visitedby.ai is built to measure AI systems, not to surveil people. This policy explains what we collect in two distinct roles: as a controller of your account data, and as a processor of visitor data collected from our customers’ websites. Data controller: VisitedBy.AI Ltd, a company registered in the United Kingdom. Contact: hi@visitedby.ai.
01YOUR ACCOUNT (WE ARE THE CONTROLLER)
We collect and store:
- name, email, and a hashed password — to run your account;
- organization, team and plan configuration — to provide the product you configured;
- billing state from Paddle, our merchant of record (we never see or store your card details; payment data lives with Paddle under Paddle’s privacy policy);
- operational logs (errors, billing events) — to keep the Service reliable.
We use session cookies for sign-in only. There are no advertising trackers and no third-party analytics cookies, and we never sell data.
02VISITORS TO OUR CUSTOMERS’ SITES (WE ARE A PROCESSOR)
Customers deploy our tracking snippet or edge integration on their own websites to understand AI-originated traffic. For that purpose we process, on the customer’s behalf:
- page paths, referrers and user-agent strings — to classify whether a visit came from an AI assistant, an AI crawler, or elsewhere;
- a pseudonymous visitor identifier — IP addresses are truncated and hashed at the edge of our ingest process and never stored raw; coarse geography is derived at that moment and the address is discarded;
The customer who operates the website is the controller of this data and is responsible for any notice or consent their jurisdiction requires. If you believe a site using visitedby.ai has processed your data, contact that site’s operator first. We act on their instructions, including deletion requests.
03AI MEASUREMENT QUERIES
To measure AI visibility we send prompts about brands and topics to AI providers (OpenAI, Google, Perplexity). These prompts contain only the brand and market terms our customers configure, never personal data about identifiable people.
04WHERE DATA LIVES & SUBPROCESSORS
Our primary database runs on infrastructure we operate in Germany (Hetzner, EU). Subprocessors we rely on:
- Hetzner (DE) — servers and database hosting;
- Vercel — web application hosting;
- Cloudflare — network routing and security;
- Paddle — payments, invoicing and tax (merchant of record);
- Resend — transactional email (digests, invitations);
- OpenAI, Google, Perplexity — AI measurement queries as described above.
05RETENTION & SECURITY
Measurement history is the product, so it is retained for as long as the workspace exists. Account deletion removes your data within 30 days (backups roll off within a further 30), except minimal records kept for legal or accounting reasons. Data in transit is encrypted with TLS; access is limited to the operator; backups are encrypted at rest off-site.
06YOUR RIGHTS
Where GDPR or similar laws apply, you may request access, correction, export, or deletion of your personal data, and you may object to or restrict processing. Email hi@visitedby.ai and we will respond within 30 days. You also have the right to complain to your local data-protection authority.
07CHANGES
We will announce material changes to this policy by email or in the product before they take effect. The date at the top reflects the latest revision.
