Privacy Policy
This policy explains what AIScoring collects, why, and what your rights are. Plain language, no dark patterns. Written to be jurisdiction-neutral; where local law (GDPR, UK GDPR, CCPA, etc.) gives you stronger rights, those rights apply.
1. What we collect
- Scan inputs — the URL / domain you enter, plus your IP address and User-Agent for rate limiting.
- Scan results — the score, per-check pass/fail, and evidence we computed for that URL. Stored so results are shareable and re-openable.
- Account data (if you sign up) — your email address, primary domain, competitor URLs, and reference queries you configure.
- Product usage / events — we log privacy-conscious events (page views, scan started/completed, email captured, account created, pricing viewed, payment initiated, share clicked, referral link created) with an anonymous session id (random, rotates every 30 days of inactivity), your first-touch referrer and UTM parameters, and coarse timing. No third-party trackers, no ad networks, no cross-site cookies. We honor the browser Do-Not-Track (DNT) signal and skip event logging when set.
- Attribution data (first-party analytics) — when you land on the site we store, in your browser (localStorage + cookie, ~90 days, first-touch wins): your UTM parameters (source/medium/campaign/content/term) if present, your referring domain (e.g. google.com, chatgpt.com), a derived channel label (organic_search, ai_referral, social, direct, etc.), and the landing page you arrived on. On the /scan page we also record the internal source you came from (e.g. the blog post slug) as a "last internal touch". When you run a scan or submit your email, these fields are attached to that scan / email / order record so we can understand which channels and which content actually drive scans and revenue. This data is stored server-side in tables with no public read access and is never sold or shared with third-party ad networks.
- Referral data — the referral code that brought you, and whether you activated (created an account and scanned).
We do not collect payment card data ourselves; if billing is enabled it will run through a PCI-compliant processor.
2. What we don't collect
- We do not require login to run a scan.
- We do not sell personal data.
- We do not use ad networks or cross-site tracking cookies.
- We do not fetch anything that is not publicly reachable at HTTPS.
3. Public data
Agentic Scores are computed from publicly available data and may be displayed publicly. If you believe a score for a domain you represent is incorrect, email hello@aiscoring.io — see Terms § 4.
4. Third-party sub-processors
- Hosting & database — Supabase (auth, Postgres, storage).
- LLM APIs — OpenAI, Anthropic, Perplexity, and Google, used only to measure your visibility in their assistants. We send buying-intent queries; we do not send your account email or PII.
- Email delivery — a transactional email provider for magic-link sign-in and product notifications.
Each sub-processor is subject to its own privacy terms.
5. How long we keep data
- Anonymous scan results — kept indefinitely so shared links keep working. You can request deletion of a specific scan.
- Account data — kept for the life of your account.
- Logs — rotated within 90 days.
6. Your rights
You can, at any time:
- Access, export, or correct your account data.
- Delete your account and all associated data.
- Request deletion of a specific scan attributed to a domain you represent.
- Object to processing or withdraw consent where local law requires it.
To exercise any of these, email hello@aiscoring.io from the address on your account. We respond within 30 days.
7. Security
Data is stored encrypted in transit and at rest. Access is limited to a small operator team. Report a vulnerability at /.well-known/security.txt.
8. Children
AIScoring is not intended for children under 16. We do not knowingly collect personal data from children.
9. Changes
We may update this policy from time to time. When we do, we bump the version and effective date at the top of this page. Material changes will be announced to signed-in users by email.
10. Contact
Privacy questions and requests: hello@aiscoring.io.