspace is closed — see Section 8.
4.4 Website visitor data (the U&AI snippet)
A customer may install the U&AI measurement snippet on its own website. This is off by default, is enabled per customer, and is configured by the customer across three collection tiers. When it is enabled, the customer is the controller of the resulting data and is responsible for disclosing it in its own privacy notice and for obtaining any consent its jurisdiction requires. The snippet includes a consent-gated mode that a customer can switch on; when it is on, only page-view events are recorded until consent is given.
Depending on the tiers the customer enables, the snippet may collect:
A random anonymous visitor ID stored in the browser's
localStorage, and a session ID. These are not linked to a name or email unless the customer's own site passes one (see below).Page URL and path, referrer, UTM parameters, ad click identifiers, derived traffic source, and device type.
Interaction events: clicks (including the clicked element's tag, visible text, ARIA label, CSS selector, nearest heading, and whether it looked like a call-to-action), scroll depth, time on page, and exits.
Form interaction events: form start, field focus, field blur, field validation errors, abandonment, and submission — recorded by field name, label, and type. Values in
password,hidden, andfilefields are never captured.Form field values only for fields the customer explicitly allowlists (by default: email, phone, tel, mobile). These values are stored encrypted at rest and are purged on the customer's configured schedule (90 days by default).
A hashed IP address (SHA-256 with a per-site salt). We use the raw IP address transiently to derive coarse location and to compute the hash; we do not store the raw IP. The hash is purged on the customer's schedule (30 days by default).
Coarse geolocation: country, and — at higher tiers — region and city. Approximate user-agent string.
An external user ID, only if the customer's own website chooses to pass one to identify a logged-in user of that site.
Third-party cookie identifiers already set on the customer's site (for example
_ga,_fbp) — only where the customer enables the highest tier and consent has been given.Session replay recordings using the open-source rrweb library, sampled (10% of sessions by default), capped in duration (10 minutes by default), and retained for a limited period (30 days by default). All text input is masked in the recording and password fields are blocked entirely. Replay chunks are stored in our object storage. Where the library is not already present on the customer's site, the snippet loads it from the public jsDelivr CDN, which means the visitor's browser makes a request to that CDN and jsDelivr receives the visitor's IP address and user agent as part of that request.
We provide our customers with tooling to export and to delete all snippet data associated with a single anonymous visitor ID, so that they can fulfill data subject requests from their own visitors. A scheduled job purges hashed IPs, captured form values, and replay recordings once they exceed the customer's configured retention windows.
4.5 Content, brand, and AI assistant data
To produce and optimize content we store: brand documents and guidelines, source material provided by the customer, publishing plans and calendars, drafts and published articles, images and image metadata, prompts we construct, model responses, and the reasoning artifacts we keep so customers can audit why the system made a given recommendation. Conversations with the in-app AI assistant are stored so the thread persists.
4.6 Digital PR data
Where a customer uses our PR features, we store journalist source requests (which may include a journalist's name, email address, publication, request text, and deadline), the pitches sent on the customer's behalf, and any replies received. Replies arrive at a dedicated inbound address and we store the sender address and name, subject, body, and any attachment.
4.7 Other connected accounts
Only when a customer chooses to connect them, we store credentials and identifiers for third-party systems, with all secrets encrypted at rest: WordPress site URL and application password or API key; hosting, DNS, registrar, and CDN API tokens and SFTP credentials used for website migrations; Reddit or other community account usernames, user IDs, and OAuth tokens; CRM API keys; and Stripe customer and subscription identifiers. Where a customer connects a CRM, we may process meeting participant email addresses in order to match meetings to the right client workspace.
4.8 Product analytics, logs, and website visitors
We use PostHog to understand how the Service is used — which features are opened, which flows fail — keyed to a user or account identifier.
Our servers keep operational logs (timestamps, IP address, request path, status, error detail) for security, debugging, and abuse prevention.
Our marketing websites use standard web analytics and may set cookies. Where required, we present a consent banner and honor the choice made.
4.9 What we do not collect
We do not knowingly collect: government identifiers, payment card numbers (Stripe handles card data directly — we never see or store card numbers), biometric data, precise GPS location, or special-category data such as health, religion, or political opinions. Please do not upload such data into the Service.
5. How we use information
Purpose | Examples |
|---|---|
Provide the Service | Authenticate you, show your dashboards, sync your connected accounts, generate and publish content you approve |
Reporting and analysis | Build performance reports, visibility scores, keyword rankings, funnels, and recommendations for the customer's own brand |
Communicate | Send transactional email — invitations, password resets, report links, digests, and PR outreach that a customer has approved |
Bill and administer | Manage subscriptions, plan limits, and invoicing through Stripe |
Secure and maintain | Detect abuse, investigate incidents, debug failures, and keep the Service available |
Improve the Service | Understand aggregate feature usage and reliability |
Comply with law | Meet legal, tax, and regulatory obligations, and respond to lawful requests |
We do not use personal information for automated decision-making that produces legal or similarly significant effects about an individual.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies and we act as a controller, we rely on: contract (to provide the Service to you and administer your account); legitimate interests (to secure the Service, prevent abuse, and understand aggregate product usage); consent (for non-essential cookies and marketing email, where required); and legal obligation (for tax and compliance records). Where we act as a processor, our customer determines the legal basis.
7. Who we share information with
We disclose information to service providers who process it on our behalf, under contract, and only for the purposes we specify:
Provider | Purpose | Data involved |
|---|---|---|
DigitalOcean | Application hosting, managed PostgreSQL database, and object storage (United States) | All Service data at rest |
OpenAI | Content generation, the in-app assistant, keyword research, and classification | Brand documents, prompts, content drafts, and the metric summaries needed to answer a question. Processed through the API and, per OpenAI's API terms, not used to train their models |
Profound | AI-assistant visibility, citation, and sentiment measurement | Brand names, prompts, and market/vertical configuration |
DataForSEO, Ahrefs, SerpAPI, Perplexity, Google Gemini | Keyword volume and difficulty, SERP results, ranking data, and AI-answer citation research | Keywords, domains, and prompts — not personal information |
Resend | Transactional email delivery and inbound email receipt | Recipient addresses, message content, and attachments |
PostHog | Product analytics | User/account identifiers and feature-usage events |
Stripe | Subscription billing and payments | Billing contact and subscription records. Card data goes to Stripe directly and never reaches our servers |
Pexels | Stock imagery | Search terms only |
jsDelivr (CDN) | Delivers the open-source session replay library to a customer's website when replay is enabled and the library is not already present | The visitor's IP address and user agent, as part of the browser's request for the script |
Customer-connected systems (WordPress, hosting, DNS/CDN, CRM, community platforms) | Only where the customer connects them, to perform the actions the customer requests | Content, credentials, and identifiers for that system |
We may also disclose information: to comply with law, legal process, or an enforceable governmental request; to enforce our terms; to protect the rights, property, or safety of U&AI, our customers, or the public; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy. Google user data will not be transferred in a change-of-control event without the customer's explicit consent.
8. Retention
Data | Retention |
|---|---|
Account records | For the life of the account, then deleted or anonymized within 90 days of closure unless a longer period is legally required |
OAuth tokens (Google and other integrations) | Until the integration is disconnected or access is revoked, then deleted |
Imported analytics, search, and visibility metrics | For the life of the workspace, so historical reporting stays intact; deleted when the workspace is deleted |
Content, drafts, and brand documents | For the life of the workspace |
Snippet: hashed IP addresses | 30 days by default, configurable by the customer |
Snippet: allowlisted form field values | 90 days by default, configurable by the customer |
Snippet: session replay recordings | 30 days by default, configurable by the customer |
PR correspondence | For the life of the workspace |
Operational logs | Typically 30–90 days |
Billing and tax records | As required by law, generally 7 years |
9. Security
We protect information with measures appropriate to its sensitivity, including:
TLS encryption for data in transit.
Encryption at rest for all stored secrets — OAuth refresh tokens, third-party API keys and application passwords, and any allowlisted form values captured by the snippet.
Passwords stored only as salted hashes.
Role-based access control, with agency users scoped to the specific client workspaces they are assigned.
Managed, access-controlled infrastructure, with credentials held in environment configuration and never committed to source control.
OAuth flows protected with PKCE and single-use state values.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law.
10. Your rights and choices
Everyone. You can access and correct most of your account information inside the Service, disconnect any integration at any time, and ask us to delete your account by writing to office@uandai.co.
California residents (CCPA/CPRA). You have the right to know what personal information we collect and how we use and disclose it; to request access to and a portable copy of it; to request correction or deletion; and to be free from discrimination for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share My Personal Information" opt-out to exercise. You may designate an authorized agent to make a request on your behalf. We will verify requests by confirming control of the account email address.
EEA, UK, and Switzerland (GDPR/UK GDPR). You have the right to access, rectify, erase, restrict, and port your personal data; to object to processing based on legitimate interests; and to withdraw consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your supervisory authority.
Other US states. Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, and Oregon) have comparable rights of access, correction, deletion, and portability, and an appeal right if we decline a request.
To exercise any right, email office@uandai.co. We will respond within the time the applicable law requires — generally 45 days, extendable where permitted. If your request concerns data we process on behalf of one of our customers, we will forward it to that customer and support them in responding.
11. Cookies and similar technologies
The Service uses:
Strictly necessary cookies — a session cookie to keep you signed in and a CSRF token cookie to protect form submissions. The Service will not function without them.
Product analytics — PostHog, to understand feature usage.
On our marketing websites, analytics and, where applicable, marketing cookies, subject to the consent choice you make in the banner.
The U&AI snippet on a customer's website uses browser localStorage and sessionStorage rather than its own cookies, and reads existing third-party cookie identifiers only where that customer has enabled the highest tier and consent has been given.
You can block or delete cookies in your browser settings; strictly necessary cookies cannot be disabled without breaking sign-in.
12. International transfers
We are based in the United States and our infrastructure is hosted in the United States. If you access the Service from outside the United States, your information will be transferred to and processed there. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) together with appropriate supplementary measures.
13. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact office@uandai.co and we will delete it.
14. Third-party links
The Service and our websites link to third-party sites and services we do not control. This policy does not apply to them; review their privacy policies before providing information.
15. Changes to this policy
We may update this policy. When we do, we will change the "Last updated" date above. For material changes we will give notice through the Service or by email before the change takes effect. Continued use after the effective date means you accept the updated policy.
16. Contact us
Questions, requests, or complaints:
U&AI Labs, Co. Attn: Privacy 145 S Fairfax Ave. STE 200 Los Angeles, CA 90036 United States office@uandai.co
