Security and data handling
What we store, where it goes, and how to export or delete it.
#What we store
Your account (name, email, company, a hashed password), your projects, prompts and competitors, every answer collected for you (with its sources), audit results, briefs and insights, and billing identifiers from Stripe (customer and subscription ids and status — not card details). We also keep a log of emails we send you.
#Who it goes to
To collect an answer we send a prompt and your brand and competitor names to the AI provider for that engine (OpenAI, Anthropic, Google or Perplexity). Hosting, the database, email and payments are handled by the services listed on the subprocessors page. We don't use your data to train models.
#Isolation and access
Every query is checked against the signed-in account. Passwords are hashed with scrypt, sessions use httpOnly cookies and are stored hashed, and reset and confirmation links are single-use. There is one login per account; role-based access, SSO and an audit log are not built. See the security page for what we do and don't claim.
#Retention
Answers, audits and drafts are kept until you delete the project or your account. There is no automatic expiry today.
#Export and deletion
- Export — Settings → Download my data (JSON), and CSV on the Answers page for paid plans.
- Delete a project — Project settings. Removes its prompts, answers, audits, briefs and insights.
- Delete your account — Settings. Removes your account and everything under it, and cancels any active subscription immediately. Billing records Stripe is legally required to keep stay with Stripe.
#Reporting a vulnerability
See the security page and /.well-known/security.txt.
Last updated Oct 8, 2026 · Suggest an edit