Privacy Policy
Last updated: [date]. This policy is a draft template for owner and legal review.
1. What we process
We process the minimum needed to run the service: your account information (name, email address, password hash), the websites you add, the crawl and audit results we produce from public pages of those sites, monitoring and reporting data, and billing records. Email addresses in delivery logs are stored only as hashes.
2. How we use it
We use the data to provide the service you asked for: crawling and auditing your sites, generating fixes, verifying changes, monitoring AI visibility, and producing reports. We do not sell personal information, and we do not use your personal data to build advertising profiles.
When you connect Google Business Profile, we read performance metrics (ratings, review counts, direction requests, calls, profile views, impressions) to show them in your dashboard. We never write to your Business Profile — no review replies, no post creation, no location edits.
3. Tracking and cookies
We do not run analytics or advertising scripts that track you. The portal sets only strictly-necessary cookies (your login session). Because we place no marketing or analytics cookies, no consent banner is required for cookie use.
4. Sharing with processors
We share data only with the sub-processors needed to deliver the service, bound by data-processing agreements consistent with our DPA. The list reconciles with docs/legal/subprocessors.md:
- Paddle — merchant of record and payment processor (name, email, billing data).
- Railway — hosting and compute (all customer data, us-west-2).
- Anthropic, OpenAI, Google, Perplexity, SERP vendor — AI visibility sampling and analysis; prompt text only, no PII.
- Google (Search Console, PageSpeed, Knowledge Graph, Business Profile) — search-performance, page-speed, and local-business data you connect.
- Postmark — transactional email delivery (recipient email address).
- Cloudflare — DNS and CDN for the public site.
- Backup object store — encrypted backups of the database.
Sub-processors may be added or changed only with prior notice to customers; you may object by contacting us or terminating your account within the notice period.
5. Retention
We keep data only as long as needed, and in any case no longer than the periods configured in backend/src/config/retention.ts. In summary:
- Email delivery logs: 30 days.
- Raw AI-monitoring samples and citations: 90 days.
- Search-analytics, referral and crawler-visit aggregates: 180 days.
- URL-inspection snapshots: 180 days.
- Alert events and freshness findings: 365 days.
- Erasure grace period before a deletion request executes: 7 days; erased-account tombstones are kept 30 days; export artifacts expire after 7 days.
Financial and audit records are retained longer where legally required and are never deleted by the retention sweep.
6. Your rights
You may request access to, correction of, or deletion of your personal data, and may object to or restrict certain processing. Where applicable law gives you these rights, you can exercise them from your account or by contacting us at [email protected]. We will respond within the time required by law.
7. International transfers
Data may be processed outside your country, including in the United States and the EU. Transfers are made using appropriate safeguards (standard contractual clauses or an adequacy determination).