Privacy Policy
What we collect, and what you can have removed
This policy explains what data AEO Radar collects, who it flows to, how long we keep it, and how to request deletion, including if your business was scanned without your involvement.
What we collect
From people who use AEO Radar, we collect:
- The email address you enter to run a free scan or to create an account.
- The business name and the queries ("races") you submit to be measured.
- Account and billing details for paid plans (handled by our payment processor; we do not store full card numbers).
- Basic technical data such as a hashed IP address used for rate limiting.
Data about third-party businesses (scanned without consent)
The public free scan can measure a business by name even when that business did not ask to be measured and did not consent. For those businesses we store the business name that was submitted, the queries it was measured against, the raw answers the AI engines returned, and the scores we derived. We measure only what AI answer engines already say in response to public-style queries; we do not access any private system. A scanned business can request deletion at any time (see below).
Who processes your data (subprocessors)
To run a scan we send the business name and queries to the AI answer engines and to our infrastructure providers. These subprocessors receive data only to perform their function:
- AnthropicClaude answer-engine queries and answer classification
- OpenAIChatGPT answer-engine queries
- PerplexityPerplexity answer-engine queries
- xAIGrok answer-engine queries
- DataForSEOGoogle AI Mode measurement
- SupabaseDatabase and authentication hosting
- VercelApplication hosting
- InngestBackground job orchestration for recurring census runs
- StripePayment processing for paid plans
How long we keep it (retention)
We retain the raw answers returned by the AI engines for 24 months, so we can reclassify and re-score them as our methods improve and so trend history stays intact. Derived scores and aggregate figures may be kept longer. We delete or anonymize data on request as described below.
Your deletion rights (GDPR / CCPA carve-out)
If you are in a jurisdiction with deletion or access rights (for example under the EU/UK GDPR or the CCPA/CPRA in California), you may request that we delete or disclose the personal data we hold about you. This applies both to people who used the Service and to a founder or business that was scanned without consent: if your business was measured and you want its data removed, you can ask us to delete it, and we will, subject to any legal obligation to retain specific records.
To make a request, email privacy@aeoradar.ai with the business name and the queries (or scan link) involved. We will confirm and act on verified requests within a reasonable time.
Our current posture (no false claims)
We do not currently hold a SOC 2 report or any third-party security certification, and we do not claim to be "GDPR compliant" or "CCPA compliant" as a certification. This page states our actual practices, and we honor the deletion rights above. We will update this page as our posture changes.
Contact
Questions about privacy, or a deletion or access request, can be sent to privacy@aeoradar.ai.