Privacy Policy
Last updated: September 15, 2026
nqzai is operated by Immortal Reality PA LLC, 6375 Penn Ave Ste B, Pittsburgh, Pennsylvania 15206, USA ("nqzai", "we", "us"). It is an AI marketing assistant for outbound email, SEO and AI-search visibility. This page is our privacy notice: it says what we collect, why, who processes it, how long we keep it and what you can ask of us. It is not a contract; your agreement with us is the Terms of Service. Where the law makes consent the basis for a particular use, we ask for it in the product at the point it applies.
1. Who is responsible for what
- Your account, usage, billing and product analytics — nqzai decides how this is processed. Under the GDPR and UK GDPR we are the controller; under India's DPDP Act we are the Data Fiduciary.
- Contacts and leads you upload, import, or ask nqzai to find or enrich for you — you decide who to reach and why. For that data you are the controller (or business) and we process it on your instructions as your processor (or service provider). If your details are in a customer's nqzai account, the customer is the party to ask first; we help them answer within 30 days.
- Our lead corpus — business contact records we assemble from public and licensed sources to power lead search. We are the controller of that corpus. Section 9 says how a person can have their record removed.
2. Information we collect
- Account data — email address, name if you give one, and authentication credentials (held by our auth provider; we never see your password).
- Product & campaign data — your website URL, product brief, personas, brand kit, email signature, sending settings, standing instructions and campaign configuration.
- Contacts — names, email addresses, companies, titles, verification status and enrichment data for the people you research, import or save.
- Chat and tool activity — your messages to the assistant, its replies, the tools it ran and their results, and the token and API consumption used to meter your balance.
- Email activity — messages sent through your connected provider, and replies, bounces and unsubscribe requests that reach the tracking addresses on those messages.
- Connected-service data — when you connect a third-party account (Google, Shopify, Notion, WordPress, Slack or an email provider), the data described at connection time and in Section 4.
- Payment data — handled by Stripe. We receive the amount, a payment identifier, the last digits of the card and its outcome; we never receive full card numbers.
- Technical data — IP address, browser and device information, request logs and error reports, used for security, rate limiting and debugging.
- Product analytics — with your in-app consent, product-usage events go to Mixpanel so we can see which features are used and where they fail.
- Public website measurement — our marketing pages (not the signed-in app) load Google Analytics and Tag Manager, Datafast, shown.io and an OpenAI advertising measurement pixel. You can limit these with your browser's tracking controls.
- Feedback and support — votes and comments you leave on replies, bug reports (including a screenshot when you attach one), and emails you send us.
3. How we use it, and on what basis
- To run the service — find and verify leads, draft and send email, run sequences, produce SEO and AI-visibility research, and show you the results. Basis: performance of our contract with you.
- To meter and bill — deduct tokens, process payments, refunds and disputes, and keep the records tax law requires. Basis: contract and legal obligation.
- To keep the service safe — rate limiting, abuse and fraud detection, outbound-content screening, security logging and incident response. Basis: our legitimate interest in a service that works and is not abused.
- To improve the product — measure which features are used, judge the quality of the assistant's replies, fix errors, and develop new features. Automated quality scoring of replies is part of this. Basis: legitimate interest; consent for Mixpanel analytics.
- To communicate with you — transactional email about your account, balance, sends and connections, and product updates you can opt out of. Basis: contract and legitimate interest; consent where the law requires it for marketing.
We do not sell personal data, do not use your contacts or connected-account data for advertising, and do not train machine-learning models on your content. Requests to model providers are processed under those providers' API terms.
4. Google user data (Search Console & Analytics)
If you connect Google, you grant nqzai read-only access to your Google Search Console and Google Analytics (GA4) data via OAuth, using these scopes:
webmasters.readonly— read search performance (clicks, impressions, positions, queries).analytics.readonly— read traffic metrics (sessions, users, channels, conversions).
We use this data solely to display your search and traffic performance back to you inside nqzai and to enrich your SEO audits. We store only an encrypted OAuth refresh token (AES-GCM at rest); access tokens are short-lived and never persisted. Some Google connections are brokered through Composio, a connector platform that holds the OAuth grant on our behalf under the same scopes. You can revoke access anytime from the Connectors panel or at myaccount.google.com/permissions.
4a. Google Ads API (roadmap and connected-account handling)
nqzai's current keyword research and SEO recommendations are powered primarily by DataForSEO and related SEO data providers, not by your Google Ads account. Google Ads account workflows for campaign measurement and management are planned roadmap capabilities.
- If you connect a Google Ads account now or in the future, nqzai operates only on the account you authorize via OAuth and never on a third party's account without that owner's grant.
- Any future Google Ads campaign creation or management flows will be performed only at your direction.
- Today, keyword planning metrics shown inside nqzai come from SEO data vendors rather than Google Ads account data.
5. Service providers (sub-processor schedule)
We share data only with providers that help us run the service, each under its own terms and only for the purpose listed. This is the current schedule; we may add or replace providers, and a material change is reflected by the date at the top of this page.
- Hosting, storage, DNS and inbound email routing — Cloudflare (global edge; United States and EU).
- Database and authentication — Nhost / Hasura (Frankfurt, EU).
- Lead corpus database — Neon (United States).
- Payments — Stripe.
- Language-model inference — OpenRouter, and through it the model providers it routes to (including OpenAI, Anthropic, Google, xAI and Mistral), plus direct calls to OpenAI and Google where a feature needs them. Prompts include the relevant parts of your product brief, contacts and chat.
- Lead discovery, enrichment and verification — Apify, Apollo, api.market, Exa, MillionVerifier.
- SEO, SERP, backlink and AI-visibility data — DataForSEO, ValueSERP, Serper, Ahrefs, Common Crawl, and public Google APIs (Knowledge Graph, Safe Browsing, Chrome UX Report, PageSpeed).
- Connector brokering — Composio, for some Google connections (Section 4).
- Email delivery — your own connected provider (Gmail, Resend, SendGrid, Mailjet, Mailtrap or SMTP) for campaign mail; Mailtrap for our own transactional mail.
- Integrations you connect — Google, Shopify, Notion, WordPress, Slack, only when you connect them and only within the grant you give.
- Product analytics and error monitoring — Mixpanel (EU) with your consent; Sentry (EU).
- Public-site measurement — Google Analytics / Tag Manager, Datafast, shown.io, OpenAI advertising pixel (marketing pages only).
- Engineering and quality tooling — GitHub and Testomat receive error context and test results, never your contacts.
6. Email sending and inbound mail
Campaign email leaves through the provider you connect; we hold that provider's credentials encrypted and use them only to send what you approved. Every campaign message carries an unsubscribe link and one-click unsubscribe headers pointing at us, and a reply address on our domain so replies, bounces and unsubscribe requests reach your account. We process those inbound messages to update the contact's status and show you the reply. You are responsible for the content and recipients of what you send; the Terms say how that responsibility is shared.
7. International transfers
We are a United States company. Your data is stored in the EU (database, authentication, error monitoring, product analytics) and processed in the United States and elsewhere by the providers in Section 5, including model providers. By using the service you instruct these transfers. For customers established in the EU, UK or Switzerland we rely on our providers' adequacy status, Data Privacy Framework certification or standard contractual clauses, and we will sign a data processing agreement with standard contractual clauses on request from a paid business account.
8. How long we keep it
- Account and product data — for the life of the account, then erased as described in Section 9; copies persist in encrypted backups for up to 30 days.
- Contacts, campaigns, sent email and drafts — until you delete them or delete the account; contact records you have not deleted when the account closes are kept under the same protections until you ask us to delete them.
- Chat history — the live conversation store expires 24 hours after the last message; a record of each turn and the tools it ran is kept with the account for quality review and your own history.
- Token ledger, payments, refunds and disputes — 7 years, as tax and payment rules require.
- Security and request logs, error reports — up to 90 days.
- Product analytics — per Mixpanel's retention; you can withdraw consent in the app.
- Backups — rolling 30 days, then overwritten.
- Records we must keep — as long as the applicable law requires, and no longer.
9. Deleting your account, and what remains
Self-serve: Profile → Danger zone. Your name, signature, brief, personas, instructions and brand kit are erased, every connected account is disconnected and its credentials destroyed, the login is disabled and the account is locked; the confirmation email is your record. What remains: the token ledger and payment records for the period in Section 8, backups until they roll off, contact and campaign records you did not delete first (email us and we delete them), and statistics that no longer identify anyone. Providers in Section 5 delete on their own schedules; model providers hold request data only as their API terms allow.
If you are in our lead corpus and want your record removed, email info@immortalai.us with the address concerned; we suppress it from every future search and remove it from the corpus within 30 days.
10. Security
Connector secrets, provider keys and OAuth tokens are encrypted at rest with AES-GCM. Every database read on behalf of a signed-in user is scoped to that user's own rows by the database itself. Data moves over TLS. Staff access to account data is limited to support you ask for, security and abuse review, and what the law requires. Backups run nightly and our restore procedure is exercised. No method of storage or transmission is perfectly secure; if a breach affects your data we notify you without undue delay, and within any time the law sets.
11. Your rights
Two rights are self-serve:
- Export — while signed in,
GET /api/user/account/exportreturns everything the product holds about your account as one JSON file: contacts, campaigns, sent email, templates, keywords, connections (without secrets), your token ledger and your feedback. Twice a day. - Delete — Profile → Danger zone, as described in Section 9.
For everything else — correction, restriction, objection, the internal records the export does not include, or a request on behalf of someone whose details a customer holds — email info@immortalai.us. We answer within 30 days and may ask you to verify the account. Depending on where you are:
- EU, UK, Switzerland — you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is the basis. You may complain to your supervisory authority.
- India (DPDP Act) — you may access, correct and erase your data, nominate someone to exercise these rights, and raise a grievance with our Grievance Officer at info@immortalai.us.
- United States — where a state privacy law applies, you may access, correct and delete your data and opt out of targeted advertising. We do not sell personal data. The advertising-measurement pixel on our marketing pages can be limited with your browser's controls.
12. Children
nqzai is for business use by adults. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.
13. Changes
We may update this notice. The date at the top changes when we do; for a material change we also tell you by email or in the app before it takes effect.
Contact
Questions about this policy or your data? Email palash@nqz.ai.