Last updated 2 August 2026.
| Data | Why |
|---|---|
| Your email address | To identify your account and sign you in. Handled by Supabase Auth. |
| Your API keys | To run tracking on your behalf. Encrypted with a key held only as a server environment variable, never stored alongside the data it protects. Only the last four characters are ever displayed again. |
| Brands, prompts and competitors you add | To know what to track. |
| Tracking results | The text of AI answers, the URLs they cited, and the scores derived from them. This is the product. |
| Run costs | The figures DataForSEO reports for each call, so you can see your own spend. |
We do not use analytics or advertising trackers, and there are no third-party cookies. The only cookie-equivalent is the session token that keeps you signed in.
Running a tracking job means sending your prompts to third parties. Specifically:
We do not sell data, and we do not share it with anyone beyond the processors above.
Data is stored in the United States. If you are in the UK or EU and that matters to your obligations, take it into account before adding client data.
Until you delete it. Deleting a brand removes its runs, answers and competitor records immediately and permanently: there is no recovery, which is why the app makes you type DELETE to confirm. Deleting your account removes everything associated with it.
API keys are encrypted at rest. Database access is restricted per user. Traffic is over HTTPS. That said, this is a free tool run by a small agency, not a bank, use judgement about what client data you put into it, and use a DataForSEO key you're willing to rotate.
This is a business tool and is not directed at anyone under 16.
If this policy changes materially, the date above changes and we'll say so in the app.