Legal
Privacy Policy
This policy explains what personal data VisibilityProof processes, why, on what legal basis, who we share it with, and the rights you have. We keep it specific — it names the actual services we use. If anything here is unclear, contact us at privacy@visibilityproof.com.
1. Who we are (the controller)
VisibilityProof (“we”, “us”) provides a website-visibility analyzer covering classic search (SEO) and AI answer engines (GEO). For the personal data described here, we are the data controller. Questions or requests: privacy@visibilityproof.com.
2. What we collect
- Account data — your email address and a securely hashed password (Argon2id; we never store the plaintext). Optionally a display name, and 2FA/passkey credentials if you enable them.
- Audit data — the domains and URLs you submit for analysis, and the public information we fetch about them (HTML, metadata, performance signals). This is data about websites, which may be your own.
- Usage data — records of actions such as scans run and reports exported, used for quotas, billing and product improvement.
- Contact messages — if you write to us through the contact form, we store your name, email and message so we can reply and keep a record of the request.
- Billing data — your subscription status and plan. Payments are processed by our merchant of record, Polar; we never receive or store your full card number.
- Technical & log data — IP address, browser/device information and timestamps, processed to run the service securely and prevent abuse.
- Referral data — if you sign up through someone’s referral link, we record who referred you, so their discount can be calculated. This links your account to another user’s. We also generate a referral code for every account. The code travels in the link’s
?ref=address — we set no cookie for it. - Sign-in provider data — if you use “Continue with Google” or “Continue with Apple”, we receive your email address, and your name where the provider supplies it, to create or match your account.
- Analytics & marketing data — only if you consent (see the Cookie Policy). Nothing in this category is collected before you allow it.
3. Why we use it, and our legal basis (GDPR Art. 6)
- To provide the service — creating your account, running audits, showing and exporting reports. Basis: performance of a contract.
- Billing & fraud prevention — managing subscriptions and protecting against abuse. Basis: contract and legitimate interests.
- Security & reliability — authentication, rate-limiting, logging. Basis: legitimate interests and legal obligation.
- Analytics & marketing — understanding usage and measuring campaigns. Basis: your consent, which you can withdraw at any time.
- Legal compliance — keeping records we are required to keep. Basis: legal obligation.
4. Who we share it with (processors & sub-processors)
We do not sell your personal data. We share it only with service providers who process it on our behalf:
- Hostinger — our hosting provider. It hosts the application and the MySQL database (account, audit and usage data), and operates the mail servers that send our email.
- Hostinger (email) — transactional email (address verification, password resets, subscription notices) and your contact-form messages are delivered through Hostinger’s SMTP service, which therefore receives your name, email address and message content.
- Google and Apple — if you choose “Continue with Google” or “Continue with Apple”, that provider tells us your email address (and name, if available), and necessarily learns that you signed in to VisibilityProof.
- Polar — merchant of record for payments; the legal seller for your subscription and the party that remits EU VAT. Polar processes your billing details under its own privacy policy.
- Google PageSpeed Insights — we send the target URL you audit (not your personal data) to measure Core Web Vitals.
- DataForSEO — we send the target domain to retrieve keyword and backlink metrics.
- Anthropic (Claude) — we send audit prompts referencing the target domain to measure AI answer-engine visibility (GEO). We do not send your account credentials.
- Google Analytics / Google Tag Manager and Meta Pixel — only if you consent to analytics/marketing cookies.
Referral relationships stay inside VisibilityProof — we do not share them with anyone. A referrer sees how many people they referred and whether those referrals qualified, never who they are.
The measurement providers above receive the website you ask us to analyze, not your identity. Providers act under data-processing terms; where a provider is outside the EEA (e.g. in the United States), transfers rely on the EU Standard Contractual Clauses or an equivalent safeguard.
5. International transfers
Some sub-processors (for example Google, Apple, Anthropic and DataForSEO) may process data in the United States. Where that happens we rely on appropriate safeguards — primarily the European Commission’s Standard Contractual Clauses — to protect your data to an EU-equivalent standard. Our hosting and email provider, Hostinger, is established in the EU.
6. How long we keep it
- Account data — for as long as your account exists; deleted (or anonymised) on account closure, subject to legal retention periods.
- Audit reports — retained as your report history so you can compare results over time; you can delete individual reports.
- Billing records — kept as long as tax/accounting law requires.
- Logs — kept for a limited period for security, then deleted or anonymised.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (“right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time (this does not affect processing already carried out); and
- lodge a complaint with a supervisory authority — in Slovenia, the Information Commissioner (Informacijski pooblaščenec).
To exercise any of these, email privacy@visibilityproof.com. You can change cookie choices anytime via .
8. How we protect your data
Passwords are hashed with Argon2id and never stored in plaintext. Traffic is encrypted in transit (HTTPS). We use a strict Content-Security-Policy, CSRF protection, session rotation and optional two-factor authentication. No system is perfectly secure, but we take reasonable and appropriate measures to protect your data.
9. Children
VisibilityProof is a business tool and is not directed to children under 16. We do not knowingly collect their data.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by a new effective date at the top, and where appropriate we will notify you.
11. Contact
Privacy questions or requests: privacy@visibilityproof.com.
See also the Cookie Policy for the exact cookies we use and how the consent banner works.