Privacy Policy
Last updated: October 1, 2026We are the data controller for the personal data described here, and you can reach us at support@answerpeek.com.
AnswerPeek (“AnswerPeek”, “we”, “us”, or “our”) helps you see whether your brand shows up in AI answers — and gives you the fixes if it doesn’t. This Privacy Policy explains what information we collect when you use answerpeek.com and the AnswerPeek application (together, the “Service”), how we use and share it, and the choices and rights available to you. It applies to everyone who visits our site, signs up for an account, or signs in with Google.
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
1. Information we collect
Account information
When you create an AnswerPeek account, we collect:
- Your name and email address, provided directly or via Google Sign-In.
- If you sign in with Google, your basic Google profile information — name, email address, and profile picture — as returned by Google’s OpenID Connect / basic profile scopes (
openid,email,profile). We do not request access to your Gmail, Google Drive, contacts, calendar, or any other Google data, and we do not request any sensitive or restricted Google scopes. - Your password, stored as a salted hash, if you sign up with email instead of Google.
- Workspace details such as agency or client names you add to organize your reports.
Content you submit
- Brand names, website domains, and URLs you submit to run an AI visibility check.
- Prompts, fixes, and notes you create, edit, or save inside the product.
Billing information
Paid subscriptions are processed by our payment provider, Paddle.com Market Limited, acting as merchant of record. Paddle collects and processes your payment card details directly — AnswerPeek never receives or stores full card numbers. We receive your name, email, country, and subscription/transaction status from Paddle to manage your account.
Usage and device information
Four analytics tools run on the Service, each doing a different thing:
- PostHog — pages visited, features used, links clicked, and session duration, across both the marketing site and the signed-in product. Once you are signed in, what you do in the product is recorded against your account: your account identifier, your e-mail address, and the workspace and plan you are on. That means the screens you open, the filters you change, the checks you run and the tasks you move — never the contents: not the questions you track, not what an AI assistant answered, not the pages you publish.
- Google Analytics — aggregate site-traffic data.
- Meta Pixel — page views, plus three conversion events: submitting a free check, unlocking its report, and completing sign-up. We use these to measure and target our advertising on Facebook and Instagram. The pixel runs only after you have agreed to analytics cookies, and it is switched off on the signed-in product and on white-label client reports — so a report an agency shares with its own client never loads it. Where it does run, it records the address of the page and nothing else; it is never sent your account contents, your reports, or anything you submit to a check.
- Plerdy — heatmaps and session recordings of how our public marketing pages are used. It runs only after you have agreed to analytics cookies, and it is switched off entirely on the signed-in product, the sign-in and sign-up pages, and white-label client reports — so it never records a page containing your account data or a credential field.
- Browser type, operating system, device type, approximate location derived from IP address, and referring URL.
- Standard server logs (IP address, timestamps, request metadata) for security and abuse prevention.
Cookies and similar technologies
We use cookies and local storage to keep you signed in, remember preferences, and understand how the Service is used (see “Usage and device information” above). You can block or delete cookies in your browser settings; doing so may affect parts of the Service that require sign-in.
Optional storage is a separate matter. If you are visiting us from the EEA, the UK or Switzerland, we ask once — and we ask in three parts, because a support chat, product measurement and advertising are not the same question. Nothing optional is stored on your device unless you say yes to that category, and nothing arrives pre-ticked. Until you do — and equally if you choose “Essential only” — we still count the visit, but without recognising you: Google Analytics runs with every storage type denied (Google Consent Mode) and PostHog runs in cookieless mode, so a page view is added to a total and nothing links it to your previous or next page. Session recording (Plerdy) and the Meta Pixel do not run at all in that state.
Some measurement happens on our servers rather than in your browser, and it happens either way. When a free check finishes, or when you ask us to e-mail you its report, we send Google Analytics the fact that it happened. If you have agreed to analytics cookies, that fact is attached to your session. If you have not, it carries no identifier at all — not your e-mail address, and nothing derived from your IP address, which in this case never reaches Google, because the request comes from our servers and not from your browser.
The same is true of the signed-in product, with one difference worth stating plainly. When a check completes, a task moves, a change is re-measured or a client report is opened, our server records that step in PostHog against your account, whatever you answered about cookies. Nothing is stored on your device to do it and nothing follows you around the web: this is us measuring whether our own product works — a scheduled check at four in the morning has no browser to be measured in, and a trial that quietly fails is one we cannot fix if we cannot see it. What we record is the step and its shape. The contents of your account are not sent, and neither is your clients’ data.
When somebody you shared a report link with opens it, we count that the link was opened and add it to your report’s view count. We do not identify that person, and we deliberately keep nothing that would let us recognise them on a second visit.
Say yes to analytics and the ordinary tools apply: analytics cookies, a visitor identifier that persists between pages, and Plerdy session recording on our marketing pages. Say yes to advertising and the Meta Pixel loads as well; say yes to functional and the support chat runs inside the app. You can change any of those answers at any time using the Cookie settings link in the footer, which reopens the choice and reloads the page so that any script you have withdrawn consent from stops immediately — and deletes what it had already written to your device.
Our Cookie Policy lists every cookie and storage key by name, who sets it, and how long it lasts.
2. How we use information
- Create and authenticate your account, and let you sign in securely (including via Google).
- Run AI visibility checks: we send the brand, domain, and generated prompts you submit — never your Google account data or password — to the providers that operate the assistants we track, to see how ChatGPT, Perplexity, Gemini and AI Overviews answer about your brand.
- Generate your prompt set, read the answers that come back, score your visibility, and draft your fixes. This analysis runs on Anthropic’s Claude models. Claude is not one of the assistants we measure — it is the model that does the reading and writing behind the report.
- Measure Google AI Overviews: your prompts are run as Google searches through a search-results provider (SerpApi) so we can read the AI Overview Google shows for them. Only the prompt text and the market (country and language) you track are sent — no account data, and nothing that identifies you.
- Operate, maintain, and secure the Service, including detecting and preventing fraud or abuse. Our operations alerts — a new sign-up, a failed check, a support message — are delivered to a private Telegram channel that only our team can read, and can include your email address and the domain you are checking. When something breaks, a crash report — the error, the code that produced it, and the page it happened on — is also recorded in Sentry so we can fix it.
- Send transactional email — account verification, password resets, billing receipts, and report-ready notifications — via our email provider, Resend.
- Process payments, manage subscriptions, and apply usage limits via Paddle.
- Understand product usage and improve features, performance, and reliability via PostHog, Google Analytics, and Plerdy.
- Measure and target our own advertising on Facebook and Instagram via the Meta Pixel, but only if you have agreed to analytics cookies.
- Respond to support requests you send us, whether by email or through the chat widget inside the app, which is operated by Crisp.
We do not sell personal information to third parties. We do not use the information you submit inside the product — your account data, your brands, your prompts, or your reports — to target advertising, and we never use anything obtained through Google Sign-In for advertising. The Meta Pixel described above sees only which pages you visited and whether you started a check, unlocked a report, or signed up; it is not given your Google profile, your account contents, or anything you submit to a check.
3. Legal bases and how long we keep data
If you are in the EEA or the UK, the GDPR requires us to name a lawful basis for each thing we do with your data, and to say how long we keep it. This is that list.
| Data | Purpose | Legal basis | Kept for |
|---|---|---|---|
| Account and profile | Creating your account and signing you in | Performance of our contract with you | Life of the account, then erased within 30 days |
| Brands, domains, prompts, reports and fixes | Running your checks and producing your reports | Performance of our contract with you | Life of the account, then erased within 30 days |
| Billing records | Invoicing, tax and accounting | Legal obligation | Up to 7 years after the transaction, as tax law requires |
| Product and website analytics | Understanding and improving how the Service is used | Your consent in the EEA, UK and Switzerland — except the cookieless visit count described above, which rests on our legitimate interest in knowing how much the Service is used; our legitimate interest in improving the Service elsewhere | Up to 14 months |
| Advertising measurement (Meta Pixel) | Measuring and targeting our own advertising | Your consent — it does not run without it | Up to 14 months, or until you withdraw consent |
| Server and security logs | Keeping the Service up, and preventing fraud and abuse | Legitimate interest in securing the Service | Up to 30 days |
| MCP tool-call logs | Operating and debugging the AnswerPeek MCP server | Performance of our contract with you | 180 days, then deleted automatically — and the link to you is removed the moment you delete your account |
| Crash reports | Finding and fixing errors in the Service | Legitimate interest in a Service that works | 90 days |
| Support correspondence | Answering you, and keeping a record of what was agreed | Legitimate interest in supporting our customers | Up to 24 months after the conversation ends |
When you delete your account
You can delete your account yourself from Settings, or ask us to by emailing support@answerpeek.com. Either way your workspaces, projects, checks, reports and login credentials are erased, and your Google profile data goes with them. Two things deliberately survive, and you should know about both:
- Your email address stays on our do-not-email list. It is there for one purpose — so that a later sign-up form or import cannot start mailing you again — and removing it would defeat the point.
- We keep a record that the deletion happened, containing your email address, name, the brand and domain on the account, the plan you were on, and any reason or feedback you chose to give us. We use it to understand why people leave. If you would rather we did not hold it, tell us when you delete, or email us afterwards, and we will erase it.
Billing records are kept for as long as tax and accounting law requires, as set out in the table above. Aggregated, de-identified statistics that can no longer be linked to you may be kept indefinitely.
4. Google user data & the Limited Use policy
AnswerPeek’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only request the minimum Google profile information needed to create and authenticate your AnswerPeek account (name, email address, profile picture).
- We use this data solely to provide and improve the sign-in and account features of the Service — never to serve ads, and never to sell, rent, or transfer it to data brokers, advertising platforms, or any other third party for purposes unrelated to operating the Service.
- Only a limited set of AnswerPeek personnel and automated systems necessary to operate, secure, and support the Service can access this data, and only for those purposes.
- You can review or revoke AnswerPeek’s access to your Google account at any time at myaccount.google.com/permissions.
5. How we share information
We do not sell your personal information. We share it only with the service providers (“subprocessors”) that help us run the Service, each bound by contract to use your data only to provide their service to us. The list below names them; our subprocessors page adds what each one receives and where it processes, and is the version we keep current for customers who need it for their own compliance.
- Vercel — hosting and content delivery for the site and the application.
- Supabase — authentication, database, and storage infrastructure.
- Paddle — payment processing, billing, and tax compliance.
- Resend — transactional email delivery.
- Crisp — the support chat inside the signed-in app. It receives your name and email address so a conversation is attached to your account rather than to an anonymous visitor, along with whatever you write in the chat.
- OpenAI, Perplexity, and Google — operate the assistants we track (ChatGPT, Perplexity, Gemini and AI Overviews). They receive the brand, domain, and prompts you submit, and nothing that identifies you.
- Anthropic — its Claude models generate your prompt set, read the answers the assistants give, and draft your fixes.
- SerpApi — runs your prompts as Google searches so we can read the AI Overview shown for them.
- PostHog, Google Analytics, and Plerdy — product and website analytics, including heatmaps and session recordings of our marketing pages.
- Meta — advertising measurement and targeting, only with your consent.
- Sentry — error monitoring. When something breaks it receives the error, the code that produced it, and the page it happened on. We have turned off the collection of IP addresses and request cookies, so a crash report says what broke, not who hit it.
- Telegram — carries our internal operations alerts, which can include your email address and the domain on your account, to a private channel readable only by our team.
We may also disclose information if required by law, subpoena, or legal process, to protect the rights, property, or safety of AnswerPeek, our users, or the public, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you before your information becomes subject to a different privacy policy.
6. Your rights
Depending on where you live (including under the GDPR and similar laws), you may have the right to:
- Access the personal data we hold about you and get a copy of it.
- Correct inaccurate or incomplete data.
- Request deletion of your data (“right to be forgotten”).
- Object to or restrict certain processing, and withdraw consent at any time.
- Export your data in a portable format.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@answerpeek.com. We will respond within 30 days.
7. Security
“Industry-standard safeguards” is a phrase that says nothing, so here is what we actually do:
- Everything travels over TLS, and is encrypted at rest by our database and storage providers.
- Row-level security in the database, so one workspace cannot read another’s projects, runs or reports even if application code asked it to.
- Passwords are stored only as salted hashes; we never see or store a plaintext password, and card details never reach us at all — Paddle handles them.
- Administrative access to production is separately credentialed, time-limited, and every entry into the admin panel is written to an audit log.
- Session recording is switched off on every page where account data or a password field can appear.
- We review what our subprocessors receive when we add one, and publish the result at answerpeek.com/subprocessors.
No method of transmission or storage is 100% secure, and we will not claim otherwise. If we become aware of a breach affecting your personal data we will tell you without undue delay, and within 72 hours where the law requires it.
8. International data transfers
AnswerPeek is operated from Ukraine, and the providers listed in section 5 may process and store data in the European Union, the United States, or other countries — most of them in the United States. Where required, we rely on standard contractual clauses or equivalent safeguards for cross-border transfers.
Article 27 of the GDPR asks a controller established outside the EU that offers services into it to designate a representative in the Union. We have not appointed one yet. We would rather say so here than leave the question unanswered: our processing is occasional, is limited to business contact details and the brand data described above, and does not involve special categories of data — which is the exemption we are relying on. Until a representative is appointed, address anything you would put to one directly to privacy@answerpeek.com, and you retain the right to complain to your own supervisory authority regardless.
9. Children’s privacy
The Service is intended for businesses and professionals and is not directed to, and we do not knowingly collect personal information from, anyone under 18 years old. If you believe a child has provided us personal information, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or with a notice on the Service before the change takes effect. The “Last updated” date above reflects the most recent revision.
11. Contact us
Questions about this Privacy Policy, or a request to exercise any of the rights in section 6? Email privacy@answerpeek.com, which is monitored for data-protection requests specifically. Our general support@answerpeek.com reaches us too, but a request sent there may take longer to route.