1. Who we are
VisibilityOS is operated by One Network Solutions Limited ("VisibilityOS", "we", "us", or "our"). We provide website auditing, search-performance analytics, AI visibility monitoring, competitive research, and related reporting tools.
Questions or privacy requests may be sent to hello@getvisibilityos.com.
2. Information we collect
- Account and workspace information: your name, email address, authentication records, workspace membership, and preferences.
- Website and project information: domains, URLs, crawl results, page content needed for analysis, configured competitors, keywords, reports, and project settings.
- Google Search Console data: only after you authorize access, we receive the verified properties available to your Google account and search-performance data such as dates, pages, queries, countries, devices, clicks, impressions, click-through rate, and average position.
- Google Analytics data: only after you authorize access and select a property, we read property and account names plus aggregated website metrics such as sessions, users, page views, engagement, acquisition channels, and landing pages.
- Bing Webmaster Tools data: only after you authorize read-only access and select a verified site, we receive Bing search clicks, impressions, top queries and pages, crawl statistics and issues, index counts, and sitemap status.
- Microsoft Clarity data: only after you provide a Data Export API token, we receive aggregate behavior analytics such as sessions, users, engagement, scroll depth, popular URLs, acquisition dimensions, and frustration-event counts. VisibilityOS does not import Clarity recording playback or heatmap images.
- Advertising account data: only after you separately authorize Google Ads or Meta Ads and select an account, we receive account metadata and aggregate reporting such as spend, impressions, reach, clicks, attributed actions and value, campaign performance, platforms, devices, networks, search terms where available, and geographic performance. VisibilityOS does not create or modify campaigns.
- Usage and device information: IP address, browser and device attributes, request logs, timestamps, error reports, and security events.
- Billing information: subscription and transaction status from our payment provider. VisibilityOS does not store complete payment-card numbers.
- Communications: messages, support requests, and feedback you send to us.
3. How we use information
We use information to:
- provide, secure, maintain, and improve VisibilityOS;
- crawl authorized websites and produce audits, analytics, alerts, and reports;
- authenticate users, administer workspaces, and prevent abuse;
- process subscriptions and provide customer support;
- send service-related notices and communications you request; and
- comply with applicable law and enforce our Terms of Service.
4. Google API data
VisibilityOS requests the Google Search Console read-only scope (webmasters.readonly), Google Analytics read-only scope (analytics.readonly), and—when you separately connect Google Ads—the Google Ads scope (adwords). Search Console and Analytics permissions cannot modify those properties. VisibilityOS uses the Ads permission only for reporting and does not provide campaign-creation or campaign-editing controls.
We use Google data only to provide the Traffic Analytics, website-engagement, search-opportunity, and paid-search intelligence features you request. Google Ads snapshots may include account identifiers, campaign performance, search terms, devices, networks, and geographic performance. We do not sell Google user data, use it to place advertising, transfer it to data brokers, or use it to train generalized advertising or AI models. Access and refresh tokens are encrypted at rest and are never exposed to other VisibilityOS customers.
Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
5. Bing Webmaster Tools data
VisibilityOS requests the Bing Webmaster Tools read-only scope (webmaster.read). It cannot submit URLs, edit site settings, or otherwise manage your Bing property. OAuth access and refresh tokens are encrypted at rest and are deleted from VisibilityOS when you disconnect the integration.
We use Bing data only to provide the connected search-performance, crawl-health, index-coverage, and sitemap features you request. We do not sell this data or use it for advertising.
6. Microsoft Clarity data
When you connect Microsoft Clarity, the project Data Export token is encrypted at rest and used only to request aggregate analytics for your project. VisibilityOS stores the resulting aggregate snapshots, not session-recording content, DOM playback, keystrokes, or heatmap images. The token and cached snapshots are deleted when you disconnect Clarity or delete the VisibilityOS project.
You are responsible for configuring Clarity consent, masking, and disclosures on the monitored website and for following Microsoft's eligibility and privacy requirements. Do not use Clarity on websites or applications directed to people under 18.
7. Meta Ads data
VisibilityOS requests Meta's ads_read permission only. It is used to list ad accounts available to the authorizing user and import aggregate reporting for the account you select. VisibilityOS does not request ads_management and cannot create, edit, publish, or delete Meta campaigns.
Meta access tokens are encrypted at rest and are never returned to the browser after authorization. Cached reporting and the token are deleted when you disconnect Meta Ads or delete the project. Meta Ads data is not sold, used to place advertising, transferred to data brokers, or used to train generalized advertising or AI models.
8. Sharing and service providers
We do not sell personal information. We may share limited information with:
- hosting, infrastructure, email, analytics, security, and customer-support providers acting on our instructions;
- payment processors for subscriptions and fraud prevention;
- AI or search-data providers when you enable a feature that requires them, subject to the feature's disclosed settings;
- professional advisers and authorities where reasonably necessary to comply with law, protect rights, or investigate abuse; and
- a successor in a merger, acquisition, financing, or sale, subject to appropriate confidentiality protections.
9. Retention and deletion
We retain account and project information while your account or workspace remains active and as reasonably necessary for the purposes described here. Retention periods may also reflect security, backup, billing, dispute-resolution, and legal requirements.
When you disconnect Google in VisibilityOS, we delete the stored OAuth connection and the Search Console performance data cached for that project. Google Analytics reports are read live and are not retained as a historical event-level dataset. You may also revoke VisibilityOS directly from your Google Account permissions. Account or data-deletion requests may be sent to hello@getvisibilityos.com.
Disconnecting Bing or Microsoft Clarity deletes the corresponding encrypted provider credentials and cached project snapshots from the active VisibilityOS database. Provider-side data remains subject to the provider's own retention controls.
10. Security
We use technical and organizational safeguards designed to protect information, including encryption in transit, encrypted OAuth credentials at rest, access controls, audit logging, least-privilege permissions, and monitored infrastructure. No system can guarantee absolute security, so we encourage strong, unique passwords and prompt reporting of suspected misuse.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export personal information, or to object to certain processing. You may manage project integrations in VisibilityOS, revoke connected-provider access at any time, and opt out of non-essential communications using the instructions provided in them.
12. International processing
VisibilityOS and its providers may process information in countries other than your own. Where required, we use appropriate safeguards for international transfers and apply this policy to the information wherever it is processed.
13. Children
VisibilityOS is a business service and is not directed to children under 16. We do not knowingly collect personal information from children through the service.
14. Changes to this policy
We may update this policy as the service or legal requirements change. We will post the revised version here, update the date above, and provide additional notice when a change materially affects your rights.