
Privacy Policy
This Privacy Policy describes how Flow Ninja, Milutina Milankovića 11g, 11070 New Belgrade, Serbia (“Foresight”, “we”, “us”, “our”) collects, uses, stores and shares information when you use the Foresight website and applications at askforesight.ai and its subdomains (together, the “Service”).
Foresight is an AI website-intelligence product: you give us a website URL and we analyze the publicly available website, producing a scored audit and strategy recommendations. Paid workspaces can connect data sources — Google Analytics, Google Search Console, or a CRM — so the analysis is verified against real data. Questions about this policy or your data: privacy@askforesight.ai.
The short version
- We collect what we need to run the Service: your account details, the websites you ask us to analyze, documents you choose to upload, and — only if you connect them — read-only data from your Google Analytics, Search Console or CRM accounts.
- Payments are handled by Stripe. Card details never touch our servers.
- We use a single essential login cookie. No advertising cookies, no cross-site tracking.
- We never sell your data, never use it for advertising, and never use your data to train AI models.
- Google Analytics and Search Console access is read-only and aggregate-level, encrypted at rest, and used solely to build the reports you request — in line with the Google API Services User Data Policy, including its Limited Use requirements (see Section 2).
01 Information we collect
Information you provide
- Account details. Your name, email address and a password when you create an account. Passwords are stored only as salted argon2id hashes — we cannot read them.
- Websites you submit. The URL of each website you want analyzed.
- Documents you upload. Paid workspaces can upload documents to a project knowledge base (PDF, DOCX, PPTX, TXT, MD, VTT, SRT — for example call transcripts or proposal decks, up to 20 MB per file). We store the file and the text extracted from it. Please do not upload documents containing sensitive personal data that the analysis does not need.
- Billing information. Payments are processed by Stripe. Card details are entered in Stripe's own interface and are never received or stored by us. We store your Stripe customer reference, plan and subscription status, and purchase records (amount, currency, dates, invoice references).
- Communications. Messages you send to our support address.
Information from connected services
Collected only when you explicitly connect a source to a project:
- Google Analytics 4 and Google Search Console — aggregate website performance statistics, described in detail in Section 2.
- CRM (HubSpot or Pipedrive) — aggregate sales statistics for the one pipeline you select: counts of deals created, won, lost and open, amounts, win rate, distribution by stage and by month, and the most common loss reasons, over a trailing 365-day window. We do not store contact names, contact details or individual deal titles. We also store the identity of the connected portal/company account (its ID, the authorizing user's email, and the portal name/domain) and an encrypted OAuth token.
Information collected automatically
- Server logs. Our servers record requests (IP address, timestamp, path, status code) for security, abuse prevention and operations. Rate-limiting counters store only truncated cryptographic hashes of IPs/emails — not raw values — and expire automatically within hours.
- Session cookie. A single essential, HttpOnly login cookie (fs_session). We set no analytics or advertising cookies (Section 8).
- Usage records. We record which reports were run for which project, to enforce plan limits and keep an auditable usage ledger, and technical telemetry about our own AI pipeline (model used, token counts, cost) that contains no personal data.
Website content we analyze
When you request an analysis, we crawl the publicly available pages of the website you submitted (respecting its robots.txt) and run performance audits on it. This is content about a public website; we keep it temporarily as working data (Section 6).
A free report can be generated without an account. It is linked to an anonymous token in your browser and is automatically deleted after 30 days unless you sign up and claim it into an account.
02 Google user data
This section describes how we handle data obtained through Google APIs. It applies in addition to the rest of this policy; where anything differs, this section governs for Google user data.
What we request. When you connect Google Analytics and/or Search Console, we request read-only access with these OAuth scopes:
openidandemail— to identify which Google account you connected;- https://www.googleapis.com/auth/analytics.readonly — read-only access to Google Analytics;
- https://www.googleapis.com/auth/webmasters.readonly — read-only access to Search Console.
We never request write access and we never receive your Google password. You can approve either service individually on Google's consent screen — the connection works with only the permissions you granted.
Why we request it. Foresight's audit initially produces findings as hypotheses derived from a website's public content. Connecting Analytics and Search Console lets Foresight check those findings against your real traffic and search data and mark them as verified. That is the sole purpose of the access.
What we access. Aggregate statistics for the property or site you explicitly link to a project, over a trailing ~90-day window:
- From Google Analytics: overall totals (sessions, users, engaged sessions, engagement rate, session duration, bounce rate, key events, page views) and breakdowns by marketing channel, landing page, page and device category; plus the list of properties available on the account, so you can pick one.
- From Search Console: overall totals (clicks, impressions, click-through rate, average position) and breakdowns by top search queries, top pages and device; plus the list of your verified sites.
We request no user-level, demographic or geographic dimensions — nothing about your website's visitors as individuals.
What we store.
- The identity of the connected Google account (its email address and display name) and the list of scopes you granted.
- The OAuth refresh token, envelope-encrypted at rest (AES-256-GCM with per-record data keys). Short-lived access tokens are used in memory only and are never written to disk or a database.
- Normalized aggregate snapshots of the statistics listed above — never raw API responses.
How we use it. Solely to provide user-facing features you request: displaying the statistics in your workspace and verifying the findings in your reports. When our AI analysis processes this data, it is sent to our AI model providers under agreements that prohibit its use for training their models. We never use Google user data to develop or train generalized AI or machine-learning models, never use it for advertising purposes, and never sell it. Our personnel do not read this data except with your permission (for example, in a support case), where necessary for security or abuse investigation, or where required by law.
Limited Use disclosure. Foresight's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and revocation. You can disconnect Google inside the Service at any time. Disconnecting immediately and permanently deletes the stored refresh token and stops all data pulls. Aggregate snapshots already used in your reports remain part of those reports until you delete the related project data or ask us to delete them (privacy@askforesight.ai). You can also revoke Foresight's access directly in your Google Account at any time at https://myaccount.google.com/permissions.
03 How we use information
We use the information described above to:
- provide the Service: run analyses, generate reports, verify findings against connected data, and show them in your workspace;
- create and secure your account and sessions;
- process payments, manage subscriptions and enforce plan limits;
- send transactional email (email verification, password reset, sign-in links) and service notifications related to your reports and account, which you can manage in your notification settings;
- keep the Service secure: rate limiting, abuse prevention, debugging and incident response;
- comply with legal obligations (for example, tax and accounting rules for payment records).
Where EU/UK data-protection law applies, our legal bases are: performance of a contract (providing the Service), your consent (connecting data sources, which you can withdraw by disconnecting), legitimate interests (security, service improvement, defending legal claims), and legal obligation (financial records). We do not use your information for automated decisions that produce legal or similarly significant effects about you.
04 AI processing
Foresight is an AI product. To generate your reports, the following content is processed by our AI model providers (currently OpenAI, via its API): extracted content of the analyzed public website, website performance audit summaries, and — where you use those features — aggregate statistics from your connected sources and the content of documents you uploaded to the project knowledge base.
Our AI providers process this data to serve our requests only; our agreements with them prohibit using it to train their models. We do not use your data to train generalized AI models of our own, and report outputs for one customer are never derived from another customer's private data.
06 Data retentionDataRetentionAnonymous free reportsDeleted automatically after 30 days (unless claimed into an account)Crawled website content and performance auditsDeleted automatically after 90 days (reports built from them are kept)AI pipeline telemetry (model, tokens, cost)Deleted automatically after 180 daysAccount details, projects, reports, uploaded documents, connected-source snapshotsKept while your account is active; deleted on verified requestGoogle/CRM OAuth tokensDeleted immediately when you disconnect the integrationBilling and purchase recordsKept as long as required by tax and accounting lawServer and security logsKept for a limited operational period
After a subscription is canceled, your workspace remains available in read-only mode for a period (currently 12 months) so you keep access to reports you paid for; you can request earlier deletion at any time.
To request deletion of your account and associated data, email privacy@askforesight.ai from your account email address. We honor verified requests within 30 days, except for records we are legally required to keep (for example, payment records) and residual copies in encrypted backups that expire on their own schedule.
07 Security
We protect your information with, among other measures: TLS encryption in transit; envelope encryption (AES-256-GCM) of OAuth tokens at rest with support for key rotation; argon2id password hashing; HttpOnly session cookies; scoped, account-isolated data access in our application layer; single-use, short-lived tokens for email verification and password reset; and rate limiting on authentication endpoints. No method of transmission or storage is 100% secure, but we work to protect your data appropriately for its sensitivity.
09 Your rights and choices
Depending on where you live (for example, under the EU/UK GDPR or California law), you may have rights to access, correct, delete or export your personal information, to restrict or object to certain processing, and to withdraw consent at any time (such as by disconnecting a data source). You will not be discriminated against for exercising them.
You can exercise most of these directly: edit your profile in settings, disconnect integrations, delete uploaded documents, or cancel your subscription in the billing portal. For anything else — including full account deletion and data export — email privacy@askforesight.ai and we will respond within 30 days. If you are in the EU/UK, you also have the right to lodge a complaint with your data-protection authority.
10 International transfers
Our infrastructure and service providers may process data in the United States and the European Union. Where personal data is transferred out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or the providers' participation in the EU-U.S. Data Privacy Framework.
11 Children
The Service is a business tool, not directed to children, and may not be used by anyone under 16. We do not knowingly collect personal information from children; if you believe a child has provided us information, contact us and we will delete it.
12 Changes to this policy
We may update this policy as the Service evolves. We will post the new version at this address with an updated date, and for material changes we will notify you by email or in the Service before they take effect.