Privacy Policy
Our privacy policy and how we use your data
This is an interim privacy notice. It states truthfully what this product collects, what leaves your browser, and who else handles it, written from the system as it is actually configured. It is deliberately incomplete: what has not been confirmed is listed at the end as outstanding, rather than filled in with a plausible-sounding answer.
What we collect
Four kinds of information, and nothing else:
- What you give us when you sign up — your email address, your name if you provide one, and the workspace or team you belong to.
- What you set up inside the product — the domains, brands and competitors you ask us to watch, and the topics and settings for each project.
- What the product measures for you — the answers AI assistants give for the topics you monitor, and the scores, trends and reports derived from them.
- What your browser sends with every request — such as your IP address and browser user agent, recorded in our web server's access logs.
Session analytics
Microsoft Clarity records how pages are used, including the address of the page you are on as your browser shows it. It loads only if you allow analytics, and only on the public pages of this site — the home page, pricing, FAQ, contact, the blog and the policy pages. A public page opened at an address carrying a sign-in code, an invitation token, an email address or any other credential-like or identifying parameter does not start a recording either, for as long as it is open. It is never loaded inside your workspace, whose address contains your account name, nor on a sign-in, invitation, password or first-setup page, a shared report link, a print or PDF view, an administrative page or the content editor. Because a session recorder reads the address from your browser rather than from us, the rule about it is which pages it may load on at all, and not what we send it; moving from the public site into the product is a full page load, so the recording ends with the page. The page you came from is bounded the same way: every address outside those public pages is served so that your browser passes on this site's name alone and never the address itself. Page text is masked in Clarity's own settings for this project, so the content displayed to you is not collected; that is a setting in Microsoft's console rather than something in this site's code. Clarity is Microsoft's service, and what Microsoft does with a recording is governed by Microsoft's own privacy statement.
Google Tag Manager loads on the same permission and measures more of the site than Clarity does, including pages inside your workspace. What it receives from us is described below: reduced page addresses, and nothing that names you. Google Analytics 4 is set up through it in Google's own console and has not been switched on yet. The cookie policy describes both in more detail.
What never reaches an analytics tool
The analytics events this site sends are assembled from a fixed list of fields, checked in code and in tests. None of the following can appear in one: your email address, your name, your account, brand or competitor names, the domains you monitor, the topics or prompts you track, anything you type into a search box, the text of an AI answer, invitation links, shared report links, or sign-in codes.
Page addresses are reduced to a generic route template before they are sent, so /home/acme-industries/aeo/reports is sent as /home/[account]/aeo/reports, and an address the code does not recognise is redacted rather than guessed at. Pages whose address is itself a key — a shared report link — along with print and PDF views and every administrative page are excluded from those events entirely.
Microsoft Clarity does not take the page address from us: like any session recorder it reads the address bar itself — the page you are on, and the page you came from — so the reduction described above cannot be applied to either. That is why it is not allowed to load at all outside the public pages of this site — never inside your workspace, never on a sign-in, invitation, password or first-setup page, and never on a shared report link, a print or PDF view, an administrative page or the content editor. Google Tag Manager is not limited the same way, because what it is given is the reduced address rather than the one in your browser.
The consequence, stated rather than glossed over: session recording covers the public site only, and never the product you are paying for. Page-view measurement does cover the product, and what it reports about it is the reduced kind — a route template such as /home/[account]/aeo/reports, with your account name removed — never the address as your browser shows it.
Who else handles this data
Each of these does one job and does not go beyond it:
- Supabase — the database, sign-in and file storage this product runs on.
- Microsoft — session analytics through Clarity, as described above.
- Google — Tag Manager, loaded only with your permission; Analytics is set up through it and has not been switched on yet.
- Cloudflare — protection against automated abuse on public forms.
- Moyasar — payment processing if you buy a subscription. Card details are entered on Moyasar's own pages and never reach ours.
- The complete list, including any processor used behind one of these, is still being compiled and is named below as outstanding.
Your choices
You can accept or reject analytics and marketing at any time, as described in the cookie policy, and a refusal is what we assume until you say otherwise. You can also ask us what information is held about you, or ask for your account and its data to be deleted.
The formal process for those requests, and the authority you may complain to, are named below as outstanding.
When this notice changes
We update this notice when what we collect, or who handles it, changes. What you are reading describes the system as it is configured now, not as it is planned to be.
Pending owner and legal review
The following are missing deliberately rather than by oversight. Publishing an invented retention period or an invented legal basis would be worse than publishing nothing, so each one is named here until it has been confirmed.
- TODO (owner and legal review): the legal entity that controls this data, its registered address, and a contact address for privacy questions.
- TODO (owner and legal review): the lawful basis for each of the purposes described above.
- TODO (owner and legal review): how long we keep account data, product data and access logs, and how long each vendor keeps what it holds.
- TODO (owner and legal review): where data is processed and stored, and the safeguards covering any international transfer.
- TODO (owner and legal review): how to exercise access, correction, deletion and objection rights, and which supervisory authority applies.
- TODO (owner and legal review): the complete processor and sub-processor list, and whether a data protection officer is appointed.

