Privacy

Last updated 26 August 2026

What Visibility collects, why, who else touches it, and what it never receives. Written to be read rather than to be survived.

Who we are

Visibility is operated by Relevance Com, a company registered in Missouri, United States, at 4013 Frontgate Dr, Suite 104, Columbia, MO 65203.

Our role under data protection law depends on which data is in question, so it is worth stating both. For your account, billing and support data we are the controller — we decide what is collected and why. For the search and analytics data we pull from the accounts you connect, we are a processor acting on your instructions — you choose which properties to connect and can disconnect them at any time, and we use that data only to produce your reporting.

What we collect

Account

Your email address and a bcrypt hash of your password. Your agency name and white-label settings if you set them.

Connections

OAuth tokens for Google (read-only) and your Bing Webmaster API key, encrypted at rest. Which property or account you selected.

Synced search data

Aggregated performance data from Search Console, Bing Webmaster Tools and GA4 — queries, pages, clicks, impressions, positions, sessions, conversions.

Prompts and answers

The prompts you choose to track, the answers LLMs gave, and the pages those answers cited.

Billing

A Stripe customer id, subscription id, plan and prompt allowance. Not your card details — see below.

Operational logs

Server logs and sync outcomes, kept to diagnose failures.

What we never collect

Card numbers.Payment details are entered on Stripe's own pages and never reach our servers or logs.

Personal data about your website's visitors. The reporting APIs we read return aggregated metrics. We do not receive user-level events, and there is no script to install — Visibility never runs code on your site, so it cannot see your visitors at all.

Write access to anything. Every scope we request is read-only, and the full list is short: webmasters.readonly and analytics.readonly for Google, plus openid so we can show you which account you connected. We make no write calls to any Google API, and we could not make one with these scopes if we tried.

Google user data

We request four scopes, all read-only: webmasters.readonly for Search Console, analytics.readonly for Analytics, and openid and email so we can show you which Google account you connected. We use them to read the properties you select and render your own reporting back to you, and for nothing else.

Visibility's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means we do not sell Google user data, do not use it for advertising, and do not use it to train generalised AI or machine-learning models. No human at Visibility reads it except where you ask us to for support, where security requires it, or where the law compels it.

We don't watch anyone's conversations

The most reasonable question about this category, answered plainly: we do not observe what anyone asks an LLM. We have no access to any person's ChatGPT, Claude, Gemini or Perplexity history, and no way to obtain it.

Prompt monitoring works the other way round: you choose the questions, and we ask them ourselves on a schedule, then record what came back. Every result in your account is an answer to a question you wrote, not a conversation someone else had.

Why we collect it

To provide the product: syncing the data you connected, running the prompts you chose, producing the reports you open, and billing you for the plan you selected. We do not sell data, and we do not use your synced search data or prompt results to train models.

Aggregate, non-identifying usage data may be used to understand which features get used and to keep the service running. The only analytics tool we use for this is Google Analytics, and only on our public marketing pages — see Cookies below.

Legal bases for processing (UK/EEA)

Where UK or EU data protection law applies, we rely on:

Contract

Running the account you signed up for — syncing your data, running your prompts, producing your reports, and billing you.

Legitimate interests

Keeping the service secure and working, preventing abuse, and understanding which features get used. Balanced against your interests, and you can object.

Legal obligation

Accounting and tax records, and responding to lawful requests.

Consent

Marketing email. The box at signup is unticked by default and you can withdraw at any time.

Children

Visibility is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us and we'll delete it.

If the business changes hands

If we're involved in a merger, acquisition, financing or sale of assets, account data may transfer as part of that transaction. It would remain subject to this policy, and we'd tell account holders before anything material changed about how it's handled.

Do Not Track

Browsers send Do Not Track signals inconsistently and there is no agreed standard for honouring them, so we don't respond to them. What we can tell you is where analytics runs and where it does not: Google Analytics loads on our public marketing pages only. It is never loaded on the dashboard, on shared report links, or on password reset and email verification links — those URLs carry customer identifiers or act as credentials in themselves, and sending them to a third party is exactly the thing not to do.

Who else touches it

These are the services that handle data on our behalf in order to run the product:

Railway

Hosting for the application and the database.

Stripe

Subscription billing and card handling. Card details go to Stripe directly and never reach us.

Resend

Transactional email — verification, password reset and billing notices.

Google and Microsoft

Search Console, GA4 and Bing Webmaster Tools. Read-only, and only for the properties you connect.

AI answer monitoring

A third-party provider runs your tracked prompts against the LLMs and returns what they said. It receives the prompts you choose to track; it does not receive your account data or anything synced from Search Console, Bing or GA4.

International transfers.Our application and database are hosted in the United States, in Railway's US West (San Francisco) region. Where personal data moves out of the UK or EEA we rely on the UK and EU Standard Contractual Clauses.

When you connect an AI platform to your account

Visibility can be connected to an AI agent that speaks MCP, so you can ask questions about your own data in the place you already work. This is off until you turn it on, and you turn it on per client.

What you connect can read what you can read. That includes the figures we derive from Search Console and Analytics. A connected AI platform is read-only — it cannot change anything in your account, and it cannot reach your Google account, only the data already in ours.

Once it leaves for that AI platform, its provider's terms apply, not ours. We have no visibility into what happens to an answer after we return it, so connect only AI platforms you would be comfortable handing the same data to directly. Every connection is listed in your account settings and can be revoked there individually, which takes effect immediately.

How long we keep it

While you're a customer

For as long as the account is open, since the value of the product is the history.

After cancellation

90 days, then permanently deleted. The window exists so that coming back within a quarter doesn't mean starting your history from zero — not so we can hold onto it. If you'd rather it went sooner, ask and it will.

On deletion request

Within 30 days. Invoices and payment records are kept longer where tax and accounting law requires it; nothing else survives.

Your rights

Depending on where you are, you may have the right to access, correct, export or delete your data, and to object to certain processing. You can disconnect any data source yourself at any time, which revokes our access at the source rather than merely locally.

For anything else — including deleting your account, which is handled by hand today rather than by a button — write to [email protected]. We'll respond within 30 days. If you are in the UK or the EEA and think we have handled your data badly, you can also complain to your local supervisory authority — in the UK, the Information Commissioner's Office.

Cookies

A session cookie, which is strictly necessary. It holds a random token, is marked httpOnly and SameSite=Lax, and is sent over HTTPS only. It is what keeps you signed in; without it the product cannot work.

Google Analytics cookies on our marketing pages. These are not strictly necessary. They are not set on the dashboard, on shared reports, or on any link that carries a token. If you would rather they weren't set at all, your browser's cookie controls or any tracker blocker will stop them, and nothing about the product stops working.

Changes

If this policy changes materially we'll tell account holders by email rather than relying on a quietly updated date at the top of the page.

Questions about any of this go to [email protected]. See also Terms.