Legal
Privacy Policy
Last updated July 18, 2026
This policy explains what data Recometrix collects, why, and the choices you have. We aim to collect only what the Service needs to work.
Data we collect
Account data: your email address, name, role, and company details you provide at signup and setup. We also record technical data needed to run and secure the Service, such as your IP address and browser type.
Project data: the brand, website, category, competitors, and prompts you configure, and the audit results derived from them, including the full answers the AI providers return, which we store so your reports stay stable over time. To build your inventory and readiness checks, we also fetch and store pages from the website you give us, using a crawler that respects your robots rules.
Connected-service data: when you choose to connect Google Search Console or Bing Webmaster Tools, we read the verified site, search queries, landing pages, clicks, impressions, and average positions available to your account. When you connect Plausible or DataFast, we read traffic, page, source, goal, and conversion metrics available to the site-scoped API key you provide. When you connect PostHog, we read aggregate page traffic, referring domains, and custom-event counts for the project you select. We also store the connection identifier and the credentials needed to keep the connection working. OAuth tokens and API keys are encrypted at rest.
Billing data: handled by Stripe. We store your plan, subscription status, and a Stripe customer identifier. We never see or store full card numbers.
Product analytics: we use PostHog to understand how the product is used. It is tied to your account, so we can see which features you use, and we send your user id, email, and plan to it. We do not use it for advertising.
How we use it
To provide and operate the Service (run audits, produce reports, send alerts), to process payments, to communicate with you about your account, and to improve reliability and features. We do not sell your personal data.
Connected-service data is used only to provide and improve the features you request: comparing search and traffic performance with AI visibility, generating recommendations, and showing connection health. We do not use it for advertising. Limited connected-service metrics may be sent with your project context to our AI provider, Anthropic, so the strategist can generate your recommendations; under its business terms, that data is not used to train general-purpose models.
Recometrix’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Processors and sub-processors
We share data with vendors that process it on our behalf under contract:
- Neon: application database hosting
- Cloudflare: application hosting, storage, and delivery
- Stripe: subscription billing and payments
- Resend: transactional email (sign-in links, reports)
- PostHog: product analytics, hosted in the EU
- Sentry: error monitoring, hosted in the EU. When something breaks we record the technical details of the error, not your content.
- AI providers (OpenAI, Anthropic, Google, Perplexity, xAI, and similar): to run your buyer-intent prompts and generate content. Your prompts and brand context are sent to these providers to produce results. Under their business terms, none of these providers use what we send through their APIs to train their models.
Public share pages
You can choose to publish a public share page for a project. It is off by default, lives at an unguessable link, and shows the brand’s domain and visibility scores; anyone with the link can read it. Turning it off removes the page, though copies indexed or cached elsewhere may persist for a while.
Retention
We keep your data for as long as your account is active. When you delete your account, we delete or anonymize associated personal data within a reasonable period, except where we must retain records to comply with legal or accounting obligations.
You can disconnect a connected service at any time in Settings. Disconnecting deletes its stored OAuth tokens or API key and stops future collection. Reports and recommendations already generated may retain the metrics or conclusions incorporated into them until the associated project or account is deleted. You can also revoke Google, Bing, or PostHog access in the connected provider, and you can revoke a Plausible or DataFast key from that provider’s settings.
Your rights
Depending on where you live (including under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email us and we will respond within the timeframe the law requires.
Security
We use industry-standard measures including encryption in transit, hashed API keys, and scoped access to secrets. There are no passwords to protect: you sign in with a one-time email link or your Google account. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you of material breaches as required by law.
Cookies
We use a small number of essential cookies to keep you signed in, and privacy-respecting analytics to understand product usage. We do not use third-party advertising cookies.
Contact
Questions or requests about your data: email us.
See also our Terms of Service.