Skip to main content
Privacy Policy

Privacy Policy

Best CEO collects only the information needed to authenticate users, analyze websites, run connected integrations, and operate the platform securely. This page exists as the public privacy document for product users and OAuth consent review.

Last updated: September 4, 2026

Section 01

What this policy covers

This Privacy Policy explains how Best CEO collects, uses, stores, and shares information when you use the platform, request a website analysis, connect third-party integrations, or interact with the product through the web app.

The goal of the service is to analyze websites, generate marketing intelligence, and power connected workflows such as Search Console, Slack, GitHub, Notion, and Google Chat. This policy applies to the information needed to operate those features.

Section 02

Information we collect

We collect account and workspace information such as email address, authentication provider identifiers, billing state, and basic profile details needed to create and secure your workspace.

We also collect information you actively submit to the platform, including website URLs, analysis requests, report configuration, connected integration metadata, and optional feedback you send through the product.

When integrations are connected, Best CEO may store scoped access tokens, refresh tokens, account identifiers, and the minimum related metadata required to keep those integrations working.

Section 03

How we use information

We use collected information to authenticate users, run analyses, return reports, improve result quality, support connected integrations, process billing, and keep the platform secure and reliable.

Operational telemetry and error logs may be used to diagnose failures, investigate abuse, monitor uptime, and improve product performance. We do not sell customer data or analysis data.

Section 04

How we protect your data

All data moves between your browser, our servers, and third-party APIs over encrypted TLS (HTTPS) connections. In our production environment, OAuth access and refresh tokens for connected integrations are encrypted at rest with AES-256-GCM using a dedicated encryption key that is stored in managed environment secrets separately from the database, so a database leak alone cannot expose usable credentials.

Workspace data is tenant-isolated: every read and write is scoped to the authenticated workspace, and administrative access is limited to authorized personnel under role-based controls. We request only the narrowest OAuth scopes needed for each feature: our Google data integration (Search Console) is read-only, and messaging integrations such as Google Chat request only what is needed to deliver the reports you configure (creating messages in the space you select and listing your spaces) - never to read your conversations. Disconnecting an integration deletes its stored tokens and stops all further access.

Sensitive configuration such as API keys and encryption keys is held in managed environment secrets, never in source code or client-side bundles. We monitor for abnormal access patterns and log security-relevant events with redaction of sensitive values.

Section 05

Google user data

When you connect Google Search Console, Best CEO requests only a read-only scope and uses the data solely to provide features you see in the product: Search Console data (webmasters.readonly) powers search performance reporting, reports, and scheduled briefs for your verified site. Search Console is the only Google data integration Best CEO offers.

Google Chat carries one non-read-only scope with a narrow, disclosed purpose: chat.messages.create is used only to deliver the briefs and alerts you configure into the space you select. The chat.spaces.readonly scope is used only to list the spaces available for destination selection; Best CEO never reads your conversations.

Best CEO's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not transfer it except to provide the features you request, for security purposes, or to comply with law.

Humans do not read your Google user data unless you give explicit permission for support, it is necessary for security or abuse investigation, or we are required to by law. Disconnecting a Google integration deletes the stored tokens immediately, and account deletion removes all associated data entirely.

Section 06

AI processing

Best CEO uses Anthropic's Claude models through Anthropic's paid commercial API to generate your reports, briefs, and chat responses. Data from your connected integrations, including Google user data, is processed by this API only to produce output for your own workspace. Under Anthropic's commercial terms, API inputs and outputs are not used to train Anthropic's models.

Chat also offers an optional, clearly labeled Privacy Mode that routes your chat message to the 0G decentralized compute network instead of Anthropic. Privacy Mode conversations exclude content derived from your Google user data: knowledge previously synced from Google Workspace sources and prior chat history are programmatically withheld from that path, so Google user data is only ever processed through Anthropic's no-training commercial API.

The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements. We do not use Google user data - raw, aggregated, anonymized, or derived - to create, train, improve, or fine-tune any generalized machine learning or artificial intelligence models, whether our own or a third party's.

Section 07

Sharing and subprocessors

Best CEO uses infrastructure and software providers to operate the service. Depending on the feature you use, this can include hosting, database, authentication, payments, observability, AI processing, and third-party integration providers.

Examples may include Vercel for hosting, Neon for database infrastructure, Privy for authentication, Stripe for billing, Anthropic for AI report generation under its commercial no-training API terms, and the providers you explicitly connect through OAuth. Data is shared with these providers only as required to deliver the requested feature.

Section 08

Retention and deletion

We retain account data, analysis history, and configuration data for as long as needed to operate your workspace, satisfy contractual obligations, resolve disputes, and maintain security records.

Where the product exposes deletion controls, you can remove analysis data or disconnect integrations directly. You can also request account-level deletion and we will process it subject to legal, security, and billing retention requirements.

Section 09

Your choices

You can decide whether to connect optional integrations, whether to submit websites for analysis, and whether to keep stored reports inside the platform. Disconnecting an integration stops new sync activity for that provider.

If you believe information is inaccurate or want help with deletion or privacy-related questions, contact us at hello@best.ceo.