Privacy Policy

Last updated: July 2026 · Public Beta

1. Data we collect

Account data (name, email, organization), brand configuration you provide (website, competitors, keywords), metrics pulled from data sources you explicitly connect (Google Analytics, Search Console, social platforms, CRMs), and AI answer snapshots produced by scans you trigger.

2. How we use it

Solely to operate the product: computing visibility, citation, authority, traffic and revenue metrics for your brands. We never sell data, never train models on your private data, and never share it across organizations.

3. Tenant isolation

Every record is scoped to your organization and enforced with database Row Level Security. Members of one organization can never query another organization's data.

4. Tokens & credentials

OAuth refresh tokens are encrypted at rest with AES-256-GCM. Provider API keys are stored only in server environment variables and are never sent to the browser or written to logs.

5. Data deletion

Deleting a brand or organization cascades through all stored metrics, prompt runs, citations and usage events. Contact us to request full account erasure.

6. Contact

Questions about this policy: jimmy@indexvisibility.com.