Security & Data Protection
Encrypted at rest
Our database (Neon Postgres) encrypts all stored data with AES-256, with keys managed in a cloud key-management service.
Encrypted in transit
Every connection, from your browser to us and from us to our database, uses TLS 1.2 or newer.
Secrets encrypted twice
Google Search Console and Analytics tokens, AI-assistant sessions you connect, and webhook signing secrets are also encrypted inside the app with AES-256-GCM. API keys are stored only as one-way hashes.
Secure sign-in
Sign-in is handled by Clerk. We never see or store your password.
Payments kept separate
Polar processes payments. Card numbers never reach our servers.
Access controls
Team roles limit who can change settings. On the Business plan, teams get an audit log of activity and can restrict access to approved IP addresses.
Hardened app
Security headers, request size limits and rate limits on sign-in, API and audit endpoints protect against common attacks.
Download your data
Settings → Privacy & data gives you everything we store about your account as a JSON file, at any time.
Delete your account
Settings → Privacy & data permanently deletes your account, data and login, and ends your subscription.
2-year history limit
Monitoring scans and prompt-test results older than 2 years are deleted automatically every night.
No selling, no ads
We don't sell your data or use it for advertising.
Providers
Replit: Application hosting. Neon: Database (encrypted at rest). Clerk: Sign-in and account security. Polar: Payments and subscriptions. OpenAI: Asking ChatGPT your tracked questions; content analysis. Perplexity: Asking Perplexity your tracked questions. Google: Gemini analysis, transactional email, and Search Console / Analytics if you connect them. DataForSEO: Reading Google AI Overviews and search results.