Privacy
Last updated 26 August 2026
What Visibility collects, why, who else touches it, and what it never receives. Written to be read rather than to be survived.
Who we are
Visibility is operated by Relevance Com, a company registered in Missouri, United States, at 4013 Frontgate Dr, Suite 104, Columbia, MO 65203.
Our role under data protection law depends on which data is in question, so it is worth stating both. For your account, billing and support data we are the controller — we decide what is collected and why. For the search and analytics data we pull from the accounts you connect, we are a processor acting on your instructions — you choose which properties to connect and can disconnect them at any time, and we use that data only to produce your reporting.
What we collect
Account
Your email address and a bcrypt hash of your password. Your agency name and white-label settings if you set them.
Connections
OAuth tokens for Google (read-only) and your Bing Webmaster API key, encrypted at rest. Which property or account you selected.
Synced search data
Aggregated performance data from Search Console, Bing Webmaster Tools and GA4 — queries, pages, clicks, impressions, positions, sessions, conversions.
Prompts and answers
The prompts you choose to track, the answers LLMs gave, and the pages those answers cited.
Billing
A Stripe customer id, subscription id, plan and prompt allowance. Not your card details — see below.
Operational logs
Server logs and sync outcomes, kept to diagnose failures.
What we never collect
Card numbers.Payment details are entered on Stripe's own pages and never reach our servers or logs.
Personal data about your website's visitors. The reporting APIs we read return aggregated metrics. We do not receive user-level events, and there is no script to install — Visibility never runs code on your site, so it cannot see your visitors at all.
Write access to anything. Every scope we request is read-only, and the full list is short: webmasters.readonly and analytics.readonly for Google, plus openid so we can show you which account you connected. We make no write calls to any Google API, and we could not make one with these scopes if we tried.
Google user data
We request four scopes, all read-only: webmasters.readonly for Search Console, analytics.readonly for Analytics, and openid and email so we can show you which Google account you connected. We use them to read the properties you select and render your own reporting back to you, and for nothing else.
Visibility's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means we do not sell Google user data, do not use it for advertising, and do not use it to train generalised AI or machine-learning models. No human at Visibility reads it except where you ask us to for support, where security requires it, or where the law compels it.
We don't watch anyone's conversations
The most reasonable question about this category, answered plainly: we do not observe what anyone asks an LLM. We have no access to any person's ChatGPT, Claude, Gemini or Perplexity history, and no way to obtain it.
Prompt monitoring works the other way round: you choose the questions, and we ask them ourselves on a schedule, then record what came back. Every result in your account is an answer to a question you wrote, not a conversation someone else had.
Why we collect it
To provide the product: syncing the data you connected, running the prompts you chose, producing the reports you open, and billing you for the plan you selected. We do not sell data, and we do not use your synced search data or prompt results to train models.
Aggregate, non-identifying usage data may be used to understand which features get used and to keep the service running. The only analytics tool we use for this is Google Analytics, and only on our public marketing pages — see Cookies below.
Legal bases for processing (UK/EEA)
Where UK or EU data protection law applies, we rely on:
Contract
Running the account you signed up for — syncing your data, running your prompts, producing your reports, and billing you.
Legitimate interests
Keeping the service secure and working, preventing abuse, and understanding which features get used. Balanced against your interests, and you can object.
Legal obligation
Accounting and tax records, and responding to lawful requests.
Consent
Marketing email. The box at signup is unticked by default and you can withdraw at any time.
Children
Visibility is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us and we'll delete it.
If the business changes hands
If we're involved in a merger, acquisition, financing or sale of assets, account data may transfer as part of that transaction. It would remain subject to this policy, and we'd tell account holders before anything material changed about how it's handled.
Do Not Track
Browsers send Do Not Track signals inconsistently and there is no agreed standard for honouring them, so we don't respond to them. What we can tell you is where analytics runs and where it does not: Google Analytics loads on our public marketing pages only. It is never loaded on the dashboard, on shared report links, or on password reset and email verification links — those URLs carry customer identifiers or act as credentials in themselves, and sending them to a third party is exactly the thing not to do.
Who else touches it
These are the services that handle data on our behalf in order to run the product:
Railway
Hosting for the application and the database.
Stripe
Subscription billing and card handling. Card details go to Stripe directly and never reach us.
Resend
Transactional email — verification, password reset and billing notices.
Google and Microsoft
Search Console, GA4 and Bing Webmaster Tools. Read-only, and only for the properties you connect.
AI answer monitoring
A third-party provider runs your tracked prompts against the LLMs and returns what they said. It receives the prompts you choose to track; it does not receive your account data or anything synced from Search Console, Bing or GA4.
International transfers.Our application and database are hosted in the United States, in Railway's US West (San Francisco) region. Where personal data moves out of the UK or EEA we rely on the UK and EU Standard Contractual Clauses.
When you connect an AI platform to your account
Visibility can be connected to an AI agent that speaks MCP, so you can ask questions about your own data in the place you already work. This is off until you turn it on, and you turn it on per client.
What you connect can read what you can read. That includes the figures we derive from Search Console and Analytics. A connected AI platform is read-only — it cannot change anything in your account, and it cannot reach your Google account, only the data already in ours.
Once it leaves for that AI platform, its provider's terms apply, not ours. We have no visibility into what happens to an answer after we return it, so connect only AI platforms you would be comfortable handing the same data to directly. Every connection is listed in your account settings and can be revoked there individually, which takes effect immediately.
How long we keep it
While you're a customer
For as long as the account is open, since the value of the product is the history.
After cancellation
90 days, then permanently deleted. The window exists so that coming back within a quarter doesn't mean starting your history from zero — not so we can hold onto it. If you'd rather it went sooner, ask and it will.
On deletion request
Within 30 days. Invoices and payment records are kept longer where tax and accounting law requires it; nothing else survives.
Your rights
Depending on where you are, you may have the right to access, correct, export or delete your data, and to object to certain processing. You can disconnect any data source yourself at any time, which revokes our access at the source rather than merely locally.
For anything else — including deleting your account, which is handled by hand today rather than by a button — write to [email protected]. We'll respond within 30 days. If you are in the UK or the EEA and think we have handled your data badly, you can also complain to your local supervisory authority — in the UK, the Information Commissioner's Office.
Cookies
A session cookie, which is strictly necessary. It holds a random token, is marked httpOnly and SameSite=Lax, and is sent over HTTPS only. It is what keeps you signed in; without it the product cannot work.
Google Analytics cookies on our marketing pages. These are not strictly necessary. They are not set on the dashboard, on shared reports, or on any link that carries a token. If you would rather they weren't set at all, your browser's cookie controls or any tracker blocker will stop them, and nothing about the product stops working.
Changes
If this policy changes materially we'll tell account holders by email rather than relying on a quietly updated date at the top of the page.
Questions about any of this go to [email protected]. See also Terms.
