Privacy Policy
Effective Date: September 2026 · Compliant with GDPR & CCPA/CPRA
Privacy Highlights (TL;DR)
- 1.We Never Sell Your Data: Your corporate email and audit inputs are never rented, bartered, or sold to data brokers or advertising networks.
- 2.No AI Model Training on User Data: Your confidential brand inputs are not ingested to train third-party foundation models.
- 3.Single Secure Cookie: We utilize only one encrypted, signed session cookie (
open_geo_lead) strictly to prevent abuse and manage trial quotas. No cross-site ad trackers. - 4.Full GDPR/CCPA Rights: Request complete data deletion or export at any time via support@geofn.com. Requests resolved within 48 hours.
1. Information We Collect & Collection Methods
open-geo collects data only to provide accurate search engine diagnostic audits, prevent platform abuse, and deliver customer support:
A. Public Query Inputs
When you initiate an inspection, you provide a target domain (e.g. notion.so) and a commercial search query (e.g. best knowledge management software). These inputs are processed in real-time against public search engines.
B. Corporate Contact Information
When you elect to unlock deep audit probes, we collect your business email address. We perform client-side and server-side validation to filter temporary/disposable domains.
C. Automated Security Telemetry
Our Cloudflare edge network automatically logs client IP addresses, browser headers, and timestamp records strictly for DDoS protection, rate-limit enforcement, and bot mitigation.
2. How We Use Data & 24h Snapshot Cache
- Audit Execution: To query public search result interfaces (Google AI Overview, SERP listings) and extract neural entity citations and competitor visibility metrics.
- 24-Hour Snapshot Cache: Generated audit results and public domain health scores may be cached in memory for up to 24 hours. This minimizes redundant energy consumption, reduces external API queries, and provides near-instantaneous benchmarking across recurring queries.
- Customer Communications: If you supply your email, we may send your diagnostic audit link, urgent security updates regarding AI crawler blockages, and direct responses to your support inquiries.
3. Cookie Transparency & Anti-Abuse Tokens
We reject predatory third-party advertising trackers. Our application utilizes exactly one first-party essential cookie:
| Cookie Name | Security Flags | Duration | Purpose |
|---|---|---|---|
| open_geo_lead | HttpOnly, Secure, SameSite=Lax | 30 Days | HMAC-SHA256 signed stateless token holding verified email status to unlock the 3 free trial probe quota. |
4. Sub-processors & Service Infrastructure
We partner with enterprise-grade infrastructure providers to deliver high-availability global edge computing:
| Provider | Role & Activity | Data Location |
|---|---|---|
| Cloudflare, Inc. | Edge computing (Workers), DDoS shielding, and Email Routing (support@geofn.com) | Global Anycast Edge |
| SERP & Neural Extractors | Aggregating public search snapshots and zero-retention entity extraction | US / Global (Stateless processing) |
| Internal Alert Webhooks | Real-time operational lead notifications to team members | Encrypted in-transit |
5. Data Protection & Security Standards
We implement industry standard physical, administrative, and technical safeguards:
- Encryption in Transit: All data transmitted between your browser and our edge network is enforced via TLS 1.3 / HTTPS with automated HSTS.
- Stateless Authentication: Sensitive email authorization is cryptographically signed with HMAC-SHA256, eliminating server-side session database exposure risks.
- Zero Open Ports: Underlying compute runs in isolated V8 sandboxes on the Cloudflare Workers runtime.
6. Your Privacy Rights (GDPR & CCPA/CPRA)
Regardless of your geographical location, we extend comprehensive data sovereignty rights:
- Right to Access & Portability: You may request a copy of the personal data associated with your email address.
- Right to Erasure ("Right to be Forgotten"): You may request immediate deletion of your email address and any associated audit history from our internal records.
- Right to Opt-Out of Sale: We do NOT sell, lease, or monetize your personal data. You are permanently opted out by default.
- Right to Non-Discrimination: We will never degrade service quality or alter pricing because you exercise your lawful privacy rights.
7. Children's Privacy
open-geo is a professional developer utility intended strictly for individuals aged 18 and older. We do not knowingly solicit or collect personal information from children under 13 years of age.
8. Data Requests & Contact Information
To submit an erasure request, raise a privacy concern, or contact our Data Protection Officer (DPO), please email our dedicated security inbox:
Direct response SLA: Within 48 business hours