Privacy

We measure engines, not people.

This page says what we collect and why, in plain language. Last updated September 2026.

What we collect

Your email address and first name when you request a free visibility report or create a workspace.

The brand domain and competitor names you ask us to measure, the prompts you track, and the answers AI engines return for them.

Operational records of what the product did for you: measurement runs, drafted fixes, approvals and outcome receipts.

If you connect your own request logs, the AI traffic feature receives four fields per request your site served: the path, the user agent, the referrer and the client IP. The IP is used in memory to check a crawler against its vendor's published ranges and is not stored. What lands in the table is the classified bot, what the visit was for, the verification verdict, the path and which collector sent it. Query strings, cookies, bodies and other headers are not collected.

Why we collect it

Email is how we deliver your report, your daily digest and account messages. Nothing else.

Brand and prompt data is the product: we measure how AI engines answer, diagnose why you are absent, and prove whether fixes moved the needle.

What we never do

We do not sell your data or share it with advertisers.

We do not train models on your workspace data.

We do not post anywhere on your behalf on our own initiative. Publishing runs on a request from your workspace, and every push writes a receipt you can read.

Who processes data for us

Measurement reaches the engines two ways, and both carry only the prompt text, never your account details. Some engines answer through their own API (OpenAI, Anthropic, Google and xAI), and the consumer surfaces are read by scrape through DataForSEO and SearchAPI, with OpenRouter routing Perplexity. So DataForSEO and SearchAPI see every prompt measured on a scraped surface, and OpenRouter sees every Perplexity prompt.

Email delivery runs on Resend, billing on Polar, hosting and the database on Railway and Vercel, and jobs on Inngest. The nightly database backup is held by GitHub and by Cloudflare R2. The full list, every vendor with what it is for and every account you can connect yourself, is on the security page at /security.

Your controls

Every digest email carries an unsubscribe path, and you can ask us to delete your workspace and its data at any time by replying to any email we send you. Deletion removes your brands, prompts, answers and receipts.

One kind of record survives that deletion on purpose: a platform wide suppression, the note that somebody asked to stop being contacted at all. It holds a hash of their address and nothing else, and removing it would quietly restore our ability to mail a person who opted out. Your workspace's own suppression list goes with the workspace.