Version 2.0 · Effective August 13, 2026

Privacy Policy

This policy explains what AIScoring collects, why, and what your rights are. Plain language, no dark patterns. Written to be jurisdiction-neutral; where local law (GDPR, UK GDPR, CCPA, etc.) gives you stronger rights, those rights apply.

the human version
  • • We store your email, the domains you scan, your results, and — if you gave one — your phone number for billing and urgent alerts. Never for marketing calls.
  • • We use our own analytics, not ad networks: which channel brought you, which page you landed on, which events you fired. No cross-site tracking cookies, no data sold, ever.
  • • The Evidence Log records every URL we fetched on your behalf, with the status code. That's on purpose — no black box.
  • • We keep a record of when you accepted the Terms: version, moment, context and IP. It exists so a payment dispute has an answer.
  • • Emails you get: sign-in links, product alerts you switched on, and the weekly digest. One click unsubscribes from the non-essential ones.
  • • Email us and we export or delete everything. No retention games.

The section below is the detailed version and controls if the two ever conflict.

1. Who we are

AIScoring is operated by AIScoring LLC, the data controller for the personal data described here. Contact: hello@aiscoring.io.

2. What we collect

  • Scan inputs — the URL / domain you enter, plus your IP address and User-Agent for rate limiting and abuse prevention.
  • Scan results — the score, per-check pass/fail, and evidence we computed for that URL. Stored so results are shareable and re-openable.
  • Account data — your email address, full name and role if you provide them, your sites and primary domain, competitor URLs, markets, and reference queries you configure.
  • Phone number — optional at onboarding and required when you take a paid plan. Stored in E.164 format with the country you selected. Used only for billing verification and urgent account or scan alerts. It is never used for marketing calls or SMS campaigns, and it is never shared with AI providers or advertisers.
  • Evidence Log — for each run we record every URL we fetched on your behalf (yours and third-party public pages), the purpose of the fetch, HTTP status, response size and timestamp. This exists so you can audit exactly what our conclusions were built on. It contains public URLs and technical metadata, not personal content.
  • AI sampling records — the queries we sent to third-party models, which models answered, the raw answers, mentions, positions, cited sources and cost. Queries are about your category and brand, not about you personally.
  • Product usage / events — privacy-conscious events (page views, scan started/completed, email captured, account created, pricing viewed, checkout started, share clicked, referral link created) with an anonymous session id (random, rotates after 30 days of inactivity) and coarse timing. No third-party trackers, no ad networks, no cross-site cookies. We honor the browser Do-Not-Track (DNT) signal and skip event logging when it is set.
  • Attribution data (first-party analytics) — when you land on the site we store, in your browser (localStorage + cookie, ~90 days, first-touch wins): UTM parameters (source/medium/campaign/content/term) if present, referring domain (e.g. google.com, chatgpt.com), a derived channel label (organic_search, ai_referral, social, direct…), and the landing page. On /scan we also record the internal source you came from (e.g. a blog post slug) as a "last internal touch". When you run a scan, submit your email or upgrade, these fields attach to that scan / email / order record so we can see which channels and which content actually drive revenue. Stored server-side in tables with no public read access, never sold, never shared with ad networks.
  • Referral data — the referral code that brought you, and whether you activated (created an account and scanned).
  • Terms acceptance record — each time you accept our Terms (creating an account, subscribing, or redeeming a code) we store your user id, the terms version, the context, the timestamp and the originating IP address. Legal basis: our legitimate interest and legal obligation in being able to evidence a contract, especially in a payment dispute. You may request a copy of your own record.
  • Emails and alerts — we log which product emails we sent you (sign-in links, verification, high-severity alerts, weekly digest, sequence steps), delivery status, and whether you opened, clicked or unsubscribed. Notification preferences are stored on your account and you can change or disable non-essential email at any time.

We do not collect or store payment card data ourselves; card checkout runs through a PCI-compliant processor which receives your payment details directly.

3. What we don't collect

  • We do not require login to run a scan.
  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We do not use ad networks or cross-site tracking cookies.
  • We do not fetch anything that is not publicly reachable over HTTPS, and we never attempt to bypass a login, paywall or robots directive.
  • We do not send your email, name or phone number to AI providers.

4. Why we process it

  • To perform the contract — running scans, sampling models, generating deliverables, billing, and support.
  • Legitimate interests — abuse prevention and rate limiting, first-party product analytics, evidencing acceptance of the Terms, and improving the methodology.
  • Consent — non-essential product emails and, where required locally, analytics. Withdrawable at any time.
  • Legal obligation — tax and accounting records for payments.

5. Public data

Agentic Scores are computed from publicly available data and may be displayed publicly. If you believe a score for a domain you represent is incorrect, email hello@aiscoring.io — see Terms § 11.

6. Third-party sub-processors

  • Hosting, database & auth — our managed cloud backend (Postgres, authentication, storage) and edge hosting provider.
  • LLM APIs — OpenAI, Anthropic, Perplexity and Google, used only to measure visibility in their assistants. We send buying-intent queries; we do not send account PII.
  • Email delivery — a transactional email provider for sign-in links, verification and product notifications.
  • Payments — a PCI-compliant payment processor, which receives your billing details directly and returns only a status and an identifier to us.

Each sub-processor is bound by its own terms and processes data on our instructions.

7. How long we keep data

  • Anonymous scan results — kept indefinitely so shared links keep working. You can request deletion of a specific scan.
  • Account data, sites, results and deliverables — kept for the life of your account, then deleted on request.
  • Evidence Log and sampling records — 24 months, then aggregated or deleted.
  • Terms acceptance records and payment records — kept as long as needed to defend a dispute or meet accounting obligations (typically 7 years), even after account deletion.
  • Abuse / rate-limit logs — rotated within 90 days.

8. Your rights

You can, at any time:

  • Access, export, or correct your account data — including your terms acceptance record.
  • Delete your account and associated data (except records we must keep under § 7).
  • Request deletion of a specific scan attributed to a domain you represent.
  • Remove your phone number, unless you have an active paid plan that requires it.
  • Unsubscribe from non-essential email in one click.
  • Object to processing, restrict it, or withdraw consent where local law provides it, and complain to your local supervisory authority.

To exercise any of these, email hello@aiscoring.io from the address on your account. We respond within 30 days.

9. International transfers

Our providers may process data in the United States and other countries. Where required, transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.

10. Security

Data is encrypted in transit and at rest. Access is limited to a small operator team, authentication is rate-limited per IP and per account, and passwords are checked against known breach corpora. Report a vulnerability at /.well-known/security.txt.

11. Children

AIScoring is not intended for children under 16. We do not knowingly collect personal data from children.

12. Changes

We may update this policy. When we do, we bump the version and effective date at the top of this page. Material changes are announced to signed-in users by email.

13. Contact

Privacy questions and requests: hello@aiscoring.io.