CHGROUP – FZCO (“Conqueror”, “we”, “us”) is the controller of the personal data described here. We are a free zone company registered in the United Arab Emirates, registered office at IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates.
It does not cover self-hosted Conqueror. If you run your own copy of the open-source software, you control that deployment and its data; we receive nothing from it.
If you are here for the Google disclosures — what Google user data we access, how we use it, who we share it with, how we protect it, and how long we keep it — that is section 5 below.
2. What we collect
What you give us
Name, email, password hash (or your Google sign-in identifier) — to create and secure your account.
Organisation and project details, including the domains you track — to deliver the product.
Keywords, notes, saved research and other content you enter — to deliver the product.
Messages you send to our AI agents — to answer them.
Support correspondence — to help you.
What third parties give us, on your instruction
Search Console performance and index data for properties you connect — from Google, read-only. See section 5.
Analytics traffic and engagement data for GA4 properties you connect — from Google, read-only. See section 5.
Post content and metadata for sites you connect — from your WordPress installation.
Billing status, card brand, last four digits, country — from Stripe.
We never receive or store your full card number. Stripe handles that.
What we collect automatically
Log and device data: IP address, browser and device type, pages viewed, actions taken, timestamps, referring URL.
Product analytics events describing how features are used.
Cookies and local browser storage — see section 7.
Credentials you connect. If you bring your own API keys — DataForSEO, an AI provider, WordPress application passwords, Google OAuth tokens — we store them encrypted at rest and use them only to make the calls you asked for. They are never shown back to you in full and are deleted when you disconnect the integration.
3. Why we use it, and our legal basis
To provide the Service, run your projects and integrations — performance of a contract.
To authenticate you and secure accounts — contract; legitimate interests.
To take payment, manage subscriptions and prevent payment fraud — contract; legal obligation.
To send service and transactional email — verification, receipts, alerts — contract.
To provide support — contract; legitimate interests.
To understand feature usage and improve the product — legitimate interests, or consent where required.
To send marketing email about Conqueror — consent, or legitimate interests where permitted. Opt out any time.
To measure advertising effectiveness — consent where required.
To meet legal obligations and defend legal claims — legal obligation; legitimate interests.
We do not sell personal data, and we do not use Your Content to train AI models.
4. AI processing — read this one
When you use the in-app agents, the content of your messages and the data the agent needs to answer are sent to an AI model provider to generate a response.
Which provider depends on configuration: OpenRouter, Anthropic, OpenAI, Google, or AWS Bedrock.
We request zero-data-retention handling from our routing provider where that option is available, meaning prompts are not retained for training or logging beyond what is needed to return the response.
If you connect your own AI provider key, your prompts go to that provider under your own account and your own agreement with them.
Please do not paste passwords, payment details, health information, or other sensitive personal data into agent conversations.
5. Google user data
Conqueror reads Google Search Console and Google Analytics data when you connect them, and receives basic profile data when you sign in with Google. This section sets out exactly what that involves. It applies on top of the rest of this policy, and where the two differ, this section governs Google user data.
5.1 What Google user data we access
We request these scopes, and no others.
openid, email, profile Grants your Google account’s name, email address, profile picture and account identifier. Requested at Sign in with Google, and again at each integration so we can label which Google account it uses.
https://www.googleapis.com/auth/webmasters.readonlyGrants read-only access to the Search Console properties you are verified on. Requested only when you connect Search Console to a project, from Project settings.
https://www.googleapis.com/auth/analytics.readonlyGrants read-only access to the Google Analytics 4 properties you can read. Requested only when you connect Analytics to a project, from Project settings.
Both integration scopes are read-only. Conqueror cannot change, add, or delete anything in your Search Console or Analytics account, and we request no scope that would let it.
What we read through them:
Search Console — the properties on your account and your permission level on each (sites.list); clicks, impressions, click-through rate and average position, broken down by query, page, country, device and date (searchAnalytics.query); and Google’s index status for URLs you ask about, including crawl state, canonical URL and mobile usability verdict (urlInspection.index.inspect).
Google Analytics — the GA4 properties on your account (accountSummaries.list), and the metrics and dimensions of reports you run, such as sessions, users, engagement and conversions by page, channel and date (properties.runReport).
Sign in with Google — your name, email address, profile picture and Google account identifier.
We do not access Gmail, Drive, Calendar, Contacts, or any other Google service.
5.2 How we use it
Your name, email, profile picture and account id — to create and authenticate your Conqueror account, and to show you which Google account each integration is connected to.
Your Search Console property list — to let you choose which property a Conqueror project tracks.
Search Console performance rows — to draw the search performance charts and tables, surface keywords you already rank for, measure whether a content change moved clicks or position, and answer questions you ask an AI agent about your search performance.
Search Console URL inspection — to tell you whether a page is indexed, and why it is not.
Your Analytics property list — to let you choose which GA4 property a project tracks.
Analytics report rows — to show traffic and engagement next to your search data, and answer questions you ask an AI agent about it.
We read this data only to run features you are using — when you open a screen that shows it, ask an agent a question that needs it, or run a check you scheduled. We do not crawl your Google account for anything else.
When AI agents are involved. Conqueror’s agents — the in-app agent, and any AI client you connect over MCP, such as Claude or ChatGPT — call the same read-only tools you would. If you ask one of them a question that needs Search Console or Analytics data, the rows needed to answer it are sent to the AI model provider handling that request, as described in section 4. Nothing reaches a model unless a question of yours needs it.
5.3 What we never do with it
We do not use Google user data to develop, train, or improve generalised AI or machine-learning models — ours or anyone else’s. Our AI providers process it under API terms that do not permit training on it, and we request zero-data-retention handling where the provider offers it.
We do not sell it, and we do not use it for advertising. It never reaches our advertising or product-analytics processors.
We do not transfer it to data brokers, or use it for credit assessment, lending, or any purpose unrelated to the features you are using.
Our staff do not read it, except in the narrow cases Google permits: with your explicit consent, when you ask us for help with a specific problem; where it is necessary for security investigations or abuse prevention; or where the law compels it.
5.4 Who we share, transfer, or disclose it to
We do not sell Google user data or disclose it to anyone outside this list:
Cloudflare and Neon, who host our application and database — connection records and encrypted OAuth tokens at rest, and API responses in transit while a request runs.
The AI provider serving your request — OpenRouter, Anthropic, OpenAI, Google, AWS Bedrock, or your own provider key — receives only the Search Console or Analytics rows needed to answer the question you asked, in order to generate the agent’s answer.
The AI client you connect over MCP — Claude, ChatGPT, Cursor and similar — receives only the rows returned by the tool call that client made, because you connected it to your Conqueror workspace.
Law enforcement or regulators — only what is legally compelled.
An acquirer, in a merger or sale of assets — data held at the time. We will notify you before your data becomes subject to a different policy.
Members of your Conqueror organisation can see the Search Console and Analytics data of projects they have access to. That is what connecting an integration to a shared workspace does; control it through your organisation’s member list.
5.5 How we protect it
OAuth access and refresh tokens are encrypted at rest with authenticated encryption (XChaCha20-Poly1305) at the application layer, keyed from a secret held in a managed secrets store, before they are written to the database. They are never returned to the browser, never logged, and never shown back to you.
All traffic runs over TLS, and every Google API call is made server-side. No Google access token is ever exposed to client-side code.
Access is scoped per project and per organisation and checked on every request. A connection serves the project it was made on, and only people in that project’s organisation can see its data.
We request the minimum scopes our features need, and only read-only ones.
Staff access to production systems is role-limited, and application secrets live in a managed secrets store rather than in code.
We keep no copy of your Search Console or Analytics account — see 5.6 — so the data at rest is limited to the connection record and what an agent quoted back to you.
5.6 How long we keep it, and how to delete it
We do not build a copy of your Search Console or Analytics account. Performance and report rows are fetched from Google when a request needs them and are discarded once the response is served. We store the connection, not the data.
Search Console and Analytics rows — not stored. Fetched per request, discarded after the response.
The connection record — which property maps to which project, and the email of the connected Google account — until you disconnect the integration, delete the project, or delete your account.
OAuth access and refresh tokens — until you disconnect the integration, delete your account, or revoke the grant at Google.
Google sign-in profile data on your account — while your account exists; deleted or anonymised within 90 days of closure.
An agent answer that quoted the data — with the rest of your chat history, until you delete that conversation or your account.
To delete it:
Disconnect the integration. In Conqueror, open Project settings and press Disconnect on the Search Console or Analytics card. This deletes the connection record immediately, and deletes the stored OAuth tokens once no other project is using that grant.
Revoke at Google. Go to myaccount.google.com/permissions and remove Conqueror. This invalidates our tokens straight away, whatever we hold.
Delete your account. Email [email protected] and we will delete the account and everything above with it, within 90 days.
5.7 Limited Use
Conqueror’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Who we share it with
We share personal data with service providers who process it on our behalf, under contract, only for the purposes above:
Encharge — lifecycle and marketing email, where you have not opted out.
PostHog — product analytics.
Reddit — advertising conversion measurement, where consented.
Google user data goes to a narrower list than this — see section 5.4. It never reaches PostHog, Reddit, Encharge, Loops, or DataForSEO.
We also disclose data where we must comply with law, enforce our Terms, protect rights and safety, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you before your data becomes subject to a different policy.
7. Cookies, local storage, and analytics
We use cookies and browser local storage to keep you signed in, remember preferences such as theme and last-opened project, and measure product usage.
Strictly necessary storage — session and authentication — cannot be turned off without breaking the Service.
Analytics and advertising measurement are optional. You can disable product analytics at any time in Settings → Analytics, and your browser’s cookie controls apply as well. Where local law requires consent for non-essential cookies, we ask before setting them.
8. International transfers
We operate globally and our processors are located in several countries, including the United States and the European Union. Where personal data leaves the UAE or the European Economic Area, we rely on appropriate safeguards — typically Standard Contractual Clauses or an adequacy decision — and require processors to protect it to the standard described here.
9. How long we keep it
Retention for Google user data specifically is in section 5.6. For everything else:
Account and project data — while your account is active.
Data after account closure — deleted or anonymised within 90 days, except as below.
Billing and tax records — as long as tax and accounting law requires.
Security and audit logs — up to 12 months.
Backups — aged out on our normal backup cycle.
Connected credentials — deleted when you disconnect the integration.
We may retain data longer where necessary to resolve disputes or enforce agreements.
10. Security
We protect data with encryption in transit and at rest, encryption of connected third-party credentials at the application layer, access controls limiting staff access to what their role requires, and secrets held in a managed secrets store rather than in code.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any relevant regulator as required by law.
11. Your rights
Depending on where you live, you may have the right to:
Access the personal data we hold about you;
Correct inaccurate data;
Delete your data;
Export your data in a portable format;
Restrict or object to certain processing, including profiling;
Withdraw consent at any time, without affecting prior processing;
Opt out of marketing — every marketing email has an unsubscribe link;
Complain to your data protection authority.
To exercise any of these, email [email protected]. We respond within 30 days and may need to verify your identity first. Exercising your rights never costs you anything or degrades your service.
12. Children
The Service is not directed at anyone under 18 and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy. Material changes will be notified by email or in the app before they take effect, and the “last updated” date above will change.
14. Contact
CHGROUP – FZCO IFZA Business Park, DDP, PO Box 342001 Dubai, United Arab Emirates Email: [email protected]