Privacy Policy
Last updated: July 2026 · Public Beta
1. Data we collect
Account data (name, email, organization), brand configuration you provide (website, competitors, keywords), metrics pulled from data sources you explicitly connect (Google Analytics, Search Console, social platforms, CRMs), and AI answer snapshots produced by scans you trigger.
2. How we use it
Solely to operate the product: computing visibility, citation, authority, traffic and revenue metrics for your brands. We never sell data, never train models on your private data, and never share it across organizations.
3. Tenant isolation
Every record is scoped to your organization and enforced with database Row Level Security. Members of one organization can never query another organization's data.
4. Tokens & credentials
OAuth refresh tokens are encrypted at rest with AES-256-GCM. Provider API keys are stored only in server environment variables and are never sent to the browser or written to logs.
5. Data deletion
Deleting a brand or organization cascades through all stored metrics, prompt runs, citations and usage events. Contact us to request full account erasure.
6. Contact
Questions about this policy: jimmy@indexvisibility.com.