Privacy Policy
Effective August 17, 2026
LLMBrandScan is a small, solo-operated product, and its data appetite matches: we collect the minimum needed to sell you scan credits, run your scans, and show you your reports. This page lists everything — what we hold, what third parties handle for us, and how to get your data removed.
What we collect
Your email address — it is the account. Sign-in is by magic link or Google OAuth (which shares only your email and basic profile with us). Your scan configuration — brand names, aliases, domains, category, competitors, and the questions you approve. Your scan results — the raw engine answers and the metrics computed from them, kept so your reports keep working and stay auditable. Payment records — which pack you bought, when, and the Stripe identifiers for it. Payments are processed entirely by Stripe: card details go from your browser to Stripe, and we never see or store your card number.
Where your data goes
Running a scan means sending your approved scan questions — which contain your brand, category, and competitor names — to the AI engine providers you selected: OpenAI, Anthropic, Google (Gemini), xAI (Grok), Perplexity, and DataForSEO (Google AI Overviews). Your email and account identity are never part of those requests. Each provider's handling of API traffic is governed by its own terms.
Beyond the engines, four service providers handle data for us: Stripe (payments), Resend (transactional email — magic links, report-ready and monitoring notices), Sentry (error monitoring), and PostHog (product analytics). Traffic analytics run on Umami, which we self-host — cookieless and not shared with anyone. The service itself is hosted on Hetzner servers in the EU behind Cloudflare. We do not sell or rent personal data to anyone, and there is no advertising tracking on the site.
Cookies
One essential session cookie keeps you signed in. There are no third-party advertising cookies. That is the list.
We send transactional email tied to things you did: sign-in links, purchase receipts, report-ready notices, and monitoring digests you opted into. The optional updates list on the homepage is separate, and every message from it carries an unsubscribe link.
Retention and deletion
Account data and reports are kept while your account exists, because deleting them would break the reports you paid for. Billing records are kept as long as accounting rules require. To access or delete your data, contact us via the contact page from the email on the account — we will verify it is you and delete what the law does not require us to keep. If you are in a jurisdiction with statutory data rights (access, correction, deletion, portability, objection), those rights apply and the same contact route exercises them.
Changes
If this policy changes materially, the effective date above changes with it. See also the terms of service and refund policy.