Short version: Visiby only processes what you tell us to track plus a small amount of usage data to keep the service running. We never sell your data or use it to train AI models. It is encrypted in transit and at rest, and you can export or delete everything at any time.
This notice covers visiby.net and all Visiby sub-domains. It applies to anyone who visits, signs up, or uses the service.
Section 1
Data we collect
Account
Name, work email, password hash, workspace name, role
Google account (optional)
If you connect Google: your email and basic profile, plus read-only Search Console and Google Analytics 4 metrics for the properties you select. Covered in detail in section 5.
Brand config
Keywords, competitor URLs, prompts, geographies, schedules
Engine responses
Answers from ChatGPT, Perplexity, Gemini, Claude — including citations and timestamps
Usage
Pages viewed, reports run, browser, OS, truncated IP
Billing
Plan, seats, invoices, and the card summary our payment processor returns (last 4 and brand). Full card numbers stay with Razorpay and never reach us.
We never collect payment card numbers, government IDs, biometrics, or anything we don't need to operate the product.
Section 2
Why we collect it
Service delivery
Authentication, scheduled reports, dashboards, weekly digests.
Product improvement
Aggregated, de-identified usage only. We never train models on your prompts or responses.
Billing
Enough to process payments via Razorpay, our payment processor. We only store what's safe to show on an invoice.
Security & legal
Audit logs (90 days), rate limiting, tax records, and lawful disclosure when ordered.
Section 3
Who can see it
By default: you, your workspace members, and a small subset of Visiby on-call engineers. Outside that boundary, only:
Sub-processors under Data Processing Agreements and Standard Contractual Clauses: Razorpay (payments), Google Cloud (hosting, asia-south1), Cloudflare (CDN and R2 object storage), and the AI engines listed below.
AI engines — only the prompts you configure, only to engines you've enabled. No engine sees your account or billing data.
Law enforcement — only when compelled by a valid court order, and only after notifying you where permitted.
Acquirers — in a merger or sale your data moves under the same terms, with 30 days' notice.
We do not sell, rent, or barter personal data.
Section 4
How we protect it
Sensitive data (your credentials, the third-party tokens you grant us, and any Google account data you connect) is protected by the controls below. These are the mechanisms actually in place, not aspirations.
In transit
Every connection to visiby.net and to our API is encrypted with HTTPS/TLS, including the hop from our CDN edge to our origin servers. We serve no plaintext HTTP.
At rest
Databases, object storage, and backups sit on provider-managed AES-256 encrypted volumes.
Credentials
Passwords are stored only as Argon2id hashes, never in plaintext or a reversible form. Session refresh tokens are hashed the same way.
Third-party tokens
OAuth refresh tokens you grant us (including Google) are sealed with AES-256-GCM authenticated encryption before they are written to the database, using a key held outside it. They are decrypted only in memory, only to make the API call you asked for.
Network isolation
The database server has no public IP address and no internet-facing port. It accepts connections only from the application server, over a private network, enforced at the firewall.
Administrative access
Staff reach production only through identity-aware tunnels bound to their own named accounts, never shared logins or shared keys. Database roles are per-person, least-privilege, and read-only unless a role needs otherwise. Access is removed when someone leaves the project.
In-product access
Your data is scoped to your workspace by signed, workspace-scoped tokens. Access tokens expire after 1 hour, refresh tokens after 7 days, and both can be revoked.
Logging & monitoring
Authentication and administrative access are logged and retained for 90 days. Logs are scrubbed of tokens and secrets.
Change control
Production releases are manual and gated on automated type, lint, and test checks. No pipeline can push to production unattended.
If a breach affects your personal data, we notify the affected workspace owners and, where the law requires it, the relevant supervisory authority within 72 hours of becoming aware.
No system is perfectly secure. These controls reduce risk, they do not eliminate it, and we update this section as they change.
Section 5
Google user data
Connecting Google is optional. Visiby works without it. If you do connect, we ask for the narrowest scopes that let the feature work, and every one of them is read-only.
openid, email, profile
Identifies you at sign-in and links the connection to your Visiby account.
webmasters.readonly
Google Search Console: reads clicks, impressions, average position, and the queries and pages behind them, for the properties you pick. Read-only, so Visiby can never change or delete anything in your Search Console.
analytics.readonly
Google Analytics 4: reads traffic and engagement metrics for the property you pick. Read-only, so Visiby can never change your GA4 configuration or data.
What we do with it. This data is used only to produce the reports and dashboards you see inside your own workspace: search performance views, and prompt and topic suggestions derived from the queries your site already ranks for. Prompts you approve are then run against AI engines on your behalf. Your Google account identity, your OAuth tokens, and raw Search Console or Analytics exports are never sent to those engines or to any other third party.
How it is protected. The refresh token is AES-256-GCM encrypted at rest as described in section 4. Cached Search Console and Analytics results live in the same isolated database, scoped to your workspace, reachable only by your workspace members and the small on-call engineering group named in section 3.
How to disconnect. Settings, then Integrations, then Disconnect. That call revokes the token with Google immediately and erases it from our database in the same operation. You can also revoke access at myaccount.google.com/permissions. Cached Google-derived data is deleted within 30 days of disconnecting, and immediately on account deletion.
Visiby's use and transfer of information received from Google APIs to any other app adheres to the
Google API Services User Data Policy, including the Limited Use requirements. We never sell Google user data, never use it for advertising, never use it to train AI or machine-learning models, and never let a human read it except with your explicit permission, to resolve a support issue you raised, for security purposes, or where the law compels it.
Section 6
Retention & deletion
Account & workspace
Kept while your account is open. Deleting the account or workspace removes it, final after 7 days.
Google connections
Token erased the moment you disconnect. Cached Search Console and Analytics data deleted within 30 days of disconnecting, immediately on account deletion.
Reports & engine responses
Kept while your account is open so you keep your history, then deleted with the account.
Access & audit logs
90 days, then deleted.
Billing records
Retained as long as tax and accounting law requires, typically 7 years. This is the one category we cannot delete on request.
Section 7
Your rights
Wherever you live, these rights apply. Where GDPR, UK GDPR, CCPA, or DPDPA grants more, we honour the higher bar.
Access & export
Download everything we hold about you — self-serve from Settings → Export.
Deletion
Delete your account or workspace at any time. Final after 7 days.
Rectification
Correct inaccurate data from your profile settings.