Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how Oniq ("Oniq", "we", "us", or "our"), operated by ONIQ AI LTD, a company registered in England and Wales (company number 17084772) with its registered office at Flat 204 The Circle, Queen Elizabeth Street, London, England, SE1 2JN, collects, uses, stores, and protects information in connection with the Oniq marketing-audit service (the "Service"), available at oniqai.com and its subdomains (including connect.oniqai.com and audits.oniqai.com).
If you have any questions, contact us at privacy@oniqai.com.
1. Who this policy is for
Oniq is a business-to-business service. Our customers are businesses (each an "Auditee") who ask us to analyse the marketing and analytics accounts they own or are authorised to access, and to produce prioritised growth recommendations.
When an Auditee connects an account (for example Google or Meta), they authorise Oniq to read data from that account on their behalf. For that data, the Auditee is the controller and Oniq acts as a processor. Oniq is the controller for the limited account information we use to operate the Service (for example the email address used to sign in to the results dashboard).
2. What the Service does
Oniq connects, with your explicit authorisation, to the marketing and analytics platforms you already use, reads performance data from them, crawls the public pages of your own website, and uses automated analysis (including AI) to produce a prioritised set of growth actions. Results are presented to you in a dashboard. We do not run ads, place cookies on your visitors, or modify your accounts. Our access to your connected platforms is read-only.
3. Information we access and collect
3.1 Google account data (read-only)
When you connect a Google account, you grant the following read-only scopes. We request only what the Service needs, and only the scopes for the platforms you choose to connect:
| Scope | Platform | What we read |
|---|---|---|
.../auth/analytics.readonly | Google Analytics 4 (incl. Firebase Analytics) | Aggregate traffic, events, conversions, and audience metrics for the properties you select. |
.../auth/webmasters.readonly | Google Search Console | Search performance: queries, impressions, clicks, and indexed pages. |
.../auth/adwords | Google Ads | Campaign structure, spend, keywords, landing pages, and conversion actions. |
.../auth/androidpublisher | Google Play Console | App listing details, statistics, and reviews. |
.../auth/devstorage.read_only | Google Play bulk reports (Cloud Storage) | Bulk report exports (installs, ratings, and, where you have granted the role, financial/earnings reports). |
The Google Analytics data we read is aggregate and reported at the metric level. We do not request scopes that read individual end-user identities.
3.2 Meta account data (read-only)
When you connect a Meta (Facebook and Instagram) account, you grant the read-only scopes ads_read and business_management. We read aggregate ad performance: campaigns, spend, delivery, lead counts, and reported conversions, plus the business-asset structure needed to locate the right ad accounts. We do not request the `leads_retrieval` scope and do not retrieve the personal contact details of individual leads submitted through your lead forms; we read only aggregate lead counts and costs.
3.3 Website and public data
As part of an audit we fetch and store the public pages of the website you ask us to audit (including pages linked from your ad campaigns), capture screenshots of those pages, and request performance measurements from the Google PageSpeed Insights API. This covers only publicly accessible pages of the site you engage us to audit.
3.4 Authentication and account data
To use the results dashboard you sign in with a one-time "magic link" sent to your email address. We store that email address and basic sign-in records to operate and secure the dashboard.
3.5 OAuth tokens
To read the data above, we store the access and refresh tokens issued by Google and Meta. These tokens let the Service read your connected accounts until you revoke access. See Section 8 for how they are secured.
4. How we use information
We use the information solely to:
- provide the Service: analyse your connected accounts and website, and generate and display your prioritised growth actions;
- record the outcome of actions you implement, so future audits for your account are better calibrated;
- operate, secure, debug, and improve the Service; and
- comply with legal obligations.
We do not sell your data, use it for advertising, or share it for others' advertising or marketing.
5. Automated and AI processing
Oniq's analysis is performed by automated software that includes large language models. To generate your audit we transmit the collected data (including aggregate platform metrics and website screenshots) to Anthropic, PBC, which provides the Claude AI models through its API, acting as our sub-processor and processing the data under Anthropic's commercial terms.
The data is processed by AI only to generate the specific audit for the account that granted access. We do not use your data, and we do not permit our AI sub-processor to use your data, to train, develop, or improve any generalised or foundational AI or machine-learning models.
6. Google API Services Limited Use disclosure
Oniq's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use access to Google user data to provide and improve the user-facing features of the Service that are prominent in the Oniq interface.
- We only transfer Google user data to others as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with your consent.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data except: with your affirmative consent for the audit you have requested; where necessary for security purposes or to comply with applicable law; or where the data has been aggregated and anonymised for internal operations. Human access is limited to authorised personnel delivering or supporting the audit you engaged us to perform.
The same commitments apply to data we receive from Meta and other connected platforms.
7. How we share information (sub-processors)
We share information only with service providers that help us run the Service, under contract and for the purposes above:
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Anthropic, PBC | AI analysis (Claude API) | Aggregate platform metrics and website screenshots for your audit. |
| Cloudflare, Inc. | Application hosting and storage (Workers, R2, D1, KV) | Audit outputs, dashboard data, and, on the relay, end-to-end-encrypted tokens. |
| Google LLC | Source APIs and PageSpeed Insights | Requests to the APIs you authorised. |
| Meta Platforms, Inc. | Source APIs | Requests to the ad accounts you authorised. |
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of Oniq, our customers, or the public. We do not otherwise sell or rent personal information.
An up-to-date list of sub-processors is available on request.
8. Where data is stored and how we secure it
Audit data and outputs are stored on the machine operating the audit and on Cloudflare infrastructure (R2 object storage and a D1 database) associated with audits.oniqai.com.
We apply safeguards appropriate to the data, including:
- End-to-end encryption of tokens on the relay. When onboarding is done remotely, the sign-in tokens are sealed to the operator using ECDH-P256 and AES-GCM, so the relay's temporary key store holds only ciphertext, which the operator alone can decrypt.
- Automatic expiry. Relay token bundles expire from the key store after roughly seven days.
- Restrictive storage. Locally cached tokens are written with owner-only file permissions.
- Access control. The results dashboard is gated behind email magic-link authentication and an operator allowlist.
No method of transmission or storage is completely secure, but we work to protect your information using measures appropriate to its sensitivity.
9. Data retention and deletion
We retain audit data for as long as needed to provide the Service to you, and then as required for legal, security, or record-keeping purposes.
- Relay token bundles expire automatically after approximately seven days.
- You can revoke Oniq's access to any connected account at any time (see Section 10), which stops all future data collection.
- On offboarding, or on your request, we delete your account folder (its stored runs and tokens) and the associated database records.
To request deletion, contact privacy@oniqai.com.
10. Your rights and choices
Revoke access at any time. You can disconnect Oniq without contacting us:
- Google: Google Account permissions
- Meta: Business Settings → Business Integrations for the connected Business account.
Data-protection rights. Depending on where you are, you may have the right to access, correct, delete, port, or restrict processing of your personal information, and to object to processing. If you are in the EEA or UK, the legal bases we rely on are performance of a contract and our legitimate interest in operating and securing the Service. If you are a California resident, we do not sell or "share" personal information as those terms are defined under the CCPA.
To exercise any right, contact privacy@oniqai.com. Where we act as a processor on an Auditee's behalf, we will refer a request to the relevant Auditee (controller) or act on their instructions.
11. International transfers
We operate internationally, and information may be processed in countries other than your own, including the United States. Where required, we use appropriate safeguards (such as the European Commission's Standard Contractual Clauses) for such transfers.
12. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, for material changes, take reasonable steps to notify you.
14. Contact
ONIQ AI LTD Flat 204 The Circle, Queen Elizabeth Street, London, England, SE1 2JN Company number 17084772 (registered in England and Wales) Email: privacy@oniqai.com