Privacy policy
This policy explains what personal data Recomindo processes when you use our website, the free AI Visibility Check, the app, our emails and the AI-traffic snippet, and what rights you have. We describe what our software actually does.
1. Who is responsible
The controller is [FILL IN: business name (sole proprietorship: owner name or firm name)], [FILL IN: street and number], [FILL IN: postal code] [FILL IN: city], [FILL IN: country code, e.g. PL]. Privacy questions and requests: [FILL IN: privacy contact email].
We have not appointed a data protection officer; please use the address above.
2. What we process and why
- Your account: email address, optional name, language, sign-in times, and for each active session a hashed session token and your browser’s user-agent string. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- Free check: the domain you enter and the result. To prevent abuse we limit checks per IP address. For this we keep a hash of your IP address, made with a key that changes every day, and delete it after 2 days. We do not store your IP address itself. Legal basis: our legitimate interest in protecting the service (Art. 6(1)(f)).
- Free tools (AI crawler checker, llms.txt generator, AI-readiness audit): the domain you enter and the result, which we keep for 7 days so repeat visits don’t re-check the site. To prevent abuse we limit uses per IP address with a hash made with a daily-changing key, deleted after 2 days. Legal basis: legitimate interest (Art. 6(1)(f)).
- Websites we analyse: we read up to 10 public pages of the website you enter, including any contact details published there (phone numbers, email addresses, postal addresses), and store a summary with your brand. To produce your analysis, this public page text is sent to our AI provider Anthropic. Legal basis: contract (6(1)(b)) and, for third-party details published on the analysed site, legitimate interest (6(1)(f)).
- AI engine checks: we send the buyer questions for your market to OpenAI, Perplexity, Google and SerpAPI and analyse the answers. These questions contain no personal data about you.
- Payments: payment happens on Stripe’s hosted checkout; card details never reach our servers. We store Stripe customer and subscription IDs and the subscription status. Legal basis: contract (6(1)(b)) and statutory accounting and tax obligations (6(1)(c)).
- Emails: sign-in links and account emails, and the weekly report if you receive it, are sent through Resend. Every report email has a one-click unsubscribe link. Legal basis: contract (6(1)(b)).
- AI-traffic snippet on our customers’ websites: the snippet sets no cookies and uses no visitor IDs. We store only visits that come from an AI assistant (ChatGPT, Perplexity, Gemini, Copilot, Claude): the AI source, the landing page path without query string and the time, plus a hash of the visitor’s IP address (made with a daily-changing key, deleted after 30 days) for de-duplication and abuse limits. For this data our customer is the controller and we act as their processor.
- Visits to our website: we count each visitor once per day and where they came from (for example a search engine, an AI assistant or a link we sent), using no cookies. To count a visitor only once per day we briefly store a hash of the IP address and browser, made with a key that changes every day; it is deleted after 2 days and cannot be linked across days. The visit record itself (day, source, landing page) holds no personal data and is kept 13 months. Legal basis: legitimate interest (Art. 6(1)(f)), understanding where our visitors come from.
- Slack alerts: if you connect a Slack webhook, alert messages about your brand are sent to your Slack workspace.
- Server logs: our hosting provider records technical request logs, which include IP addresses, to operate and secure the service. Legal basis: legitimate interest (6(1)(f)).
3. Cookies and local storage
We use no analytics or advertising cookies. We use only:
- Session cookie (strictly necessary): keeps you signed in; expires after 30 days of inactivity or when you sign out.
- Language cookie (geo_locale): remembers the language you chose; expires after one year.
- Bot protection: on the free check, Cloudflare Turnstile verifies that you are human. Your IP address is sent to Cloudflare for this check, and a temporary token is kept in your browser’s session storage.
4. Service providers
We use these providers, each only for the purpose listed:
- Google Cloud Platform: hosting and database, region europe-west1 (Belgium).
- Anthropic: AI analysis of public website text and AI answers; content generation.
- OpenAI, Perplexity, Google (Gemini) and SerpAPI: answering the buyer questions we track. No personal data about you is sent.
- Resend: sending emails.
- Stripe: payments and subscriptions.
- Cloudflare: bot protection (Turnstile).
- Slack: only if you connect it, for alerts.
Some of these providers are based in or process data in the United States. Transfers outside the EEA are safeguarded by: [FILL IN: per provider, e.g. EU-US Data Privacy Framework certification and/or Standard Contractual Clauses].
5. How long we keep data
- Sign-in and sign-up links expire after 15 minutes, invites after 7 days; all are deleted 1 day after use or expiry. Sessions are deleted when they expire, 30 days after your last visit.
- Free-check results (public data about a domain) are kept for 30 days and reused for 7 days. The free-check log, which contains no personal data, is kept for 90 days.
- Raw AI answers behind your reports are kept for 13 months, AI-referral visit records for 13 months. Report scores, fixes and generated content are kept as long as your account exists. When you delete your account in Settings, we immediately erase the account, its brands and all their data, team members who have no other account, and cached free-check results for your domains. We keep only a record that the deletion happened (account ID, time and counts, no email address).
6. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format. You can download your data as a JSON file and delete your account yourself in Settings. Where processing is based on consent, you can withdraw it at any time. For anything else, email [FILL IN: privacy contact email] and we will answer within one month. You can unsubscribe from report emails with the link in every email.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in your country of residence. Our lead authority is [FILL IN: lead supervisory authority, e.g. UODO (Poland)].
8. Businesses we contact
We may send a business a single message about its visibility in AI answers. This section covers business contact data that we did not receive from you.
- What we store: company name, website domain, city and industry, a business contact email address, the result of a free AI-visibility check of the company’s public website, the status of our contact, and how often the report link in our message was opened (no tracking pixel and no cookies).
- Source: the company’s public website or a list of business contacts that we compiled ourselves.
- Purpose: a one-off business message about the company’s AI visibility. Nothing is sent automatically; each message is reviewed and sent by a person.
- Legal basis: legitimate interest (Art. 6(1)(f)), presenting a relevant service to businesses. You can object at any time.
- Retention: the email address, company name, city, industry and check result are erased after 12 months without activity, and at once if you opt out. We keep only the minimal record needed so that the domain is not contacted again: the domain, the batch, the status, the dates and the number of link opens.
- How to object: reply “no” to our message or write to [FILL IN: privacy contact email]. We stop contacting you and erase your email address at once. Your other rights are described in section 6.
9. Demo requests
- If you send the demo form on our agency page, we store your name, agency, email address, website, client range and message. We use them only to answer your request.
- Legal basis: taking steps at your request before a contract (Art. 6(1)(b)).
- Retention: deleted 12 months after you send the form. We store your IP address only as a hash made with a daily-changing key, to limit abuse; it is deleted after 2 days.
10. Client checks and share links
Agency accounts can run checks on a client's or prospect's website and share the result by a private link. The check and its link are kept as long as the agency's account exists. They are deleted when the agency deletes the check (the link stops working at once) or deletes the account. For link opens we store only a visit count, no IP address and no cookie.
7. Security
Data is encrypted in transit. Sign-in tokens and session cookies are stored only as hashes, IP addresses only as hashes made with a daily-changing key, and card data is handled entirely by Stripe. Our crawler only fetches public web addresses.
11. Changes to this policy
We update this policy when our processing changes. The date at the top shows the latest version.