AI Visibility Tracker
Log inGet started
Contents

Privacy Policy

What AI Visibility Tracker collects, why, who else receives it, how long we keep it, and what you can ask us to do. Written to match how the Service actually works.

Last revised September 24, 2026 · Terms of Service

1. Who we are

AI Visibility Tracker (the "Service") is operated by Linkee, Inc. ("we", "us"), the company behind Loopex Digital. Registered address: 651 N Broad St, Suite 201, Middletown, Delaware 19709, United States. For anything in this policy, contact us through our support channel.

This policy explains what we collect when you use the Service at aivisibility.loopex.ai and any successor domain, why we collect it, who else receives it, how long we keep it, and what you can ask us to do with it. Last revised September 24, 2026.

2. Information we collect

Account information

When you create an account we store your name, email address and a hashed password. Passwords are hashed with a one-way function; we cannot read them. If you sign in with Google, we store the identifier and tokens Google gives us for your account and link it to the same email. We also store whether your email is verified and the role assigned to your account.

Workspace and billing information

Each account has one workspace. For it we store the plan, subscription status, billing interval, the current billing period, whether cancellation is scheduled, and the identifiers Stripe assigns to your customer and subscription. We never receive or store your card number; Stripe holds payment details.

Content you add

  • Brands: the name, website domain, aliases, competitor domains and industry you enter. When you add a brand we read its public homepage and store a short business description, core services and competitor keywords derived from it. You can edit all of these.
  • Prompts: the questions you add, their tags, their location, and whether they are active.
  • Schedules and the settings on your Billing page.

Data the Service generates for you

  • Answers: the full text of every answer an AI model returns for your prompts, stored word for word, with the model, the time and the location used.
  • Citations: for each page an answer cited, the URL, page title, a short snippet, our classification of the page (page type and who owns the domain), and whether your brand was mentioned with a link, without a link, or not at all. We do not store the fetched page itself.
  • Mentions: which brands appear in each answer, where in the answer they appear, and a sentiment score computed from the words around the mention.
  • Usage records: which model ran which prompt, when, the tokens and web-search calls it used, and the estimated cost, so we can enforce plan limits.
  • Deleted prompts: for 30 days after you delete a prompt we keep a snapshot of it and its history so it can be restored (see section 6).

Information collected automatically

  • Sessions: when you sign in we record the IP address and browser user agent of that session alongside the session token.
  • Server logs: our web server and application write standard request and error logs. We do not run analytics, advertising or behavioural tracking software of any kind on the Service.

Cookies and browser storage

  • A session cookie (better-auth.session_token, with a __Secure- prefix in production) keeps you signed in. It is HTTP-only, sent only over HTTPS in production, restricted to same-site requests, and expires after 7 days.
  • A support-mode cookie (support-workspace-id) exists only for our staff and expires after four hours; it is never set on customer browsers.
  • Your browser's local storage keeps three preferences: your recently opened brands, whether the sidebar is collapsed, and which columns the Brands table shows. These never leave your browser.
  • We set no advertising or analytics cookies, so the Service shows no cookie banner. You can clear or block cookies in your browser; blocking the session cookie prevents signing in.

3. How we use information

  • To run the Service: send your prompts to the AI models you track, fetch and classify the pages they cite, detect mentions, compute visibility, sentiment and share of voice, and show you the results.
  • To run your weekly schedule automatically and to run a new prompt once when you add it.
  • To bill you, enforce the brand, prompt and monthly run limits of your plan, and handle upgrades, downgrades and cancellation.
  • To send transactional email: email verification and password reset. We send no marketing email from the Service.
  • To keep the Service secure: rate limiting, abuse prevention, and investigating problems using logs.
  • To support you when you ask us to (see section 5).

We do not sell personal information and do not use your content to train AI models.

4. Who receives your information

The Service is built on third-party providers. Each receives only what is needed for its part of the job.

  • AI model providers: Anthropic (Claude), OpenAI (ChatGPT models), Google (Gemini) and, where enabled, Perplexity receive the text of your prompts and the location you set for them, and return the answers we store. OpenAI additionally receives short excerpts of cited third-party pages and brand names so that mentions of generic brand names can be judged in context. Each provider processes this data under its own API terms; we send no account information to them.
  • DataForSEO receives the prompt text and location code to retrieve Google AI Overviews and search results, and supplies the list of locations you can choose from.
  • Jina Reader (r.jina.ai) receives the URLs of pages cited in answers, and the homepage URL of a brand you add, and returns the page text we classify in memory. Some pages are fetched directly by our server instead.
  • Stripe receives your email address and processes payments; we store only the identifiers and status Stripe returns.
  • Postmark delivers our verification and password-reset emails and therefore receives your email address and name.
  • Google's favicon service: the dashboard shows favicons for tracked and cited domains by loading them from www.google.com/s2/favicons in your browser. Google therefore sees which domains your browser requested icons for, together with your IP address, under Google's privacy policy.
  • Hosting: the Service and its database run on servers we manage. The database is not reachable from the internet.
  • Authorities and successors: we disclose information when the law requires it, to protect our rights or users, or to a successor if the Service changes hands, in which case this policy continues to apply to information already collected.

We use no advertising networks and no analytics providers.

5. Access by our staff

Authorized Loopex Digital staff can open a customer workspace in a time-limited support mode (four hours per activation) to reproduce a problem or help with setup, and administrators can see the list of accounts with their email addresses and plans. Staff access is limited to what is needed to operate and support the Service and is governed by confidentiality obligations. Staff-only tools that read across workspaces are not available to customer accounts.

6. How long we keep information

  • Account and workspace data: for as long as your account exists.
  • Answers, citations, mentions and usage records: for as long as the brand and prompt they belong to exist. Deleting a brand deletes its prompts, answers, citations and mentions immediately and permanently.
  • Deleted prompts: recoverable for 30 days from the Recently deleted list, then purged.
  • Archived brands: kept in full, with their weekly runs paused, until deleted.
  • After cancellation: nothing is deleted. Your data stays readable until the end of the paid period and is retained afterwards so you can resubscribe, until you ask us to delete it.
  • Sessions: expire after 7 days of inactivity, or when you sign out.
  • Backups: an encrypted-at-rest database backup is taken nightly and the three most recent are kept, so deleted data can persist in backups for up to about three days.
  • Server logs: rotated on a short cycle and not used for profiling.

7. Your rights and choices

Depending on where you live you may have rights under the GDPR, the UK GDPR, the CCPA/CPRA or similar laws. Regardless of where you live, we offer everyone the following:

  • Access and portability: your data is visible in the dashboard, and the Overview, Prompts and Sources pages export CSV files of your answers, brands, prompts and sources.
  • Correction: edit your brands, prompts and profile details in the dashboard, or ask us to correct account details.
  • Deletion: delete brands and prompts yourself at any time. To close your account and delete the whole workspace, contact us from the account's email address; we confirm and complete deletion within 30 days, after which the data also rolls out of backups.
  • Objection and restriction: you can pause tracking by deactivating prompts, archiving brands or cancelling, and you can object to any processing by contacting us.
  • Complaints: you may complain to your local data-protection authority. We would appreciate the chance to address your concern first by contacting us directly.

We will not discriminate against you for exercising any of these rights. We verify requests by contacting the email address on the account.

8. International transfers

The providers listed in section 4 operate in the United States and other countries, so your prompts, answers and account details may be processed outside the country you live in. Where a transfer mechanism such as standard contractual clauses is required, we rely on the mechanisms offered by those providers.

9. Security

All traffic to the Service is encrypted with TLS, and browsers are told to use HTTPS only. Passwords are hashed. Every request is checked against the signed-in account's workspace, so one customer cannot read another's data. Sign-in attempts and API calls are rate-limited. Fetches of third-party pages are restricted to public internet addresses. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as the law requires.

10. Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect information from children; if you believe we have, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service changes. We will post the revised policy here with a new "last revised" date and, for material changes, notify you by email or in the dashboard before they take effect. Continuing to use the Service after that date means you accept the revised policy.

12. Contact

Linkee, Inc. (Loopex Digital), 651 N Broad St, Suite 201, Middletown, Delaware 19709, United States.