Privacy policy
What we store, why we store it, and how to have it removed.
Last updated 12 September 2026
What we collect
- Account — your email address and a hashed password. We never store the password itself.
- Projects — the domains you track, plus the brand name, category, language and competitors you enter.
- Scan results — the questions asked, the answers returned, which brands were named, and the fixes we generate.
- Usage events — for example that a scan was started or a checkout was opened, with a coarse session identifier. We use these to understand where the product loses people.
- Billing state — a mirror of your Paddle customer and subscription identifiers, so we know which plan to grant. We never see or store your card details.
- A free-scan lead — if you ask for a report without creating an account, we keep the address you gave us so we can send it.
Why we hold it
To run the service you asked for (scanning, monitoring, reports), to bill you correctly, to keep the service secure and working, and to meet accounting obligations. We do not sell your data, and we do not use your projects to train models.
Who else is involved
- Paddle — merchant of record. They take the payment, handle tax, and hold your billing details under their own privacy policy.
- AI model providers — the questions in a scan are sent to the engines being measured, so that they can answer them. The domain and brand being researched are part of those questions by nature.
- Hosting and infrastructure — the servers and database the service runs on.
How long we keep it
Account data, projects and reports stay while your account is open, so that history and trends keep working. Deleted projects take their scans with them. Billing records are kept as long as tax and accounting rules require, even after you close your account. A free-scan lead is kept until you ask us to remove it.
Your choices
You can ask us for a copy of your data, correct it, or delete your account and everything attached to it. Write to us and we will action it; we may ask you to prove you control the account first. If you are in a region that gives you specific rights over your data, those rights apply — ask, and we will honour them.
We set one cookie: a signed session cookie that keeps you signed in. It is not used for advertising or tracking across other sites. Analytics is first-party and stores events in our own database rather than sending them to a third-party tracking network.
Contact
Contact details are unset. See the contact page for the current status.
This page is not finished
The values below are unset, so this page cannot serve as a binding agreement yet. They are not defaulted on purpose — a placeholder would ship without anyone noticing.
- · LEGAL_ENTITY=
- · SUPPORT_EMAIL=
- · GOVERNING_LAW=
Set them in .env.local (see .env.example). See the go-live checklist in docs/02-上线手册.md.