Privacy policy
What we collect, and what we don’t.
Last updated
The short version
- We collect the minimum needed to run the product: your email, the URLs you scan, and the brands and prompts you ask us to track.
- The free analyzer doesn’t store your IP address. It stores a salted hash of it, purely to enforce the daily scan limit.
- We never see your card details — Stripe handles payments end to end.
- We don’t sell your data, run ad tracking, or use your content to train AI models.
- Analytics cookies only load if you accept them. Everything works if you decline.
- Ask us to delete your account and everything tied to it goes with it.
A summary, not the agreement — the numbered sections below are the ones that count.
1 Who’s responsible for your data
Kwotable operates kwotable.io and is the data controller for the personal data described here. We’re based in Spain and this policy is written against the EU General Data Protection Regulation (GDPR).
For anything in this document — a question, a request, a complaint — write to hello@kwotable.io. A real person reads it.
2 What we collect
Things you give us. Your email address, used to create your account and sign you in. The URLs you submit to the analyzer. The brands, competitors and prompts you set up for visibility tracking. Anything you type into the app or send us by email.
Things we generate about your account. Analyzer results — the score, the category breakdown and the findings for each URL you scan. Tracking results — for every prompt run, whether each engine mentioned your brand, which URLs it cited, and the answer text it returned. Your plan, billing status and subscription history.
Things collected automatically.
- A hashed IP address. The free analyzer is rate-limited per day. To do that without keeping a log of who scanned what, we take your IP, add a secret salt and store only the resulting SHA-256 hash. The hash can’t be turned back into an address, and we never store the address itself.
- Server logs. Our hosting provider records standard request metadata (timestamps, paths, user agent, IP) for security and debugging. These are short-lived and we don’t mine them.
- Analytics. Google Analytics, and only if you accepted cookies. It tells us which pages get used and where people drop off. If you decline, no analytics script loads at all.
We don’t ask for your name, address, phone number or date of birth, and we don’t buy data about you from anyone.
3 Scanning without an account
The first analysis needs no signup. When you scan anonymously we store the URL, the result, and the salted hash of your IP for the daily limit. That record isn’t linked to a person, because we don’t have one to link it to.
Results are cached for a short window so re-scanning the same URL is instant and free. If you create an account later, past anonymous scans aren’t retroactively attached to it.
4 What we analyze about other people’s websites
The analyzer fetches publicly available pages — the same HTML, robots.txt and structured data any search engine crawler can read — and scores them. We don’t bypass logins, paywalls or access controls, and we respect the standard crawl directives.
If a page you own has been scanned and you want the cached result removed, write to us and we’ll delete it.
5 Why we’re allowed to use it
Under GDPR every use of personal data needs a legal basis. Ours are:
- Performing our contract
- Running your account, storing your scans, executing tracking runs, sending reports and taking payment. Without this data there’s no product to deliver.
- Legitimate interests
- Rate limiting, fraud and abuse prevention, security monitoring, and understanding aggregate product usage — balanced against your privacy, which is why the rate-limit signal is a hash and not an address.
- Your consent
- Analytics cookies and any marketing email. You can withdraw either at any time, and withdrawal is as easy as giving it.
- Legal obligation
- Keeping invoices and tax records for as long as accounting law requires.
7 Who else processes your data
We don’t sell or rent personal data. We do rely on a small set of providers to run the service, each bound by a data processing agreement and each given only what they need:
- Supabase
- Database and authentication — your account, scans, prompts and tracking history live here.
- Vercel
- Hosting and content delivery. Sees request metadata as traffic passes through.
- Stripe
- Payments and subscription management. Card details go straight from your browser to Stripe; we only ever store your customer id, plan and subscription status.
- Resend
- Transactional email — sign-in links, loss alerts and monthly reports. Receives your email address and the contents of those messages.
- Google Analytics
- Usage analytics, only if you consented.
- Answer engines
- OpenAI, Anthropic, Perplexity and Google receive the prompts you configure, in order to answer them. They don’t receive your email or account details. Anthropic also receives your URL when you use the automatic prompt generator.
Some of these are based outside the European Economic Area. Where that’s the case, transfers rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses.
We’d also disclose data where the law genuinely requires it, or to establish or defend a legal claim. If Kwotable is ever sold or merged, your data would move with it and you’d be told before that happened.
8 How long we keep it
- Account data — for as long as your account exists. Delete the account and it goes.
- Tracking history — kept for the life of the account, because the whole point is watching visibility move over time.
- Anonymous scan results — cached briefly to serve repeat scans, then aged out.
- Hashed IPs — kept only as long as the daily rate-limit window needs them.
- Invoices and payment records — for as long as tax and accounting law requires, typically several years. This is the one category we can’t delete on request.
- Encrypted backups — deleted data can persist in backups for up to 30 days before those rotate out.
9 Your rights
You can ask us to:
- give you a copy of the personal data we hold about you, in a portable format;
- correct anything that’s wrong;
- delete your account and the data tied to it;
- restrict or object to a particular use, including anything we do under legitimate interests;
- withdraw a consent you previously gave, such as analytics cookies or marketing email.
Most of this you can do yourself from your account settings. For the rest, email hello@kwotable.io — we’ll respond within 30 days, and we won’t charge you or make you explain yourself.
If you think we’ve handled your data badly, tell us first and we’ll try to fix it. You also have the right to complain directly to the Spanish Data Protection Agency (AEPD) or to the supervisory authority in your own country.
10 Security
Everything travels over TLS. API keys and service credentials are server-side only and never reach the browser. Database access is protected by row-level security so one account can’t read another’s data. Sign-in is passwordless, so there’s no password of yours for us to leak.
No system is perfectly secure, and we won’t pretend otherwise. If a breach ever affects your personal data, we’ll notify you and the relevant authority without undue delay.
11 Children
Kwotable is a business tool and isn’t directed at children. We don’t knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we’ll delete it.
12 Changes to this policy
When this policy changes we update the date at the top. If a change materially affects how we use your data, we’ll email account holders before it takes effect rather than quietly editing the page.
13 Contact
Privacy questions, data requests, or anything on this page you think is wrong: hello@kwotable.io.
Changed your mind about analytics cookies?