Security and data protection
This page describes concretely what happens to your data. No badges, no certifications we do not hold.
Where your product data lives
Your product data, scores and account records live in our PostgreSQL database at Supabase in region eu-central-1, which is AWS Frankfurt. The same applies to file storage, for example Excel exports.
An important limitation, because there is no point glossing over it: not everything about FeedOptimizer.AI sits in the EU. The marketing website is served through Vercel, payments run through Stripe, AI processing runs through Google's Gemini API, and our company is based in the US. The full list is below.
How we access your Merchant Center
The connection runs through Google OAuth 2.0. We never see your Google password, it is never transmitted to us, and we do not store it. What we store are the access and refresh tokens Google issues, and those sit encrypted in the database.
Google does not offer a read-only permission for Merchant Center. There is one scope, and the consent screen calls it "manage". During the feed check we only read. We write only once you approve a specific optimization in the Workbench. Go to the free feed check.
What we do not do to your feed
- We never write into your primary feed. It stays as it is.
- Approved optimizations go into a separate supplemental feed that we create in your Merchant Center. You can delete it at any time and your original takes over again.
- We do not pass your data to third parties, other than the service providers listed below that we need to run the service.
- We do not sell data and we do not use it for advertising.
What goes to the AI
For optimizations and for the example rewrites in the report we send product data to Google's Gemini API: title, description, attributes, product URL and category. That processing does not necessarily happen in the EU.
What we do not send: customer data, order data, revenue, your credentials. We simply do not have them, because we have no access to your store, only to the product feed in Merchant Center.
Encryption and access control
- Transport exclusively over TLS.
- Encryption at rest at the database and storage layer.
- OAuth tokens additionally encrypted at the application layer.
- Row level security in the database: access rules enforce that an account can only read its own feeds, products and scores.
Revoking access and deleting data
- Revoke access: any time in your Google account at myaccount.google.com/permissions. After that we cannot retrieve anything.
- Delete account and data: directly in the app settings. This removes product data, scores, optimization history and tokens.
- On request: write to support@feedoptimizer.ai and we will handle it.
- If you lose access to an account inside Merchant Center, we flag it and delete the associated data automatically after 30 days unless you tell us otherwise.
Service providers we use
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, auth, file storage | EU (Frankfurt) |
| Google Gemini | AI optimization of product text | US / EU |
| Google Merchant API | Reading the feed, uploading the supplemental feed | US / EU |
| Vercel | Website hosting | US |
| Stripe | Payment processing (paid plans only) | US |
| Resend | Transactional email delivery | US |
| Sentry | Error monitoring (technical error data) | US / EU |
| Google Analytics 4 | Website analytics, only with your consent | EU / US |
Details on legal bases, retention periods and your rights are in the privacy policy.
Data processing agreement
If you check feeds for clients as an agency, you are processing someone else's data and you need a data processing agreement. We provide one: request a DPA.
Reporting a security issue
If you find a vulnerability, please write to support@feedoptimizer.ai with subject "Security". We will get back to you and will not publish anything before the issue is fixed.