Skip to content

One free scan, 6 AI engines.

Run yours
AI Visibility Checker Pro
Legal

Privacy Policy

Effective

This policy explains what we collect when you use AI Visibility Checker Pro, why, who helps us process it, and how to get it deleted. It's written in plain English. If anything is unclear, ask us.

The short version

  • A scan stores what you type in (brand, website, category, audience, competitors, country), the prompts we build from it, and the AI answers we get back.
  • We never store your raw IP address, only a salted one-way hash used for abuse limits.
  • Your email is only collected if you choose to unlock a report, join a waitlist, request a call or contact us.
  • Prompts go to AI engines through our data provider. Your email never does.
  • We don't sell or rent personal data, and we don't use advertising cookies.
  • Scans are kept for 12 months; contact details until you unsubscribe or ask us to delete them. Email us to access or delete your data.

1. Who we are

AI Visibility Checker Pro (“we”, “us”) runs aivisibilitycheckerpro.com, a free tool that checks whether AI engines such as ChatGPT, Claude, Gemini, Perplexity and Google's AI features recommend a business. We are the controller of the personal data described in this policy.

Questions about privacy go to [email protected].

2. What we collect

When you run a scan

  • What you enter: website or domain, brand name, what you sell (category), who you sell to (audience, optional), up to three competitors (optional) and a country.
  • What the scan produces: the prompts we generate from your inputs, the answers and cited sources returned by each AI engine, and our analysis of them (mentions, ranks, citations, competitors, scores).
  • Technical data: a salted one-way hash of your IP address (for IPv6, of its network prefix), your browser's user-agent string, the page that referred you to us, and campaign tags from the link you arrived on (for example utm_source or ad click IDs such as gclid).
  • Bot check: Cloudflare Turnstile checks that a person, not a script, is using the form. Your IP address is passed to Cloudflare in memory to verify the check. We don't store it.

When you unlock a report, join a waitlist, request a call or contact us

  • Contact details: your email address (required) and anything else you choose to give us: name, company, website, role and your message.
  • Context: which form you used, the scan it relates to (if any), whether you asked for a call, and that you ticked the consent box.
  • Technical data: the same hashed IP, user-agent, referrer and campaign tags described above.

When you book a call

Our scheduling page uses a booking provider (Cal.com or Calendly). It collects what you enter there, such as your name, email, notes and chosen time, and shares the booking with us. If you arrive from a report, the page may pre-fill your name, email and report link for you.

When we email each other

If you write to us or receive email from us, we keep that correspondence. Our email provider processes delivery data, such as whether a message was delivered.

3. What we don't collect

  • We don't ask for passwords or create accounts.
  • We don't take payment details on this site.
  • We don't crawl, copy or analyze your website. A scan only reads what AI engines say.
  • We don't store raw IP addresses.
  • We don't want sensitive data. Please don't put personal details about other people into scan fields or messages.

4. How we use it, and our legal bases

  • To run your scan and show your report. Necessary to provide the service you asked for.
  • To send your report link and reply to you. Necessary to do what you asked, or our legitimate interest in answering business enquiries.
  • To follow up about your results, the call you requested or the waitlist you joined. Based on the consent you gave when you ticked the box. You can withdraw it at any time.
  • To keep the free tool available and safe: daily scan limits, bot checks, spend caps and abuse investigations. Our legitimate interest in protecting the service and our costs.
  • To improve the product: understanding which pages and features are used, in aggregate. Our legitimate interest, and your consent where the law requires it.
  • To meet legal obligations, such as responding to lawful requests or keeping records.

We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Our scoring describes how AI engines treat a brand. It isn't a decision about you.

5. Who we share it with

We use a small number of service providers who process data on our behalf, under contract, and only to run the service:

ProviderWhat they doData involved
CloudflareCloudflare privacy policyHosting, serverless functions, database (D1), answer cache (KV), bot protection (Turnstile) and, if enabled, cookieless web analytics.All data described in this policy, including hashed IP addresses and request metadata.
DataForSEODataForSEO privacy policySends our scan prompts to AI engines and Google on our behalf and returns the answers. It passes prompts to providers such as OpenAI, Anthropic, Google and Perplexity.Prompt text (your brand, domain, category, audience and competitors) and country. Not your email.
ResendResend privacy policyDelivers emails, such as your report link and replies to your messages, when email is enabled.Email address, name if given, and the email content.
Booking provider (Cal.com or Calendly)Cal.com privacy policyCalendly privacy noticeRuns the scheduling calendar on /book-a-call/ when you book a call.What you enter when booking: name, email, notes and the time you pick.
Lead routing toolsIf configured, a webhook forwards new leads to the tools we use to follow up (for example a CRM, Zapier, Make or Slack).Lead details you submitted and the scan they relate to.

AI engines. To answer your scan, our data provider sends the prompt text to the AI engines we check (operated by OpenAI, Anthropic, Google and Perplexity) and to Google Search. Prompts contain your brand, domain, category, audience and competitors. They never contain your email or other contact details. Those companies handle prompts under their own terms and policies.

We may also disclose data if the law requires it, to protect our rights or users' safety, or as part of a merger or sale of the business (in which case this policy continues to apply to your data).

We don't sell or rent personal data, and we don't share it for cross-context behavioral advertising.

6. Who can see your report

Each report lives at a long, random link. Reports aren't listed anywhere on our site and we tell search engines not to index them.

Anyone who has the link can open it. Before you unlock it, the link shows the headline results; after, it shows the full report, including the AI answers. Treat the link like a shared document: share it with people you trust, and ask us if you want a report deleted.

7. Cookies, local storage and analytics

We don't set advertising or tracking cookies. Here is what is stored in your browser:

  • aivcp:scan:<id> (local storage). A token that lets your browser finish or resume a scan you started. We clear entries older than 14 days the next time you run a scan, and you can clear them anytime in your browser settings.
  • aivcp:utm (session storage). Campaign tags, the referring page and the first page you visited, so we know how you found us. It's deleted when you close the tab.
  • Security cookies. Cloudflare may set strictly necessary cookies to protect the site from attacks and bots, and Turnstile runs its human check in your browser.
  • Booking calendar. If you use the embedded Cal.com or Calendly calendar, that provider may set its own cookies under its own policy.

Analytics. We may use Cloudflare Web Analytics, which measures page views without cookies or fingerprinting. If we add analytics or tag-management tools that use cookies or similar identifiers, we will ask for your consent first where the law requires it, and update this section before we do.

We treat a Global Privacy Control signal as a request to opt out of any sale or sharing of personal data. We don't sell or share data anyway.

8. How long we keep it

  • Scans and AI answers: 12 months from the scan date, then deleted or anonymized.
  • Contact details and messages: until you unsubscribe or ask us to delete them. If you unsubscribe, we keep only your email address on a suppression list so we don't contact you again.
  • Answer cache: 24 hours. A recent AI answer may be reused for the same prompt, engine and country. The cache holds answers, not contact details.
  • Scan limit counters: about a day, keyed by hashed IP and domain.
  • Backups: deleted data can remain in database backups for up to 30 days before it is overwritten.
  • Server logs: our hosting provider keeps short-lived request logs for security and debugging.
  • Bookings: kept by the booking provider under its policy, and by us for as long as we keep your contact details.

9. Your rights and choices

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct it if it's wrong;
  • delete it;
  • restrict or object to how we use it, including objecting to follow-up emails at any time;
  • send it to you or another company in a portable format;
  • withdraw consent you gave earlier (this doesn't affect what we did before).

If you live in California or another US state with a privacy law, you also have the right to know, delete and correct personal information, and to opt out of its sale or sharing. We don't sell or share it, and we won't treat you differently for exercising your rights. You can use an authorized agent.

To make a request, email [email protected] from the address you used, or include your report link. We may ask you to confirm the request from that email address before acting on it. We aim to respond within 30 days.

If you're in the EEA or UK and unhappy with our answer, you can complain to your local data protection authority.

To stop follow-up emails, tell us through the contact form or email [email protected], and we'll stop.

10. Security

The site runs over HTTPS. IP addresses are hashed with a secret before storage, run tokens are signed, API keys live in our hosting provider's secret store, and access to lead data is limited to the people who need it. No system is perfectly secure, so if you think you've found a vulnerability, please tell us at [email protected].

11. International transfers

Our providers operate globally, and Cloudflare serves the site from data centers around the world, so your data may be processed outside your country, including in the United States. Where the law requires it, we rely on safeguards such as the European Commission's Standard Contractual Clauses or the provider's certification under an adequacy framework.

12. Children

The service is built for businesses and isn't intended for anyone under 16. We don't knowingly collect personal data from children. If you think a child has given us data, contact us and we'll delete it.

13. Changes to this policy

We'll update this policy when what we collect or how we use it changes, and change the effective date at the top. If a change is significant and we have your email, we'll tell you before it takes effect.

14. Contact

Email [email protected] or use our contact form. This policy was last updated on October 4, 2026.

Check my brand free