Privacy Policy
Effective 3 September 2026
This policy explains what personal information Appomate Pty Ltd collects through AI Visibility, why, and how you can control it. We are bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, for customers in the EU or UK, act as a processor of your customer data under the GDPR.
What we collect
Account information
- Your email address and, if you sign in with Google, your Google account identifier.
- The websites you register, their brand name and business description, the prompts and competitors you track, and the knowledge base you build or connect.
- Billing details are held by Stripe; we store only a customer reference, plan and subscription status — never card numbers.
Website activity you send us
- The collectors you install (Cloudflare Worker or WordPress plugin) report which AI crawlers requested which paths on your website, plus hourly total request counts. They are designed not to send visitor IP addresses, cookies or form data.
- If you connect Google Analytics or Search Console we store an OAuth refresh token and pull aggregate metrics (sessions, clicks, impressions by page and query). We never read individual visitor records.
Usage and technical data
- Standard server logs and the actions you take in the dashboard, used to operate and secure the Service.
- Records of the AI model calls made on your behalf (tokens and cost), used for billing integrity and plan limits.
Why we use it
- To provide the Service: running scheduled checks, generating reports, sending the emails you expect (verification, invites, trial and billing notices, and the weekly digest on eligible plans — which you can unsubscribe from in one click).
- To bill you and comply with tax law.
- To keep the Service secure and to improve it. We do not sell personal information and do not use your data to train AI models.
Who we share it with
We use the following subprocessors. Some are outside Australia; where data leaves Australia we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | Sydney (AWS ap-southeast-2) |
| Google Cloud (GKE) | Application hosting and scheduled jobs | Melbourne / Sydney |
| Stripe | Payments, invoicing, tax | Global |
| Anthropic | AI analysis (citation judging, gap audits, content briefs) | United States |
| OpenAI | Citation monitoring — querying ChatGPT with web search | United States |
| Google (Gemini, Analytics, Search Console) | Citation monitoring; GA4 and Search Console data you connect | Global |
| Perplexity | Citation monitoring | United States |
| Resend | Transactional email | United States / EU |
| Cloudflare | Optional edge collector you install on your own zone | Global |
Prompts you track are sent to AI engines (OpenAI, Anthropic, Google, Perplexity) as questions, and pages of your website may be fetched and sent to Anthropic for analysis. We do not send your visitors' data to any of them.
Retention
- Monitoring history is kept for the retention period of your plan (90 days on Starter, 12 months on Growth, 24 months on Scale) and then deleted.
- Account data is kept while your account exists. Deleting your account removes it within 30 days, except records we must keep for tax or legal reasons.
- Trial accounts that never subscribe are deleted 30 days after the trial ends.
Your rights
- Access and portability: export everything we hold about your account from Settings at any time.
- Correction: update your details in Settings or ask us.
- Deletion: delete your account from Settings, or ask us. Team members can be removed by an account owner.
- Google access: disconnect Google Analytics or Search Console from Settings; we revoke the token immediately. You can also revoke it from your Google Account permissions.
- Marketing: the weekly digest has an unsubscribe link; we do not send other marketing email without consent.
Cookies
The dashboard uses only cookies that are necessary to run it: your sign-in session, your theme choice and which site you last viewed. We do not use advertising or third-party analytics cookies, so there is no consent banner.
Security
Data is encrypted in transit and at rest, isolated per customer at the database level, and accessible only to authorised Appomate staff for support. Ingest keys and invite tokens are stored as hashes. Report security concerns to hello@appomate.com.au.
Contact and complaints
Appomate Pty Ltd, Melbourne, Victoria, Australia — hello@appomate.com.au. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).