Privacy Policy
Last updated: April 2026
Information We Collect
We collect the following information: (1) Account information: your email address when you create an account. (2) Website data: URLs you submit for GEO scanning and the analysis results generated from them. (3) Usage data: how you interact with the platform, including features used, scan frequency, and session duration. We do not collect passwords. Authentication is handled via secure magic links sent to your email.
How We Use Your Information
We use your information to provide and operate our scanning, asset generation, and submission tracking services; send transactional emails (magic links, scan reports, subscription confirmations) via Resend; process payments via Polar.sh; generate AI-powered assets using the Anthropic API; improve and debug our platform; and communicate with you about service updates. We do not use your data for advertising and we do not sell it to third parties.
Data Storage and Security
Your data is stored in Supabase (PostgreSQL), hosted on cloud infrastructure with row-level security (RLS) policies that ensure you can only access your own records. Data is encrypted in transit via TLS/HTTPS and at rest. Scan results and generated assets are retained for the lifetime of your account. You can request deletion at any time via your account settings or by emailing [email protected].
Information Sharing
We do not sell, rent, or trade your personal information. We share your data only with the service providers required to operate GEO Autopilot: Supabase (database and authentication), Polar.sh (payment processing), Resend (transactional email), Anthropic (AI asset generation), and Google (Google Tag Manager and Google Analytics 4 for aggregate usage analytics). Each provider processes your data under their own privacy policies and data processing agreements.
Third-Party Services
GEO Autopilot integrates with the following third-party services, each governed by their own privacy policies: Supabase for database storage and authentication (supabase.com/privacy); Polar.sh for subscription billing and payment processing (polar.sh/privacy); Resend for transactional email delivery (resend.com/privacy); Anthropic for AI-powered asset generation (anthropic.com/privacy); Google Tag Manager and Google Analytics 4 for aggregate website usage analytics (policies.google.com/privacy). We encourage you to review their policies to understand how your data is handled downstream.
Cookies and Sessions
We use two categories of cookies. (1) Strictly necessary: session cookies and HTTP-only cookies that maintain your authenticated session after signing in via magic link. Clearing these will sign you out. (2) Analytics: we load Google Tag Manager, which deploys Google Analytics 4. GA4 sets the _ga and _ga_* cookies to measure aggregate traffic, page views, and feature usage. We do not use advertising cookies and we do not sell or share analytics data for cross-site tracking. You can opt out at any time by installing the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout), enabling 'Do Not Track' in your browser, or blocking third-party cookies in your browser settings.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data; restrict or object to its processing; and request data portability. To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are located in the EEA or UK, you may also lodge a complaint with your local data protection supervisory authority.
Contact Us
For privacy-related questions, data deletion requests, or to exercise your rights, contact us at [email protected].