Privacy policy
August 3, 2026
This policy describes the data VizibAI processes to provide its service tracking brand visibility in AI engine answers, and the rights available to you.
Who we are
VizibAI operates a service that measures how AI answer engines (ChatGPT, Claude, Gemini, Perplexity and others) talk about a brand. For any question about your data: contact@vizibai.com.
Data we process
Account data: email address, name, Google sign-in identifier where applicable.
Workspace data: the tracked brand name, domains and aliases, configured prompts, activated engines, members and roles.
Data collected on your behalf: the answers produced by the AI engines queried on your prompts, and the metrics derived from them (visibility, share of voice, sources).
Technical data: access and error logs, IP addresses, session identifiers.
Google data you connect
If you choose to connect a Google account (optional), we request two READ-ONLY scopes: Google Analytics 4 (analytics.readonly), to display in your dashboard the traffic AI assistants drive to your site, and Google Search Console (webmasters.readonly), to turn your real search queries into monitoring prompts.
We also receive the email address of the connected account, displayed in your settings so you can verify it is the right one.
Access tokens are encrypted at rest (AES-256-GCM) and are never exposed to the browser. You can revoke this access at any time, from your workspace settings or from your Google account permissions page; disconnecting deletes our tokens.
Limited Use of Google user data
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
We only use Google user data to provide and improve the features described above.
We do not sell Google user data, and we do not use it for advertising.
We do not use Google user data to train generalized or standalone AI/ML models.
We do not transfer Google user data except as necessary to provide the service (to the sub-processors listed below), to comply with applicable law, or as part of a merger or acquisition with prior notice.
Human access to Google user data is restricted to what is necessary for support, security, or to comply with the law, and otherwise prohibited.
Purposes and legal bases
Providing the subscribed service (performance of the contract): querying the engines, computing the metrics, displaying the results to your team.
Securing the service (legitimate interest): authentication, logs, abuse prevention.
Improving the service (legitimate interest): diagnostics run on technical data, never selling data to third parties.
Subprocessors
We rely on technical providers who process data on our behalf:
Supabase (database and authentication), Vercel (application hosting), Cloudflare (storage of raw answers), ClickHouse Cloud (analytical storage), Google Cloud (extraction service), Inngest (processing orchestration).
To collect engine answers: OpenAI, Anthropic, Google AI, as well as Bright Data and DataForSEO for public answers. Google is also the source of the Analytics and Search Console data you connect.
Each provider is bound by a data processing agreement.
Retention periods
Account data is kept for as long as the account remains active.
A workspace's data is deleted at the request of its owner or when the account is closed.
Technical logs are kept for a limited period, as necessary for security.
Your rights
You have the rights of access, rectification, erasure, portability and objection provided under the GDPR.
To exercise them: contact@vizibai.com. You can also file a complaint with the CNIL, the French data protection authority.
Security
Data travels encrypted (TLS).
Each workspace is isolated: a member can only access the workspaces they belong to.
Internal access is restricted to what is strictly necessary.
Changes to this policy
This policy may evolve along with the service. The update date appears at the top; significant changes will be flagged within the application.