the legal bit, in plain words
Privacy policy
last updated: 6 august 2026
01Who we are
Vidima is a product of Evolving Technologies EOOD (Еволвинг Технолоджис ЕООД), a company registered in Bulgaria under UIC 205701587, with its registered seat at 105 Gotse Delchev Blvd, fl. 7, apt. 21, Triaditsa District, 1404 Sofia, Bulgaria. We are the data controller for the personal data described in this policy.
Vidima shows businesses how they appear in AI-generated answers, in ChatGPT, Perplexity, Gemini and Google AI Overviews, and what to change to appear more often.
For anything at all about your data, write to privacy@vidima.ai. A real person reads it, and we aim to reply within five working days.
02What this policy covers
This policy covers two things:
- The website at vidima.ai - the marketing pages you are reading now.
- The Vidima application - the signed-in product where you track websites, run prompts against AI engines, and review results.
It does not cover other companies' websites we link to, or the AI engines themselves. If you connect a Google Analytics property, section 04 applies in addition to everything below, and takes precedence where the two differ.
03What we collect, and why
We collect the minimum needed to run the product. We never buy personal data, and we never sell it.
- Your account. Email address, a securely hashed password (or your chosen sign-in method), and your workspace name. We never store passwords in a readable form.
- What you ask us to monitor. The website domains you track, the prompts you want tested, your market and language, and the competitors you add.
- Results we generate for you. Answers collected from public AI engines, which brands they mention, which sources they cite, and the recommendations we derive. This is largely public information about businesses, not about individuals.
- Billing. Your plan, subscription status and invoices. Payments run through Stripe - card numbers never reach our servers and we cannot see them.
- Google Analytics data, only if you connect it. See section 04.
- Technical logs. Request metadata, error traces and security events, so we can keep the service up and detect abuse. We deliberately do not write credentials, tokens or API keys into logs.
04Google Analytics data - what we access and how we protect it
Vidima can show you how much traffic AI assistants send to your website. To do that, you may optionally connect a Google Analytics 4 property. The feature is off until you connect it, you choose which property to connect, and you can disconnect at any time. Nothing below happens unless you take that step.
The single permission we ask for. We request exactly one Google authorisation scope:
.../auth/analytics.readonly- read-only access to Google Analytics.
It grants no ability to change anything. We do not request access to Gmail, Drive, Calendar, Contacts, your Google profile, your name, your photo, or any other Google service - and we do not use incremental authorisation, so permissions you have granted to other applications are never attached to ours. If Google reports that you declined the Analytics permission, we stop and store nothing.
What we read. Only two things, and only aggregate figures:
- The list of Analytics properties your Google account can access, with their property and account names, shown once so you can choose which one to connect.
- For the property you choose, daily session counts - total sessions and engaged sessions, and the same figures broken down by traffic source - plus the property's reporting timezone.
What we never read. We do not request or receive data about individual visitors to your website, so no user or client identifiers, no IP addresses, no demographics, no device fingerprints, no event-level records, no page-level or e-commerce detail. We request only pre-aggregated report rows. We cannot identify any individual visitor to your site from what we receive, and we make no attempt to.
How we protect it. Because this is sensitive data, it gets specific technical and organisational safeguards:
- Encrypted in transit. Every connection to Google's APIs, and every connection between your browser and our services, uses TLS. We do not accept unencrypted connections.
- Encrypted at rest, individually. The long-lived authorisation credential is sealed with AES-256-GCM authenticated encryption before it is written to the database, with a unique initialisation vector for every record and an authentication tag that makes silent tampering detectable. The 256-bit key is held in a managed secrets service on separate infrastructure from the database that stores the encrypted value - it is never committed to source control, never written to logs, and never stored beside the data it protects.
- Short-lived tokens are never stored at all. The short-lived access token Google issues is used and discarded in memory; it is never written to disk or database.
- The connection handshake is hardened. We use PKCE (RFC 7636, SHA-256 method) so an intercepted authorisation code is useless on its own. The anti-forgery token is stored only as a SHA-256 hash, can be used exactly once, and expires after ten minutes.
- Strict isolation in the database. The tables holding Google credentials have row-level security enabled with no access policies at all and are revoked from every application role. They are unreachable from the browser and from ordinary application code - only a restricted server-side role can read them.
- You can only ever reach your own property. The list of selectable properties comes from Google itself, based on your own account's access. There is no way to type in a property ID, so no customer can address an Analytics property they do not already control.
- Secrets are never logged. Authorisation codes, tokens and client secrets are excluded from all logs and error messages by design; failures record only a coarse status code.
- Separated from our AI processing. Google Analytics data is stored and displayed in an isolated part of the system. It is never sent to any AI or large-language-model provider, and never mixed into the data used to generate recommendations.
- Limited human access. Access to production systems is restricted to authorised personnel on a need-to-know basis. We do not browse customer Analytics data; staff access happens only for the narrow reasons listed under Limited Use below.
Limited Use. Vidima's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely:
- We use Google user data only to provide and improve the traffic feature you connected it for - the one that shows you AI-driven visits.
- We do not transfer it to third parties except as necessary to provide that feature, to comply with applicable law, or as part of a merger or acquisition after giving you notice and obtaining your consent where required.
- We never sell Google user data, and we never use it for advertising, retargeting or profiling.
- We do not allow humans to read it, except with your explicit consent (for example when you ask us to help debug a connection); where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and anonymised.
- We do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models, our own or anyone else's.
How long we keep it. We hold a rolling window of the most recent 400 days of aggregate daily figures for your connected property; older rows fall out of the window automatically. The authorisation credential is kept only for as long as the connection is active.
Revoking access and deleting the data. Two ways, both effective:
- Disconnect inside Vidima (website settings → AI Traffic). We ask Google to revoke our credential immediately, delete the stored credential, and delete every Analytics figure we synced for that website. This is immediate and irreversible.
- Revoke at Google, via myaccount.google.com/permissions. That stops us reading anything further. Email privacy@vidima.ai if you also want the figures we already hold erased.
If you abandon the connection part-way through, for example by closing the tab at the property picker, we hand the unused credential back to Google automatically rather than keeping it.
05Our legal bases for using your data
Under the GDPR we rely on:
- Consent (Art. 6(1)(a)) - non-essential analytics cookies and connecting your Google Analytics account. You can withdraw consent at any time; withdrawing does not affect processing already carried out.
- Performance of a contract (Art. 6(1)(b)) - running your account, producing your reports, and taking payment.
- Legitimate interests (Art. 6(1)(f)) - keeping the service secure, preventing abuse, and understanding aggregate product usage. We balance these against your rights and use the least intrusive option that works.
- Legal obligation (Art. 6(1)(c)) - keeping invoices and accounting records for the period Bulgarian law requires.
07Where your data lives
Our database, application servers and background processing all run in the European Union (Frankfurt, Germany), and our server-side application code is pinned to an EU region to keep your data close to it.
Some providers above (Google, Stripe, and AI model providers) are based in the United States or process data there. Where personal data leaves the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses, by the provider's certification under the EU-US Data Privacy Framework, or by another safeguard permitted under Chapter V of the GDPR.
08How long we keep things
- Account and workspace data - for as long as your account is open. When you delete your account, we make the data inaccessible immediately and permanently erase it within 30 days. Encrypted backups are erased on their own rotation cycle, within 90 days at the latest.
- Google Analytics figures - a rolling 400 days, and deleted entirely the moment you disconnect (see section 04).
- Invoices and accounting records - retained for the period Bulgarian tax law requires, regardless of account deletion.
- Technical and security logs - a short rolling window, then discarded.
09How we protect data generally
- Everything travels over TLS. Our databases and file storage are encrypted at rest.
- Credentials and API keys live in a managed secrets service, never in source control.
- Customer data is separated at the database level by row-level security, so one customer's query cannot reach another customer's rows.
- Passwords are hashed, never stored or transmitted in readable form. We cannot see your password.
- Access to production is limited to authorised personnel on a need-to-know basis.
- Sensitive values are excluded from logs and error reports by design.
No system is perfectly secure, and we will not pretend otherwise. If a breach ever affects your personal data, we will notify the CPDP within 72 hours as the GDPR requires, and tell you directly where the law requires it.
10Your rights
Wherever you are, you can ask us to:
- Show you what we hold about you, and give you a copy.
- Correct anything that is wrong.
- Delete it (“right to be forgotten”).
- Restrict or object to how we use it, including any processing based on legitimate interests.
- Port it - receive it in a structured, machine-readable format, or have it sent to another provider.
- Withdraw consent at any time, where consent is what we relied on.
One email to privacy@vidima.ai does any of these. We will respond within one month and we will not charge you. We do not make decisions producing legal effects about you by automated means alone.
If you are unhappy with our answer, you can complain to your local data-protection authority. Ours is the Commission for Personal Data Protection (Комисия за защита на личните данни).
12Children
Vidima is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email privacy@vidima.ai and we will delete it.
13Changes to this policy
If how we handle data changes, this page changes with it, and the date at the top always reflects the current version. If a change materially affects your rights, and always before we would use Google Analytics data for anything beyond what section 04 describes, we will tell you directly and, where the law requires it, ask for your consent again.
14How to reach us
Еволвинг Технолоджис ЕООД
105 Gotse Delchev Blvd, fl. 7, apt. 21, Triaditsa District, 1404 Sofia, Bulgaria
БЪЛГАРИЯ, гр. София (1404), р-н Триадица, бул. Гоце Делчев, 105, ет. 7, ап. 21
UIC 205701587 · VAT BG205701587
Privacy and data requests: privacy@vidima.ai
Everything else: hello@vidima.ai
See also our Terms of Service.