Skip to content

Legal

Privacy

This document states plainly what the platform stores, who processes it, how long it is kept, and how to take it with you. It describes the implementation rather than an aspiration.

  • Last updated 10 September 2026
  • Processor list included
  • Export and deletion on request

We collect the minimum needed to measure AI search visibility: your account identity, the brand and competitor URLs you submit, the public pages we crawl, the AI answers collected for your tracked prompts, and the citations extracted from them. We do not sell data, and we do not use your brand data to train models.

01

What we store

Account
Your name, email address and authentication identifiers, held by the managed authentication provider. A role flag distinguishes client and administrator access.
Brand profile
Brand name, website URL, description, tracked competitor names, plan status, and whether the brand is active or deactivated.
Tracking prompts
The buyer-intent queries generated at onboarding or added by you, their intent stage, category and active status.
Collected answers
The raw response text collected for each prompt and AI surface per weekly cycle, the extraction result (stance, sentiment, position, citations, forensic explanation), and any correction you apply.
Derived metrics
Weekly snapshots containing the weighted visibility score, citation share and stance breakdown, plus the alert incidents generated from them.
Operational records
Action queue history including completion timestamps and locked baselines, audit results, and API tokens stored only as one-way hashes.
02

Data we crawl

Onboarding performs a bounded crawl of publicly accessible pages on your website and on the competitor sites you name: typically the homepage, a pricing page, a features or documentation page, and a llms.txt file if one exists. We store the extracted positioning and pricing signals used to ground prompt generation, not a copy of the page.

We do not crawl behind authentication, do not submit forms, and do not attempt to bypass bot protection. If a page is unreachable, the prompt grounding degrades gracefully rather than retrying aggressively.

If you do not want a competitor site crawled by us, do not add it as a tracked competitor. Competitor names can be tracked for comparison without crawling their pages where you tell us not to.

03

Processors we rely on

  • Managed Postgres hosting for storage of all application data.
  • A managed authentication provider for sign-in, session cookies and account records.
  • A large language model provider for prompt generation, structured extraction, discovery suggestions and asset drafting. Prompts sent for extraction contain the answer text and your brand and competitor names.
  • A transactional email provider for alert digests, when email notifications are enabled.
  • An optional chat webhook, only if you or your administrator configure one.
04

AI processing and what not to paste

Answer text and your tracked prompt set are sent to a third-party language model provider for structured extraction. That is how stance, sentiment, position and citations are derived. If you disable AI-assisted features, deterministic fallbacks are used instead.

Because collected answers may be reviewed by an operator during the weekly cycle, do not enter confidential information into a tracked prompt. A prompt should read like a real buyer question, and nothing more.

06

Cookies and local storage

Authentication uses a session cookie. By default the marketing pages set no analytics cookies and load no third-party scripts on first paint, and the walkthrough video loads only after you choose to play it.

If the operator configures a GA4 measurement ID, pages load Google Analytics after interactive paint with IP anonymization. AI-assistant referrals (ChatGPT, Perplexity, Claude, Gemini) are then visible in acquisition reports via their standard referrers — no extra tagging needed. The platform stores a small amount of interface state in your browser, such as drafts in the fulfilment console, so a refresh does not lose work in progress.

07

Retention

  • Brand data, prompts, collected answers and snapshots are retained while the brand is active so that week-over-week comparison remains possible.
  • Deactivating a brand stops all tracking immediately and removes it from every list, report and API response.
  • Account-level deletion requests remove your profile and any brands you own, including their prompts, answers, snapshots, alerts and action history.
  • Backups may retain deleted records for a short operational window before they age out.
08

Your rights and how to exercise them

You can export your data at any time from the dashboard: CSV or JSON for prompts, citations, sources and actions, plus a print-ready executive report. Export files contain brand identity and metrics only, never user identity, authentication records or access tokens.

For access, correction, deletion, restriction or portability requests, email hello@foryourreach.com. We answer within one business day and complete verified deletion requests within thirty days.

09

Security

  • All data is transmitted over TLS and stored in a managed Postgres instance with encryption at rest.
  • API tokens are hashed with SHA-256 before storage; the raw token is shown once at creation and cannot be recovered afterwards.
  • Brand data is isolated at the query layer, and every API tool is scoped to the brand that owns the token.
  • Access to production data is limited to the operator, and administrative surfaces require an explicitly granted role.
10

Changes to this document

Material changes will be reflected in the last-updated date above and, where the change affects how your data is handled, communicated to active accounts by email before it takes effect.

Note: this document accurately describes how the platform is implemented, but it is written by the engineering team rather than by counsel. It should be reviewed by a qualified lawyer in your jurisdiction before the site is used commercially.

Questions about this document? Email hello@foryourreach.com or see the contact routes. GEO operates at geo.foryourreach.com.