Privacy Policy

Last updated: December 26, 2025

1. Introduction

Welcome to SearchLens AI ("we", "our", or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered search analytics platform.

This policy complies with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Data Controller

For the purposes of the GDPR, the data controller is SearchLens AI. If you have any questions about this privacy policy or our data practices, please contact us at:

3. Information We Collect

3.1 Personal Information

We collect the following personal information:

  • Account Information: Name, email address, password (encrypted)
  • Profile Information: Company name, job title, preferences
  • Usage Data: IP address, browser type, device information, pages visited
  • Communication Data: Support tickets, emails, feedback

3.2 Analytics Data

When you use our service to track brand mentions and analytics:

  • Search queries you configure
  • Brand names and competitor information you provide
  • AI-generated search results and analysis
  • Project settings and configurations

3.3 Cookies and Tracking Technologies

We use the following types of cookies:

  • Strictly Necessary: Required for authentication and core functionality
  • Functional: Remember your preferences and settings
  • Analytics: Help us understand how you use our service
  • Marketing: Track effectiveness of our marketing campaigns

4. AI Data Processing

4.1 How We Use AI

Our platform uses artificial intelligence to:

  • Analyze search results from AI platforms (ChatGPT, Perplexity, Claude, etc.)
  • Extract brand mentions, sentiment, and positioning data
  • Generate analytics insights and recommendations
  • Process and categorize competitor information

4.2 Third-Party AI Services

We use the following third-party AI services, each with their own privacy policies:

  • OpenAI (GPT models): For natural language processing and analysis
  • Anthropic (Claude): For advanced text analysis and insights
  • Google (Gemini): For search result analysis
  • Tavily API: For search result aggregation

Your data may be processed by these AI providers in accordance with their privacy policies. We have data processing agreements in place to ensure GDPR compliance.

4.3 Automated Decision-Making

We use automated systems to analyze search results and generate insights. You have the right to request human review of any automated decisions that significantly affect you.

5. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Contract Performance: To provide our services to you
  • Consent: For marketing communications and optional cookies
  • Legitimate Interests: To improve our service and prevent fraud
  • Legal Obligation: To comply with applicable laws and regulations

6. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our services
  • Process your search analytics requests
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Analyze usage patterns and trends
  • Detect and prevent fraud or abuse
  • Comply with legal obligations
  • Send marketing communications (with your consent)

7. Data Sharing and Disclosure

We may share your information with:

7.1 Service Providers

  • Cloud hosting providers (e.g., AWS, Railway)
  • AI service providers (OpenAI, Anthropic, Google)
  • Analytics providers
  • Email service providers
  • Payment processors

7.2 Legal Requirements

We may disclose your information if required by law or in response to valid requests by public authorities.

7.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

8. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with third-party processors
  • Adequacy decisions where applicable

9. Data Retention

We retain your personal data for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations (typically 7 years for financial records)
  • Resolve disputes and enforce our agreements

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are legally required to retain it.

10. Your Rights Under GDPR

If you are in the European Economic Area, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restriction: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with your supervisory authority

To exercise these rights, please contact us at [email protected]. We will respond within 30 days.

11. Your California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the CCPA:

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your rights

12. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures

13. Children's Privacy

Our service is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

14. Cookie Management

You can manage your cookie preferences at any time by:

  • Clicking the "Cookie Settings" link in the footer
  • Adjusting your browser settings to block or delete cookies
  • Using browser extensions that block tracking

Note that disabling certain cookies may affect the functionality of our service.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date
  • Sending you an email notification (for significant changes)

Your continued use of our service after changes become effective constitutes acceptance of the updated policy.

16. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact:

For EU residents, you can also contact your local data protection authority.

Supervisory Authority

If you are located in the European Economic Area and believe we have not addressed your concerns, you have the right to lodge a complaint with your local supervisory authority.