Privacy Policy
Last updated: August 16, 2026
1. Who we are
This Privacy Policy explains how Discoverably LLC (“Discoverably,” “we,” “us,” or “our”), a limited liability company organized under the laws of the State of Maryland, USA, collects, uses, discloses, and protects personal information in connection with our website at discoverably.com (the “Site”), our Android application distributed through Google Play (the “App”), and our generative-engine-optimization (“GEO”) analytics service that measures how brands appear across AI answer engines (the “Service”). The App is a wrapper around the Service, so everything this Policy says about the Service applies when you use it through the App.
For the purposes of the EU/UK General Data Protection Regulation, Discoverably is the data controller of the personal information described below, except where we act as a processor on behalf of our customers (see Section 11).
Contact:
- Privacy inquiries: privacy@discoverably.com
- Mailing address: Discoverably LLC, 306 W Redwood St STE 201, Baltimore, Maryland 21201, USA
2. Scope
This Policy applies to personal information we process about: (a) visitors to our Site and our free onboarding report funnel; (b) customers and their authorized users of the paid dashboard, whether they reach it through a web browser or through our App; and (c) prospects who interact with our marketing. It does not apply to third-party websites, AI answer engines, or services that we link to or measure, which have their own privacy practices.
3. Information we collect
(a) Information you provide to us.
- Onboarding report requests: your business domain/website and email address, and any brand, competitor, industry, or location details you confirm so we can generate and email you a free AI-visibility report.
- Lead forms on advertising platforms: if you ask for a free report through a form we run on Facebook or Instagram (Meta Instant Forms) or on LinkedIn (LinkedIn Lead Gen Forms), the platform passes us the details you submit — your first name, work email address, and company website — together with the platform’s own lead identifier and the campaign, ad, and form identifiers. The form shows you this Policy before you submit it.
- Account and billing: name, work email, account credentials, and the configuration you select (engines, prompts, cadence). Payment card details are collected and processed directly by our payment processor (Stripe); we do not store full card numbers. At checkout Stripe also collects your billing address (city, state/region, postal code, and country), which we use for billing records and for advertising conversion matching as described in Section 6.
- Communications: information you include when you contact support, request sales/enterprise inquiries, or respond to surveys.
(b) Information collected automatically. When you use the Site, App, or
Service, we and our analytics/advertising providers may collect: IP address, device and
browser type, operating system, referring/exit pages, pages viewed and
interactions (including, where session-replay analytics is enabled, recordings
of your interactions with a page, such as mouse movements, clicks, and
scrolling), approximate location (derived from IP), and cookie/identifier data
including advertising click identifiers (e.g., gclid, gbraid, wbraid,
fbclid, li_fat_id, and OpenAI ad references) and analytics identifiers. See
Section 5 (Cookies) and our cookie banner for the categories and your controls.
When we email you a link to a free report, we record whether and when the report page was opened, how many times, and how the link was reached, so we know it reached you and can follow up appropriately.
If you turn on push notifications for your account — for example in our App or in our installable web app — we also store a push subscription for that browser or device: the delivery endpoint URL issued by your browser’s push service, the message encryption keys that accompany it, your device platform and full browser user-agent string, and your device’s time zone, so we can send the notification and diagnose delivery failures.
(c) Information from third parties.
- Brand enrichment: publicly available brand metadata (logo, industry, description, competitors) from our enrichment provider (Brandfetch) when you enter a domain.
- AI answer engines and search results: the Service collects how brands — including yours and competitors you track — are mentioned, ranked, or used as a source in responses from AI answer engines and AI-powered search surfaces, via our data vendor. This may incidentally include personal information that those engines themselves surface in public answers.
- Advertising and analytics partners: measurement and attribution data from the partners listed in Section 7.
We do not intentionally collect special categories of data (e.g., health, biometric, precise geolocation) or the personal information of children.
4. How we use information, and our legal bases
| Purpose | GDPR legal basis |
|---|---|
| Provide, operate, and secure the Service and Site | Performance of a contract; legitimate interests |
| Generate and deliver your free onboarding report, and record whether the emailed report was opened | Performance of a contract / pre-contract steps; consent for the report email; legitimate interests |
| Prepare and email the free report you asked for through an advertising lead form, follow up about what it found, and tell you about Discoverably’s paid monitoring | Performance of a contract / pre-contract steps; legitimate interests (in opt-out jurisdictions you can stop the follow-up at any time — reply to any of those emails or use its opt-out link) |
| Process payments, manage subscriptions, prevent fraud | Performance of a contract; legal obligation; legitimate interests |
| Measure and improve the Service (product analytics) | Consent (where required); legitimate interests |
| Marketing and advertising — measurement, attribution, and matched-audience lists (Section 6) | Consent (cookies/ads where required); opt-out in US states (Sections 5 and 10) |
| Customer support and service communications | Performance of a contract; legitimate interests |
| Comply with law, enforce terms, protect rights | Legal obligation; legitimate interests |
We rely on consent for non-essential cookies, advertising, and analytics where required (EU/EEA/UK/Switzerland and other consent jurisdictions); you can withdraw consent at any time via the “Your Privacy Choices” link in our footer.
If you give us your details through an advertising lead form, we use them only for the report you asked for and the follow-up described above. We do not add you to a newsletter or to any unrelated mailing, and we do not add you to an advertising audience list unless you become a paying customer (Section 6).
We do not use your confidential customer data, prompts, or report content to train third-party generative AI models, and we do not sell it.
5. Cookies and tracking technologies
We use strictly necessary, functional, analytics, and advertising cookies and similar technologies. How consent is handled depends on your location:
- Where prior opt-in is required (EEA, UK, Switzerland): we show a consent banner on your first visit, and no non-essential cookies or tags load until you opt in. You can Accept all, Reject all non-essential cookies, or Manage choices at a category level.
- In opt-out jurisdictions (e.g., most US states): analytics, session replay, and advertising cookies may run by default, and you can opt out at any time via the footer “Your Privacy Choices” link — which opens the same category-level controls — rather than through an up-front banner.
Either way, you can change your choice at any time via “Your Privacy Choices”, we honor Google Consent Mode v2, and we recognize browser-based universal opt-out signals (e.g., Global Privacy Control) as a valid opt-out of targeted advertising and “sale”/“sharing” where applicable. For details on each cookie category, see the preferences panel.
Inside our App, these technologies run in your device’s Chrome browser and share its storage, because the App displays the Service through Chrome rather than through a separate in-app browser. A choice you make in one place therefore applies in the other on the same device.
6. How we share information
We do not sell your personal information for money. We disclose personal information only as follows:
- Service providers / processors that help us run the Service under contract (see Section 7).
- Advertising and analytics partners, where you have consented, for measurement and attribution (Section 7). Some of these disclosures may be considered “sharing” for targeted advertising or a “sale” under certain US state laws; you can opt out (Sections 5 and 10).
- Matched-audience lists. If you are or have been a paying customer, we may share a one-way hashed (SHA-256) version of the email address on your account with Google, Meta, and LinkedIn to build audience lists that we use to (a) stop showing our new-customer advertising to current customers and (b) show former customers offers to return. The partners are contractually restricted from using these lists for their own purposes, and we keep list membership in sync with billing status — when you are removed (for example because you opt out or delete your account) we instruct the partner to delete your hashed identifier from the list. This disclosure may be considered “sharing” for targeted advertising or a “sale” under certain US state laws; you can opt out at any time (Sections 5 and 10), we always honor Global Privacy Control for it, and in consent jurisdictions (EU/EEA/UK/Switzerland) we only do it with your consent.
- Professional advisors (lawyers, accountants, auditors) under confidentiality.
- Legal / safety: to comply with law, legal process, or government requests; to enforce our Terms; or to protect the rights, property, or safety of Discoverably, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
Hashed data for ad-conversion measurement
For the two conversion events below, we may share hashed details with our advertising partners, solely so each partner can match the conversion to an ad interaction on its own platform. Google calls this “Enhanced Conversions” (for the free-report email, “Enhanced Conversions for Leads”); Meta and LinkedIn accept it through their conversions APIs as “advanced matching.” A hash is a one-way fingerprint of a value, computed here with SHA-256: each partner compares it against hashes computed from its own users’ contact details, so a match tells the partner that one of its existing users converted, and an unmatched hash identifies no one. We use this only to measure and optimize our advertising, and for no other purpose.
- Free-report email. If you ask us to email you a copy of your free report, we may share a hash of the email address you provide (never the address itself) with Google, Meta, and LinkedIn.
- Purchase. When a customer completes checkout, we may share with Google and Meta: a hash of the billing email address, a hash of the billing name, and coarse billing-address components from checkout (city, state/region, postal code, and country), hashed wherever the platform’s conversion API accepts hashes (postal code and country may be sent in normalized plain form where the API requires it), together with the platform’s own click identifier for the ad interaction. LinkedIn receives the hashed email only. We never send the plain name or email address, a phone number, or the street address.
Either disclosure happens only if advertising is enabled for you under Section 5 (that means opt-in consent where required, and no opt-out elsewhere) and your browser is not sending a Global Privacy Control signal. If you have declined or opted out of advertising, or a GPC signal is present, we share none of it. You can change your choice at any time via the footer “Your Privacy Choices” link.
7. Service providers and partners (subprocessors)
We use reputable third parties to provide the Service. The current categories and providers include (subject to change; an up-to-date list is available on request at privacy@discoverably.com):
| Category | Provider(s) | Purpose |
|---|---|---|
| Hosting / compute | Vercel; Cloudflare | Application hosting, CDN, bot/abuse protection. Vercel additionally routes our AI model requests through its AI Gateway, so it processes the content of those requests and responses |
| Database / auth / backend | Supabase | Data storage, authentication, edge functions |
| AI-engine data vendor | Available on request | Querying AI answer engines for visibility data |
| Brand enrichment | Brandfetch | Public brand metadata during onboarding |
| AI processing | Anthropic; Perplexity | Summarization, sentiment, recommendation generation, and web-grounded onboarding setup |
| Payments | Stripe | Subscription billing and payment processing |
| Resend | Transactional and report emails | |
| Document rendering | Doppio | Server-side PDF generation of your reports |
| Product/web analytics | Google Analytics 4; Cloudflare Web Analytics | Usage measurement — GA4 is consent-gated in the EU/UK/Switzerland and opt-out elsewhere (see Section 5); Cloudflare Web Analytics is cookieless (no cookies or device storage), so it runs without consent |
| Product analytics / session replay | Microsoft Clarity | Usage measurement, heatmaps, and session replay (consent-gated in the EU/UK/Switzerland; opt-out elsewhere — see Section 5) |
| Advertising measurement and audiences | Google Ads, Meta, LinkedIn, OpenAI | Ad attribution/conversion (consent-gated in the EU/UK/Switzerland; opt-out elsewhere — see Section 5). Meta and LinkedIn also host the lead forms described in Section 3(a) and pass us the details you submit there, keeping their own copy of your submission under their own policies. Global Privacy Control is always honored for advertising and is not overridden by accepting all. Google, Meta, and LinkedIn may also receive the hashed conversion data described in Section 6, and the hashed customer email addresses used there for matched-audience lists |
| Error monitoring | Sentry | Diagnostics and reliability (privacy-scrubbed). When an application error occurs, we may also capture a masked recording (session replay) of the affected session to diagnose it — gated on the same analytics choice as Google Analytics/Clarity above (consent-gated in the EU/UK/Switzerland; opt-out elsewhere — see Section 5; not recorded once you decline analytics). Error reports without a replay are collected regardless of your analytics choice |
| Secrets management | Infisical | Secure configuration |
Providers are bound by contract to process personal information only on our instructions and to protect it appropriately.
8. International data transfers
We are based in the United States and our providers may process data in the US and other countries. Where we transfer personal information from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum / Swiss addendum, as applicable). You may request a copy of the relevant safeguards at privacy@discoverably.com.
9. Data retention
We retain personal information only for as long as necessary for the purposes described in this Policy, then delete or anonymize it. Indicative periods:
- Onboarding report data: free onboarding reports are deleted 30 days after they are generated, including any email address you gave us to receive them, unless the report is used to open an account — in which case it is retained with the account.
- Report activity: when we email you a report link, the summary record that it was opened — whether it was opened, when it was first and most recently opened, and how many times — is kept with the report and deleted with it: 30 days for a free report that is not used to open an account, or, if the report is used to open an account, for the life of that account. The underlying log of each individual opening, including how the page was reached, is deleted within 180 days.
- AI answer data: raw engine responses and their sources are deleted approximately 14 months after collection; the aggregated visibility metrics derived from them are retained for the life of the account.
- Account and billing records: for the life of the account plus the period required by tax, accounting, and legal obligations (typically up to 7 years).
- Consent records: retained as long as needed to demonstrate compliance.
- Cookie/analytics identifiers: our own consent cookie records your choices for 182 days (about six months), after which we ask again. Analytics and advertising cookies are set by the providers listed in Section 7 and expire on their own schedules, from the end of a browsing session up to about two years. If you opt out or withdraw consent we do not simply record the preference — we actively delete the analytics and advertising cookies we control.
- Ad-form lead records: if you ask for a report through a lead form on Facebook, Instagram, or LinkedIn and do not become a customer, we delete the lead record — one-way hashes of the contact details you submitted, your company website, and the platform’s campaign, ad, form, and lead identifiers — 180 days after we receive it from the platform; if you do become a customer, it is retained with your account. The advertising platform also keeps its own copy of what you submitted under its own policy (on LinkedIn, currently about 90 days). Your name and email address are not stored in readable form in our databases — there we keep only the one-way hashes. The readable details stay in the lead export we download from the platform and in the working files we use to send the report and follow up (a spreadsheet and our own email records), and we delete those working copies within 180 days of your submission — sooner, at the end of the advertising test, for requests we do not follow up on.
- Advertising measurement records: the record that a purchase was reported to our advertising partners — our payment processor’s event and transaction reference numbers, a one-way hash of the email address the report was sent with, your IP address and browser user-agent, coarse billing region and postal code, and the advertising click identifiers that brought you to us — is deleted with your account when that hash still matches the address on it, and otherwise deleted automatically on a rolling schedule.
- Advertising audience lists: the hashed email addresses we share for matched audiences (Section 6) are kept in sync with billing status on a rolling re-upload cadence; we instruct the partner to remove your hashed identifier when you leave the relevant list, opt out, or delete your account, after which the partner deletes it under its own published schedule.
- Push notification subscriptions: retained only while notifications are enabled for that browser or device; deleted when you turn notifications off, when the device’s push service reports the subscription gone, or when your account is deleted.
10. Your privacy rights
Depending on where you live, you may have some or all of the following rights: access, correction, deletion, portability, to opt out of targeted advertising, the “sale”/“sharing” of personal information, and certain profiling; to restrict or object to processing; and to withdraw consent. We do not discriminate against you for exercising these rights.
How to exercise: email privacy@discoverably.com or use the in-app account
controls and the footer “Your Privacy Choices” link. To delete your account and
its data, sign in and go to app.discoverably.com/delete-account. We will verify
your request as required by law. You may use an authorized agent. If we deny a request, you
may appeal by replying to our decision; if you remain unsatisfied, you may
contact your state Attorney General.
EEA/UK/Switzerland: you also have the right to lodge a complaint with your local supervisory authority.
11. Maryland and other US state disclosures
Maryland (MODPA). If you are a Maryland resident, you have the rights listed in Section 10. Consistent with the Maryland Online Data Privacy Act, we practice data minimization (we limit collection to what is reasonably necessary for the purposes disclosed), we do not sell sensitive data, we do not process sensitive data without consent, and we honor universal opt-out mechanisms.
California (CCPA/CPRA). California residents have rights to know, delete, correct, and opt out of sale/sharing and certain targeted advertising, and to limit the use of sensitive personal information. We do not sell personal information for money; certain analytics/advertising cookie activity, and the hashed-data disclosures described in Section 6, may constitute “sharing” for cross-context behavioral advertising. You can opt out via the footer “Your Privacy Choices” link (Section 5) or a Global Privacy Control signal, both of which also stop the hashed-data disclosures.
Other states (e.g., Colorado, Connecticut, Virginia, and similar): residents have comparable rights, exercisable as described in Section 10.
Categories collected/disclosed in the last 12 months: identifiers (e.g., email, SHA-256 hashes of your email and billing name, IP), customer records (billing name and address, including the coarse billing-address components listed in Section 6: city, state/region, postal code, country), commercial information (subscription/billing), internet activity (usage/analytics), geolocation data (approximate location derived from IP, and the billing region and postal code described above), and inferences, disclosed to the provider categories in Section 7 for the purposes in Section 4. The hashed identifiers and coarse billing-address components are disclosed to Google, Meta, and LinkedIn (LinkedIn: hashed email only) for ad-conversion measurement, and the hashed email address of a paying customer is also disclosed to those partners for the matched-audience lists described in Section 6; these disclosures are consent-gated, honor Global Privacy Control, and stop when you opt out via the footer “Your Privacy Choices” link (Section 5).
Processor role. When we process personal information contained in a customer’s account, configuration, or reports on the customer’s behalf, the customer is the controller/business and we act as the processor/service provider; such individuals should direct rights requests to the relevant customer, and we will assist as required by our customer agreement.
12. Security
We maintain administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, row-level security, secrets management, and least-privilege practices. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Children’s privacy
The Service is intended for businesses and is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact privacy@discoverably.com and we will delete it.
14. Third-party links and AI engines
The Site, App, and Service reference third-party websites, search engines, and AI answer engines that we do not control. We are not responsible for their content or privacy practices.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice. Material changes affecting consent will be handled through the cookie banner’s revision mechanism.
16. Contact us
Questions or requests: privacy@discoverably.com or Discoverably LLC, 306 W Redwood St STE 201, Baltimore, Maryland 21201, USA.
Discoverably is established in the United States and does not target its services to, or monitor the behaviour of, individuals in the EEA or the United Kingdom. On that basis we have determined that we are not required to appoint a representative under Article 27 of the EU or UK GDPR. We will update this policy if that changes.