Controller and scope
2-UA is operated by Aleksei Galiev, an individual operating a registered micro business in Georgia under identification number 305576392, trading as 2-UA ("2-UA", "we", "us", or "our").
25 Airport Highway, Apartment 125Batumi, Georgia
Email: support@2-ua.com
We are the controller of personal data processed through 2-ua.com and its related services, except where a third-party provider acts as an independent controller under its own policy. This Policy applies to visitors, registered users, customers, free-tool users, and people who contact us.
We process personal data under the laws of Georgia, including the Law of Georgia on Personal Data Protection. Where another law applies to a particular user or processing activity, including the EU General Data Protection Regulation, we also respect the mandatory rights provided by that law.
Data we collect and its sources
Depending on how you use 2-UA, we may collect:
- Account data: name, email address, password hash, account identifiers, preferences, and account status.
- Billing and purchase data: selected subscription plan or prepaid credits, billing status, dates, the country you confirm at checkout, any country returned by PayPal for a Remote Crawler payment, PayPal subscription and transaction identifiers, and payment-related correspondence. We use country information to review tax obligations and payment records. PayPal processes payment credentials; we do not store complete card or PayPal login details.
- Website and monitoring data: domains, URLs, project settings, public page content, technical measurements, check history, reports, and notification destinations you configure.
- AI visibility data: brand names, aliases, competitors, prompts, AI answers, citations, model and engine information, and usage records.
- Connected-service data: OAuth tokens, provider authorization identifiers, authorized Webflow site identifiers, names and public domains, Webflow publish and page-metadata event details, selected Google properties, and Google Analytics or Search Console data when you connect those services.
- Communications: your name, email address, subject, message, support history, feedback, and chat content.
- Device and usage data: IP address, browser and device information, language, referring page, timestamps, requested pages, cookies, security events, and diagnostic logs.
- Free-tool data: submitted URLs, brands, prompts, results, rate-limit identifiers, and abuse-prevention signals.
We receive data directly from you, automatically from your browser or use of the service, from services you choose to connect, and from publicly accessible websites that you ask us to inspect. Do not submit passwords, payment credentials, special-category data, or confidential personal information in prompts, URLs, support messages, or monitored page content.
Why we process data
- Contract: to create and administer accounts, provide checks and reports, operate subscriptions, process requested integrations, send service notifications, and provide support.
- Legitimate interests: to secure the service, prevent fraud and abuse, enforce limits, diagnose failures, maintain logs, improve reliability, understand aggregate product usage, and establish or defend legal claims.
- Consent: to use optional analytics or advertising technologies, connect optional third-party accounts, and send direct marketing where consent is required. You may withdraw consent at any time.
- Legal obligations: to keep required transaction and accounting records, respond to lawful requests, and comply with tax, consumer, and data-protection requirements.
Information required to create an account, purchase a subscription, or run a requested check is contractual. If you do not provide it, we may be unable to provide that feature. Optional profile, integration, marketing, and analytics data is not required for basic access.
AI processing and connected services
When you run AI visibility features, the prompt and relevant brand, competitor, or website context are sent through OpenRouter to the selected AI model provider, which may include OpenAI, Google, Perplexity, or another provider shown or configured for the feature. Their systems return the answers and citations that we store in your measurement history.
AI inputs may be processed outside Georgia. Do not include personal, sensitive, or confidential information in tracked prompts. AI answers may be inaccurate and are not used by 2-UA to make decisions that produce legal or similarly significant effects about you.
If you authorize the Webflow SEO Release Guard, Webflow provides the authorized site identity and release-event metadata needed to monitor that site's public URLs. If you choose Google sign-in or connect Google Analytics or Search Console, Google provides the data needed for that feature. You can disconnect an integration from 2-UA; you may also revoke access in the provider's account settings.
Google sign-in, Analytics, and Search Console data
You choose whether to connect Google. Basic identity permissions (openid, email, and profile) identify the Google account used for sign-in or an integration. We receive account identifiers, email address, and basic profile information; we do not receive your Google password.
- Google Analytics 4:
analytics.readonlylets us list accessible Analytics accounts and properties so you can select a property, then read aggregate sessions, key events, and revenue by date, referral source, landing page, and device. AI Referral Analytics uses these reports to show traffic from AI services, compare reporting periods, and match landing pages with citations already saved in your project. It does not modify Analytics properties, settings, events, or permissions. - Google Search Console:
webmasters.readonlylets us list accessible properties and read search-performance data, including pages, queries, dates, devices, countries, clicks, impressions, click-through rate, and position. We use it for the connected site's search reports, URL discovery, keyword monitoring, and change-impact comparisons. It does not modify your Search Console settings.
Storage, protection, and deletion
We store the connected Google email, selected property, and OAuth credentials needed to maintain the connection. Google Analytics access and refresh tokens and Search Console refresh tokens are encrypted at rest. Connections to Google APIs use HTTPS, and project access controls restrict reports and connection management to authorized users.
GA4 report rows are requested on demand and are not copied into the 2-UA database. Disconnecting Google Analytics immediately deletes its saved credentials, Google email, and property selection from the active database. Search Console performance rows are stored to provide historical reports; disconnecting Search Console deletes its saved credentials but does not erase previously imported history. History follows the applicable retention settings. To request deletion of retained Google data, contact support@2-ua.com or request account deletion in Profile Settings. Backup copies follow the rotation described below.
You may also revoke 2-UA access from your Google Account's third-party connections. Revoking access stops authorized future access; it does not itself delete previously imported records from 2-UA. Access-token expiry alone does not delete a saved connection when a valid refresh token allows it to continue.
Use, sharing, and AI boundaries
Google API data is used for the connected features described above. The AI Referral Analytics report uses calculations and matching within 2-UA; it does not send GA4 reports or OAuth credentials to OpenRouter or AI model providers. The separate AI visibility workflow sends the prompts and website context described above. We do not use Google API data to train or fine-tune generalized AI or machine-learning models.
Infrastructure providers may process Google data on our behalf to host and operate these features. We do not sell Google user data, disclose it to data brokers or advertising platforms, or use it for advertising, retargeting, creditworthiness, or lending. Optional website analytics and advertising cookies do not authorize those uses of connected Google API data. Other transfers are limited to delivering the disclosed feature with your consent, security, legal requirements, or a business transfer with your prior consent. Human access is limited to your affirmative agreement, necessary security investigations, legal requirements, or permitted aggregated internal operations.
2-UA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2-UA browser extensions
2-UA browser extensions process the active page URL and the minimum page information required for the feature the user explicitly starts. Depending on the extension, this may include public page metadata, headings, links, structured data, visible content structure, HTTP responses, or a baseline saved in local browser storage. Extension-specific handling is described in the applicable Chrome web store listing.
AI SEO & GEO Readiness Checker runs its readiness analysis in the browser. It requests the selected public page and that website's public robots.txt, sitemap.xml, and llms.txt files without cookies. Page content, optional brand input, and local audit results are not sent to 2-UA. If the user explicitly clicks Open full report, the selected page URL is sent to 2-UA over HTTPS in the url query parameter to prefill the requested audit form.
SEO Release Guard runs only when the user opens it on a page. It reads SEO-related fields from that page and, when requested, downloads the public HTML of a live or reference URL without cookies. Access to a different website origin is requested only after the user enters that URL. Dated page versions, extracted SEO values, and comparison results are stored locally in the browser and are not sent to 2-UA. Public HTML is parsed only as data; all executable code is packaged with the extension.
Information received through Chrome APIs is used only to provide the extension's disclosed user-facing feature. We do not sell this information, use it for personalized advertising or credit decisions, or allow human access except where permitted by the Chrome web store User Data Policy. Our use of information received through Chrome APIs adheres to the Chrome web store User Data Policy , including its Limited Use requirements.
International transfers and retention
Some recipients operate in countries outside Georgia or your country of residence. Where required, we use provider agreements, contractual protections, consent, or another lawful transfer mechanism. You may contact us for information about safeguards relevant to your data.
We retain data only for as long as necessary for the stated purpose:
- Account and project data is retained while the account is active and is deleted or anonymized after a verified deletion request, subject to the exceptions below.
- Check, report, and AI measurement history is retained according to the applicable plan or while needed to provide history, enforce limits, and resolve service issues.
- OAuth credentials are retained while needed for the connection and removed when the integration is disconnected or the account is deleted. Google-specific handling, including retained Search Console history, is described above.
- Support, security, and diagnostic records are retained while reasonably needed to resolve the request, prevent abuse, maintain security, and establish or defend claims.
- Transaction and subscription records are retained for the period required by accounting, tax, payment, and dispute-resolution laws.
- Backups are removed on their normal secure rotation and are not restored for ordinary business use after a valid deletion request.
Your privacy rights
Subject to applicable law, you may ask us to:
- confirm whether we process your data and provide access to or a copy of it;
- correct inaccurate or incomplete data;
- erase data or stop, restrict, or block particular processing;
- provide data you supplied in a structured, commonly used, machine-readable format where portability applies;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent without affecting processing completed before withdrawal; and
- lodge a complaint with the State Audit Office of Georgia or another competent supervisory authority.
Email requests to support@2-ua.com. We may request information needed to verify your identity. We respond within the period required by applicable law: generally within 10 working days under Georgian data-protection law, subject to a permitted extension in special cases, or within one month where the GDPR applies.
You may also begin account deletion from Profile Settings. Deletion does not remove records we must retain by law, records needed to establish or defend claims, or data already anonymized so it no longer identifies you.
Security and children
We use reasonable technical and organizational safeguards designed to protect data against unauthorized access, alteration, loss, or disclosure. No internet transmission or storage system can be guaranteed completely secure. Please use a unique password and notify us if you suspect unauthorized account access.
2-UA is intended for business and professional use and is not directed to children under 18. If you believe a child submitted personal data, contact us so we can investigate and delete it where required.
Changes and contact
We may update this Policy when our services, providers, or legal obligations change. We will post the revised version here, update the effective date, and provide additional notice when a change materially affects your rights or our processing.
Questions, requests, and complaints may be sent to support@2-ua.com or to the postal address in Section 1.
Effective and last updated: 25 September 2026.