Privacy Policy

Effective date: 27 July 2026

This Privacy Policy explains how GenAuthority ("we", "us", or "our") collects, uses, shares, and protects information when you use the GenAuthority platform (the "Service"). It should be read together with our Terms of Service.

1. Information We Collect

Account information

When you register, we collect your name, email address, and a hashed password (or authentication details if you sign in through a connected provider). For tenants, we collect the agency/workspace name, the roles of users, and invitations you send.

Brand & competitor data you enter

To provide the Service, we store the information you add: client brand names and websites, tracked prompts and keywords, competitor names, and the scan results, citations, sentiment, and recommendations generated for your brands.

Usage & analytics data

We collect information about how you interact with the Service — such as pages viewed, features used, device and browser type, approximate location derived from IP address, and event timestamps — through our product analytics and error-tracking tools.

Payment information

When you subscribe, payment is handled by our payment provider (Stripe). They collect and process your payment details directly; we receive limited information such as your subscription status, plan, and billing metadata. We do not store your full card number.

Communications

If you contact support, we keep your messages and our responses so we can help you and improve the Service.

Cookies & similar technologies

We use a small number of cookies and similar technologies that are necessary to sign you in, keep your session secure, and remember your preferences, plus first-party product analytics. See Cookies & Analytics below.

Future connectors

We plan to offer optional connectors (for example Google OAuth for Analytics, Search Console, and Business Profile). If you choose to connect such an account, we will store the associated authorisation tokens and the data you authorise us to read, solely to provide the connected feature.

2. How We Use Information

  • to provide, operate, maintain, and secure the Service;
  • to run visibility scans and generate reports, scores, and recommendations;
  • to process subscriptions, payments, and renewals;
  • to send transactional messages (for example sign-in, password reset, billing, and important service notices);
  • to provide customer support and respond to your requests;
  • to monitor, debug, and improve the Service, and to develop new features;
  • to detect, prevent, and address fraud, abuse, and security incidents;
  • to comply with legal obligations and enforce our Terms.

3. Legal Bases for Processing

Where data-protection laws such as the EU/UK GDPR apply, we rely on the following legal bases:

  • Contract — to provide the Service you have signed up for, including account management and billing.
  • Legitimate interests — to secure, analyse, and improve the Service, prevent abuse, and communicate about it, balanced against your rights.
  • Consent — where required, for example for certain optional analytics or connectors; you can withdraw consent at any time.
  • Legal obligation — to comply with applicable laws, tax, and accounting requirements.

4. Sub-processors & Third-Party Service Providers

We use trusted third parties to help us run the Service. Each processes data only as needed for its purpose, and we do not authorise them to use your personal data for their own purposes. Our current sub-processors are:

Sub-processorPurpose
StripePayment processing and subscription billing
ResendTransactional email delivery
PostHog (US region)Product analytics
Better StackError tracking, logs, and uptime monitoring
OpenAIAI-visibility scans across ChatGPT / OpenAI models
Google (Gemini)AI-visibility scans across Gemini and AI Overviews
Anthropic (Claude)AI-visibility scans across Claude models
PerplexityAI-visibility scans across Perplexity
DeepSeekAI-visibility scans across DeepSeek models
DataForSEOSearch and visibility data used to run scans
OVHCloud hosting / virtual private server (application & database)
CloudflareDNS, content delivery, and offsite encrypted backups
Google WorkspaceBusiness email and communications

We may add or replace sub-processors as the Service evolves; we will update this list when we do.

5. International Data Transfers

We and our sub-processors may process and store information in countries other than where you are located, including India, the United States, and the European Union. Where required, we rely on appropriate safeguards for such transfers (for example Standard Contractual Clauses or equivalent mechanisms).

6. Data Retention & Backups

We retain your information for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Encrypted database backups are stored offsite and rotated on a schedule; deleted data may persist in backups for a limited period before being overwritten.

7. Security

We take reasonable technical and organisational measures to protect information, including encryption of data in transit, hashed passwords, access controls and role-based permissions, encrypted offsite backups, and error and uptime monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a data breach that affects you, we will notify you as required by applicable law.

8. Your Rights

Depending on where you live (for example under the GDPR or the CCPA/CPRA), you may have the right to:

  • access the personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of your information;
  • export or receive a copy of your data in a portable format;
  • object to or restrict certain processing, and withdraw consent;
  • opt out of the "sale" or "sharing" of personal information — we do not sell your personal information;
  • not receive discriminatory treatment for exercising your rights.

To exercise any of these rights, email support@genauthority.com. We may need to verify your identity before acting, and we will respond within the time required by applicable law. If we process data on behalf of a tenant (as a processor), we will direct your request to that tenant.

9. Cookies & Analytics

We keep cookies to a minimum. We use strictly necessary cookies to sign you in and keep your session secure, and first-party product analytics (PostHog) to understand how the Service is used and to improve it. We do not use third-party advertising or cross-site tracking cookies. Our website shows a cookie notice on your first visit.

10. Children's Privacy

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18 (or under 16 where that is the applicable age of digital consent). If you believe a child has provided us information, contact us and we will delete it.

11. Data-Deletion Requests

You can request deletion of your account and associated personal data by emailing support@genauthority.com with the subject line "Data deletion request". We will delete or de-identify your data as described in Section 6, subject to any legal obligations that require us to retain certain records. Residual copies may remain in backups for a limited period before being overwritten.

12. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example by email or an in-app notice) and update the effective date at the top of this page. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact

For any privacy questions or requests, contact us at support@genauthority.com.