Effective date:
This Privacy Policy explains how SIMURG LABS INC., a Texas corporation ("GeoTune", "we", "us"), collects, uses, shares, and protects personal data when you use the GeoTune platform, website, and related services (the "Service"). It forms part of our Terms of Service.
Account and billing data. For the personal data we collect about you as a user of the Service — your account, your billing, your use of the platform — SIMURG LABS INC. is the controller (the entity that decides how and why the data is processed).
Data inside your workspace. The content you submit to the Service — brand names, topics, prompts, target website addresses, team-member details, and the results generated from them ("Customer Data") — is processed on the instructions of the workspace owner. Where the workspace owner is a business and Customer Data contains personal data protected by the EU or UK GDPR or similar laws, the workspace owner is the controller and we are its processor. A Data Processing Addendum that documents our processor obligations (including the sub-processor list in Section 5, security measures, assistance with data-subject requests, and breach notification) is available on request through the contact in Section 13.
What we do not collect. We do not ask for, and you must not submit, sensitive personal data (health, biometric, genetic, racial or ethnic origin, political opinions, religion, sexual orientation, or precise geolocation). We do not knowingly collect data about children.
| Purpose | Data | Legal basis (EU/UK GDPR) |
|---|---|---|
| Creating and operating your account and workspace; running the scans and audits you request; producing results and reports | Account information, Customer Data, Results | Performance of a contract |
| Billing, invoicing, tax compliance, fraud prevention | Billing information, technical data | Performance of a contract; legal obligation; legitimate interest in preventing fraud |
| Security, abuse prevention, enforcing the Terms of Service, protecting the sites we audit and the AI providers we use from misuse | Technical and log data, Customer Data | Legitimate interest in keeping the Service secure and lawful |
| Transactional emails (verification, password reset, invoices, renewal reminders, scan completion, service changes) | Email address | Performance of a contract; legal obligation for renewal notices |
| Product announcements and marketing emails | Email address | Consent, or legitimate interest for existing customers where permitted; you can opt out at any time via the unsubscribe link |
| Error monitoring and improving reliability | Technical data, error reports | Legitimate interest in a stable service |
| Improving the Service, developing features, benchmarking | Usage data and Results, aggregated or de-identified | Legitimate interest; de-identified data is not personal data |
| Responding to legal requests, establishing or defending claims | Any of the above, as relevant | Legal obligation; legitimate interest |
We do not use Customer Data or Results to train machine-learning models, we do not make automated decisions about you that have legal or similarly significant effects, and we do not use personal data for targeted advertising.
Visibility scans. When you run a visibility scan, we send the prompts generated for that scan — which contain the brand names, topics, competitor names, and questions you configured — to the AI provider(s) you selected (OpenAI, Anthropic, Perplexity, and/or Google Gemini) through their business APIs, and we receive their responses. We do not send your name, email address, account identifiers, or billing information with those requests. Each AI provider processes the prompts under its own API terms and privacy commitments, which govern how long it retains request data; we recommend that you do not include personal data about identifiable individuals in prompts. Results shown in GeoTune that were generated by an AI provider are labelled as AI-generated.
Technical audits. When you run a technical audit, GeoTune's servers fetch the publicly accessible pages of the website address you specify, and we send that address to Google's PageSpeed Insights API to obtain performance metrics. If that website belongs to someone else, its operator may see our requests in their logs, identified by our user agent; we do not disclose your identity to the site operator.
We share personal data only with the service providers below, each bound by contract to process it solely to provide their service to us, and with the other recipients listed.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Stripe, LLC and its affiliates (including Stripe Technology Europe, Ltd. for EU customers) | Payment processing, invoicing, tax calculation, fraud screening | Name, email, billing address, payment method (handled by Stripe), transaction history | United States and European Union |
| Hetzner Online GmbH (Hetzner Cloud) | Hosting the application, database, and backups | All data described in Section 2 | United States (Ashburn, Virginia); provider organized in Germany |
| OpenAI and its affiliates (API services) | Generative-engine responses for visibility scans | Prompts (brand/topic content) and responses | United States |
| Anthropic, PBC (Anthropic Ireland, Limited for EEA, UK, and Swiss customers) | Generative-engine responses for visibility scans | Prompts (brand/topic content) and responses | United States |
| Perplexity AI, Inc. | Generative-engine responses for visibility scans | Prompts (brand/topic content) and responses | United States |
| Google LLC (Gemini API) | Generative-engine responses for visibility scans | Prompts (brand/topic content) and responses | United States |
| Google LLC (PageSpeed Insights API) | Core Web Vitals and performance metrics for technical audits | Website address submitted for audit | United States |
| Plus Five Five, Inc. (Resend) | Transactional and account email delivery | Email address, name, email content | United States |
| Functional Software, Inc. d/b/a Sentry | Error monitoring (enabled only in environments where it is configured) | Technical error data, request identifiers, IP address; not local variables or request bodies | United States |
Other recipients. We may also disclose personal data (a) to professional advisers (lawyers, accountants, auditors) under confidentiality obligations; (b) to a successor in a merger, acquisition, or sale of assets, subject to this Policy; (c) where required by law, subpoena, or court order, or to protect the rights, property, or safety of GeoTune, our users, or others — we will notify you of such requests where the law allows; and (d) to the members of your workspace, who can see Customer Data and Results within that workspace.
Changes to sub-processors. We will update this list before adding a sub-processor that processes personal data. Business customers with a Data Processing Addendum receive advance notice as set out in the Addendum and may object on reasonable data-protection grounds.
We do not sell personal data and have not sold it in the past 12 months. We do not share personal data for cross-context behavioral advertising.
We keep personal data only as long as needed for the purposes above, then delete or de-identify it.
| Data | Retention |
|---|---|
| Account information | For the life of your account. When you delete your account, it is removed from active systems within 30 days. |
| Customer Data and Results in an active workspace | For the life of the workspace, so that you can track visibility over time. You can delete individual projects, scans, or results at any time. |
| Closed workspaces (cancelled, downgraded, or deleted) | Kept in a suspended, non-accessible state for 30 days after closure so that the workspace can be restored if the closure was a mistake or if you resubscribe. After 30 days the workspace, its Customer Data, and its Results are permanently deleted from active systems, and from backups within a further 60 days (at most 90 days after closure). You can ask us to delete a closed workspace sooner. |
| Billing records, invoices, consent and cancellation records | 7 years after the transaction, to meet tax, accounting, and consumer-protection record-keeping obligations, and 3 years at minimum for records of consent to recurring billing. |
| Technical logs | Up to 12 months, unless needed longer for a security investigation. |
| Error reports in Sentry | 90 days. |
| Support communications | 3 years after the last exchange. |
| Backups | Encrypted backups are rotated on a rolling schedule; data deleted from active systems ages out of backups within 60 days. |
Where a legal hold or dispute requires it, we may keep specific data longer, limited to that purpose.
SIMURG LABS INC. is located in the United States, and the providers listed in Section 5 process data primarily in the United States. Our production infrastructure is hosted by Hetzner Online GmbH, a company organized in Germany, on servers physically located in Ashburn, Virginia, USA; the data itself is therefore processed and stored in the United States, even though our contract for that hosting is with a German company. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to the United States.
We rely on the following safeguards: (a) the European Commission's Standard Contractual Clauses (Module 1 or Module 2, as applicable), and the UK International Data Transfer Addendum, in our contracts with you and with our sub-processors; and (b) where a recipient is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), that certification as an additional basis. We also apply supplementary measures — encryption in transit, encrypted backups, access controls, and data minimization in what we send to AI providers — and we monitor the legal status of these transfer mechanisms. A copy of the applicable clauses is available on request.
Everyone. You can access and update most account information directly in your settings, export your Results, delete projects and scans, and delete your account. You can opt out of marketing emails at any time by using the unsubscribe link; we will still send transactional emails required to run your account.
EU, UK, and Swiss residents. Under the GDPR and equivalent laws you have the right to: access your personal data and receive a copy; have inaccurate data corrected; have data deleted; restrict or object to processing based on legitimate interests; receive data you provided in a portable format; withdraw consent at any time (without affecting prior processing); and lodge a complaint with a supervisory authority, in particular in the member state of your residence or workplace.
California residents. Under the California Consumer Privacy Act, as amended, you have the right to know what personal information we collect and how we use and share it, to delete it, to correct it, to opt out of sale or sharing (we do neither), to limit use of sensitive personal information (we do not collect it), and not to be discriminated against for exercising these rights. Whether or not the CCPA's thresholds apply to us, we honor these requests for California residents.
Texas and other U.S. state residents. Under the Texas Data Privacy and Security Act and similar laws in other states, you may have the right to confirm whether we process your data, to access, correct, delete, and obtain a copy of it, and to opt out of sale, targeted advertising, or profiling (none of which we do). If we decline a request, you may appeal by replying to our response; we will answer the appeal within 60 days and tell you how to contact your state attorney general if you disagree.
How to exercise rights. Use your account settings or contact us at the address in Section 13. We may ask you to verify your identity (usually by confirming control of the account email). We respond within one month (EU/UK) or 45 days (U.S. states), extendable once where the law allows, and we do not charge for requests unless they are manifestly unfounded or excessive. You may authorize an agent to make a request on your behalf, subject to verification.
Requests about Customer Data. If your personal data is in a workspace controlled by one of our business customers (for example, you were invited as a team member), we will refer your request to that customer and help them respond.
We use only strictly necessary cookies; there are no advertising, analytics, or tracking cookies on the Service.
| Cookie | Purpose | Duration |
|---|---|---|
| geotune_session | Keeps you signed in and protects your session (HttpOnly, Secure, SameSite) | Session; expires on sign-out or after a period of inactivity |
| geotune_staff | Session cookie used only for GeoTune staff administration access | Session |
| oidc_state | Protects the sign-in flow against cross-site request forgery when you sign in with a third-party identity provider | 10 minutes |
Because these cookies are essential to provide the Service you asked for, no consent banner is required for them. If we ever introduce optional cookies, we will ask for your consent first and update this Section.
We protect personal data with technical and organizational measures appropriate to the risk, including: encryption in transit for all traffic between you and the Service (TLS 1.2+, enforced via HSTS, terminated at Cloudflare); daily backups of the database and configuration that are encrypted (using age) before they leave our servers for storage; servers with no open public ports, reachable only through a Cloudflare Tunnel and a private network; database access restricted to that private network; password hashing; role-based access controls and least-privilege access for staff; workspace isolation; secrets kept out of source code and error reports; logging and monitoring for suspicious activity; rate limiting; and regular dependency and security reviews.
No system is perfectly secure. If we become aware of a personal-data breach that affects you, we will notify you and, where required, the competent authority without undue delay — and, for business customers for whom we act as processor, within the time set out in the Data Processing Addendum so that they can meet their own 72-hour notification duty.
The Service is for users aged 18 and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us and we will delete it.
We may update this Policy. If a change materially reduces your rights or expands how we use personal data, we will notify you by email or in the Service at least 30 days before it takes effect. Other changes take effect when posted, with the effective date above updated. Continuing to use the Service after a change takes effect means the updated Policy applies.
SIMURG LABS INC., a Texas corporation.
Privacy requests and questions: support@geotune.ai.
Brand visibility monitoring for AI answer engines.