Legal
Privacy Policy
This policy explains what Answerlume collects when you use the checker, sign in, join the monitoring launch list, or use Stripe billing, why the data is used, and how to request access or deletion.
1. Who controls the data
Answerlume is the controller of personal information described in this policy. Privacy requests can be sent to hello@answerlume.com.
2. Information collected
Checker submissions
When you request a report, Answerlume receives the submitted product URL and domain, product name, selected category, and optional competitor name. It also creates buyer-intent prompts and stores the resulting provider answers, citations, platform details, timestamps, and report metrics.
Email information
If you join the weekly monitoring launch list, Answerlume collects your email address, the signup source, the stated "weekly monitor" interest, and the submission time. The form is for launch notification only; it does not create an account or subscription.
Account and billing information
If you sign in with Google, Answerlume receives your verified email address, Google account identifier, display name, and optional profile image. Answerlume stores an opaque session identifier in an HttpOnly, SameSite cookie and stores only a SHA-256 hash of that random session token in Upstash Redis. Answerlume does not receive your Google password.
If you start a paid subscription, Stripe collects and processes your payment method and billing details. Answerlume stores the Stripe customer and subscription identifiers, subscription status, renewal-period information, and cancellation status. Answerlume does not store full card numbers or card security codes.
Technical data
Vercel supplies the request IP address to the checker for abuse prevention and daily rate limiting. Basic server and provider logs may also contain request times, route information, status codes, and error details. Answerlume does not intentionally ask for sensitive personal information.
3. How the information is used
- generate, retrieve, and display the AI visibility report you request;
- enforce per-IP, per-domain, and global usage limits and prevent abuse;
- operate, secure, troubleshoot, and measure the reliability of the checker;
- notify launch-list members when weekly monitoring becomes available; and
- authenticate accounts, create Stripe Checkout sessions, record subscription status, and provide access to the Stripe billing portal;
- comply with law, enforce the Terms, and protect Answerlume and its users.
Where GDPR applies, these activities rely on performance of the requested service, Answerlume's legitimate interests in operating and securing the service, consent for optional launch notifications, and compliance with legal obligations as applicable.
4. Hashing, storage, and retention
- Rate-limit identifiers: IP addresses and normalized domains are transformed with HMAC SHA-256 before they are written to rate-limit keys. Only a shortened hash is stored. These counters expire after approximately 48 hours.
- Report jobs: submitted URLs, domains, product inputs, generated prompts, provider job references, and report evidence are stored in Upstash Redis for up to seven days so report links can be reopened. They then expire automatically.
- Operational metrics: date-level counters such as checks started and report outcomes may be retained for up to 120 days. These counters do not contain the submitted IP address, domain, or email.
- Launch-list emails: email submissions do not currently have an automatic expiry. They are retained until the monitoring launch notification is complete, the list is discontinued, or you request deletion, subject to any legally required retention.
- Account sessions: hashed session tokens expire after 30 days. Signing out deletes the current server-side session. Account profile and subscription records are retained while the account is active and as reasonably necessary for billing, fraud prevention, tax, accounting, dispute, and legal obligations.
Hashing reduces exposure but is not the same as anonymous deletion. Answerlume treats rate-limit hashes as protected technical data.
5. Third-party processors
Answerlume uses the following service providers to operate the website:
- Bright Data: receives generated prompts and collects third-party ChatGPT and Perplexity dataset observations used in reports.
- Vercel: hosts the website and serverless API and processes requests, IP information, deployment data, and operational logs.
- Upstash: provides Redis storage for temporary report jobs, rate-limit counters, operational counters, launch-list submissions, account profiles, hashed sessions, and subscription status.
- Google: verifies Google Identity Services sign-in credentials and supplies the account profile fields you authorize for authentication.
- Stripe: provides hosted checkout, payment processing, subscription records, and the customer billing portal when paid monitoring is enabled.
These providers process data under their own terms and privacy commitments and may process information in countries other than your own. Answerlume does not sell personal information or share it for cross-context behavioral advertising.
6. Data disclosure
Information may be disclosed to the processors above, when required by law or valid legal process, to investigate abuse or security incidents, or in connection with a merger, acquisition, financing, or sale of the business. Answerlume does not publish submitted checker inputs as public prompt-library entries.
7. Your privacy rights
Depending on where you live, you may have the right to know or access personal information, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a data-protection authority. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service without discrimination. Answerlume does not currently sell or share personal information as those terms are defined by the CCPA.
To exercise a right, email hello@answerlume.com with the subject "Privacy request" and include enough information to identify the relevant report ID, domain, or launch-list email. Answerlume may need to verify your request before acting. You may also use an authorized agent where applicable law permits it.
8. Deleting your data
Temporary report jobs expire automatically after seven days. For earlier deletion of a report or deletion of a launch-list email or account profile, send the report ID or the relevant email address to hello@answerlume.com. Answerlume will process verified requests within the time required by applicable law. Some minimal information may be retained when necessary for security, fraud prevention, billing disputes, tax and accounting obligations, or documenting the request. Deleting an Answerlume account does not automatically delete the underlying Google account.
9. Children, security, and changes
Answerlume is intended for business users and is not directed to children under 16. Reasonable technical and organizational safeguards are used, but no internet service can guarantee absolute security. Material policy changes will be posted here with a revised effective date.