AI Visibility Tracker
Sign In Create Account

Privacy Policy

Last updated 2 August 2026.

What we store

DataWhy
Your email address To identify your account and sign you in. Handled by Supabase Auth.
Your API keys To run tracking on your behalf. Encrypted with a key held only as a server environment variable, never stored alongside the data it protects. Only the last four characters are ever displayed again.
Brands, prompts and competitors you add To know what to track.
Tracking results The text of AI answers, the URLs they cited, and the scores derived from them. This is the product.
Run costs The figures DataForSEO reports for each call, so you can see your own spend.

We do not use analytics or advertising trackers, and there are no third-party cookies. The only cookie-equivalent is the session token that keeps you signed in.

Who else sees it

Running a tracking job means sending your prompts to third parties. Specifically:

We do not sell data, and we do not share it with anyone beyond the processors above.

Where it lives

Data is stored in the United States. If you are in the UK or EU and that matters to your obligations, take it into account before adding client data.

How long we keep it

Until you delete it. Deleting a brand removes its runs, answers and competitor records immediately and permanently: there is no recovery, which is why the app makes you type DELETE to confirm. Deleting your account removes everything associated with it.

Your control

Security, stated plainly

API keys are encrypted at rest. Database access is restricted per user. Traffic is over HTTPS. That said, this is a free tool run by a small agency, not a bank, use judgement about what client data you put into it, and use a DataForSEO key you're willing to rotate.

Children

This is a business tool and is not directed at anyone under 16.

Changes

If this policy changes materially, the date above changes and we'll say so in the app.

This policy describes what the software actually does, written by the people who built it. It is not legal advice and has not been reviewed by a lawyer. If you're operating under GDPR, CCPA or a client contract with its own data terms, have someone qualified check it against your obligations.