Engineer draft, not legal advice.
Privacy
Last updated
Who we are
Controller: [FILL: company, address, DPO]. Processor role for client project data: [FILL: DPA]. Public site: [FILL: public site URL].
This marketing site explains GEO / AEO measurement and classic SEO. It is not a storefront for cards. The SaaS cabinet sits at /app after you register with a Site URL and markets.
Account and session
We store account email, a hashed secret, and a session cookie. Email is also login, contact, and password-reset. No password in logs.
There is no separate username. The same address is used for sign-in, mail, and reset. Session cookies are HttpOnly, Secure in production, SameSite=Lax, in our Redis-protocol store — not a third-party auth SaaS.
Site URL and markets
When you register later, Site URL and chosen markets (country / admin1) become project data. Not collected on this marketing form.
Markets are countries and, for the United States and India, states. They are chosen on the map, not inferred from your network. We store country, not IP, in the product.
Locale cookie
A necessary locale cookie remembers the language you pick. After an explicit choice, GEO does not overwrite it.
Anonymous first visit may bind language to a country looked up in-container. The cabinet uses User.system_language. Registration preselects English; you may choose another of the ten planned locales.
Country, not IP
Anonymous first visit may bind language to a country looked up in-container (MMDB). We store country, not IP, in the product.
The lookup is a local database in our container. We do not send your address to a GeoIP SaaS. The same URL returns the same HTML — no cloaking, no user-agent fork.
Analytics
Product analytics cookies are set only after Accept. Events carry country, not IP. Default marketing pixels: none. Security logs are separate and short-TTL.
Reject is visible on the banner. Necessary cookies (session, locale, CSRF) stay. We do not use canvas, audio, WebGL, or font probes to identify you.
Security logs
Security logs may include IP and user-agent for a short TTL. See the retention table in LEGAL-GDPR.md — we do not invent days here.
What we do not do
No browser fingerprinting. No cloaking. No hidden analytics pixels. No UA-specific HTML.
We do not sell “guaranteed citation.” We do not put an LLM on a charge path. Payments are out of v1, so this page does not describe card storage.
Payments
Payments are out of v1. We do not run a Stripe Customer Portal or describe card storage.
Your rights
Export or delete: [FILL: privacy@] or later via /app. Graph backups: [FILL: erasure procedure].
Retention
TTLs live in the LEGAL-GDPR.md table (session, reset tokens, security logs, analytics). We do not invent day counts on this page.