AI Visibility

Draft — pending legal review. This text describes how the service operates today and will be finalised before it is relied on as a contract.

Privacy Policy

Effective 3 September 2026

This policy explains what personal information Appomate Pty Ltd collects through AI Visibility, why, and how you can control it. We are bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, for customers in the EU or UK, act as a processor of your customer data under the GDPR.

What we collect

Account information

  • Your email address and, if you sign in with Google, your Google account identifier.
  • The websites you register, their brand name and business description, the prompts and competitors you track, and the knowledge base you build or connect.
  • Billing details are held by Stripe; we store only a customer reference, plan and subscription status — never card numbers.

Website activity you send us

  • The collectors you install (Cloudflare Worker or WordPress plugin) report which AI crawlers requested which paths on your website, plus hourly total request counts. They are designed not to send visitor IP addresses, cookies or form data.
  • If you connect Google Analytics or Search Console we store an OAuth refresh token and pull aggregate metrics (sessions, clicks, impressions by page and query). We never read individual visitor records.

Usage and technical data

  • Standard server logs and the actions you take in the dashboard, used to operate and secure the Service.
  • Records of the AI model calls made on your behalf (tokens and cost), used for billing integrity and plan limits.

Why we use it

  • To provide the Service: running scheduled checks, generating reports, sending the emails you expect (verification, invites, trial and billing notices, and the weekly digest on eligible plans — which you can unsubscribe from in one click).
  • To bill you and comply with tax law.
  • To keep the Service secure and to improve it. We do not sell personal information and do not use your data to train AI models.

Who we share it with

We use the following subprocessors. Some are outside Australia; where data leaves Australia we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.

ProviderPurposeLocation
SupabaseDatabase, authentication, storageSydney (AWS ap-southeast-2)
Google Cloud (GKE)Application hosting and scheduled jobsMelbourne / Sydney
StripePayments, invoicing, taxGlobal
AnthropicAI analysis (citation judging, gap audits, content briefs)United States
OpenAICitation monitoring — querying ChatGPT with web searchUnited States
Google (Gemini, Analytics, Search Console)Citation monitoring; GA4 and Search Console data you connectGlobal
PerplexityCitation monitoringUnited States
ResendTransactional emailUnited States / EU
CloudflareOptional edge collector you install on your own zoneGlobal

Prompts you track are sent to AI engines (OpenAI, Anthropic, Google, Perplexity) as questions, and pages of your website may be fetched and sent to Anthropic for analysis. We do not send your visitors' data to any of them.

Retention

  • Monitoring history is kept for the retention period of your plan (90 days on Starter, 12 months on Growth, 24 months on Scale) and then deleted.
  • Account data is kept while your account exists. Deleting your account removes it within 30 days, except records we must keep for tax or legal reasons.
  • Trial accounts that never subscribe are deleted 30 days after the trial ends.

Your rights

  • Access and portability: export everything we hold about your account from Settings at any time.
  • Correction: update your details in Settings or ask us.
  • Deletion: delete your account from Settings, or ask us. Team members can be removed by an account owner.
  • Google access: disconnect Google Analytics or Search Console from Settings; we revoke the token immediately. You can also revoke it from your Google Account permissions.
  • Marketing: the weekly digest has an unsubscribe link; we do not send other marketing email without consent.

Cookies

The dashboard uses only cookies that are necessary to run it: your sign-in session, your theme choice and which site you last viewed. We do not use advertising or third-party analytics cookies, so there is no consent banner.

Security

Data is encrypted in transit and at rest, isolated per customer at the database level, and accessible only to authorised Appomate staff for support. Ingest keys and invite tokens are stored as hashes. Report security concerns to hello@appomate.com.au.

Contact and complaints

Appomate Pty Ltd, Melbourne, Victoria, Australia — hello@appomate.com.au. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).