Privacy Policy
Last updated: 2026-09-14
This Privacy Policy explains what personal information Vedayati ("we", "us") collects, why, and what choices you have about it.
1. What we collect
- Account information: your email address (used for sign-in and account-related email).
- Site data you submit: the URLs of sites you ask us to audit, and the persona you select (Owner/Operator or Practitioner) to tailor how results are shown.
- Scan results: the content we fetch from pages you submit for scanning, and the findings/scores we compute from it.
- Billing information: handled directly by Stripe — we receive your subscription status and plan, but never your card number.
- Usage data: basic technical logs (e.g. request logs) needed to operate and secure the Service.
We do not currently use advertising or analytics cookies, and the only cookies the Service sets are strictly necessary ones needed to keep you signed in (see Section 6).
2. How we use it
- To provide the Service: run the scans you request and show you the results.
- To operate your account: authentication, plan/quota enforcement, and account-related communication.
- To process payments, through Stripe, for paid plans.
- To improve the Service and diagnose problems.
- To comply with legal obligations.
3. Who we share it with
We don't sell your personal information. We share data with the following categories of service providers, only as needed to operate the Service:
- Supabase — database hosting and authentication. Your account data and scan results are stored here.
- Stripe — payment processing for paid plans. Stripe has its own privacy policy governing the payment information it processes directly.
- Vercel — application hosting.
- DataForSEO — on paid plans, runs the citation-testing queries against AI answer engines; may process the queries and page content involved.
- AI model providers (accessed through an AI infrastructure gateway) — used for AI-assisted analysis of page content. Content submitted for analysis may be processed by these providers’ models.
We may also disclose information if required by law, or to protect the rights, property, or safety of Vedayati, our users, or others.
4. Data retention
We retain scan history indefinitely by design, so you can track how a site changes over time — this is a core part of the Service on paid plans. If you delete your account or a site, we delete the associated data within a reasonable period, except where we’re required to retain it (for example, billing records for tax purposes). You can request deletion at any time — see Section 8.
5. Security
We use industry-standard measures to protect your data, including encryption in transit and database-level access controls that ensure your data is only ever readable by your own account (Row Level Security). No method of transmission or storage is 100% secure, and we can’t guarantee absolute security.
6. Cookies
We currently use only strictly-necessary cookies: ones required to keep you signed in and to enforce the session length you choose at sign-in (an optional "stay signed in" checkbox). We do not currently use advertising, analytics, or cross-site tracking cookies. If that changes, we'll update this policy and add a cookie consent mechanism where required by law before doing so.
7. Your rights
Depending on where you live, you may have rights over your personal information, including:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate information.
- Deletion — ask us to delete your account and associated data.
- Portability — request your data in a portable format.
- Objection/restriction — object to or ask us to restrict certain processing.
To exercise any of these rights, contact us at kevin@apexmillennia.llc. We don't currently have a fully self-service deletion flow — requests are handled manually and we aim to respond within a reasonable time, and in any case within any timeframe required by applicable law.
8. European users (GDPR)
If you’re in the European Economic Area or UK, we process your personal information under the following legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (operating and improving the Service), and consent where applicable. You have the rights described in Section 7, plus the right to lodge a complaint with your local data protection authority. Some of our service providers are located outside the EEA/UK; where that’s the case, we rely on appropriate safeguards (such as those providers’ own standard contractual clauses) for the transfer.
9. California users (CCPA/CPRA)
If you’re a California resident, you have the right to know what personal information we collect (see Section 1), request deletion (Section 7), correct inaccurate information, and opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined under California law. We won’t discriminate against you for exercising any of these rights. To exercise a California privacy right, contact us at kevin@apexmillennia.llc.
10. Children’s privacy
The Service isn't directed at children, and we don't knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we'll delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We'll make reasonable efforts to notify you of material changes before they take effect.
12. Contact
Questions about this policy, or want to exercise a privacy right? Contact us at kevin@apexmillennia.llc.