Data Policy
Version 1.0 · Effective August 2026 · GeoScript, Inc.
The plain-English version
- The Script collects AI search signals from monitored websites — not visitor names, emails, or payment data.
- You (the customer) control which websites are monitored. Remove the Script and collection stops immediately.
- Signal Data collected by the Script is owned by GeoScript. This is what powers the dataset that makes the product work.
- We never sell your personal account data or your business data to anyone.
- EU customers can request a Data Processing Agreement. We use Standard Contractual Clauses for cross-border transfers.
The sections below contain the full legal detail. If anything conflicts between this summary and the full text, the full text governs.
1. Scope of This Policy
This Data Policy provides detailed information about:
- What data the GeoScript JavaScript tracking Script collects;
- Who owns that data and how GeoScript uses it;
- GeoScript's role as data controller vs. data processor;
- How customer data and end-user data are handled;
- The complete list of subprocessors GeoScript uses and what data each processes;
- Data security, retention, and deletion;
- How to exercise data rights or request a DPA.
This Policy supplements the Privacy Policy and the Terms of Service. In the event of conflict between this Policy and the Terms of Service on questions of data ownership, the Terms of Service govern.
2. What the GeoScript Script Collects
The GeoScript Script is a lightweight JavaScript snippet installed on monitored websites. It is designed exclusively to detect AI search engine activity. Here is precisely what it collects and what it does not collect:
✓ What the Script DOES collect
- AI crawler visits: user-agent strings matching known AI engine bots (ChatGPT, Perplexity, Gemini, Claude, Grok, Google AI), URL crawled, timestamp
- AI referral sessions: HTTP referrer data when a visitor arrives from an AI engine result page (e.g., referrer = perplexity.ai)
- Citation events: when a monitored page URL appears in a live AI engine response during GeoScript's scheduled query runs
- Page-level metadata: the URL of the monitored page, page title, canonical URL (used to match citation events)
- Session signals: approximate session start time, session source (AI referral vs. direct vs. organic), and session count
- Technical metadata: IP address (used for geolocation at country/region level only; not stored in full), browser type, device category (desktop/mobile/bot)
✗ What the Script does NOT collect
- Names, email addresses, or any contact information of website visitors
- Form submissions, input fields, or typed content of any kind
- Payment or financial data
- Login credentials or session tokens
- Health, biometric, or sensitive personal information
- Full IP addresses stored long-term (IP is used for geolocation derivation only, then discarded)
- Content from pages the Script is not installed on (the Script is page-scoped)
- Data from pages outside the monitored website's domain
The Script does not set any cookies that persist beyond the user's session for tracking purposes. It does not participate in cross-site tracking or behavioral advertising networks.
3. Data Controller and Processor Roles
GeoScript operates in different roles depending on what data is involved:
| Data Type | GeoScript's Role | Governing Document |
|---|---|---|
| Account data (customer's name, email, billing info) | Data Controller — GeoScript determines the purpose and means of processing | Privacy Policy |
| Signal Data collected by the Script from monitored websites | Initially a Data Processor acting on customer's behalf — but Signal Data is irrevocably assigned to and owned by GeoScript per the Terms of Service (§6.1). GeoScript uses it as controller for dataset and product purposes. | Terms of Service §6.1; this Data Policy §4 |
| Personal data of website visitors (end-users of customer's website) | Data Processor — processing personal data on behalf of the customer (the controller) solely to provide the Services. GeoScript has no direct relationship with end-users. | Terms of Service §5; DPA (available on request) |
| Aggregated / anonymized benchmark data | Data Controller — GeoScript owns and uses this data freely for product improvement, research, and publications | Terms of Service §6.3; this Data Policy §4 |
Important: End-user data subject requests
If you are a visitor to a website monitored by GeoScript and want to exercise data rights (access, deletion, etc.) regarding data about you, your request should go to the website operator (our customer), not to GeoScript. We have no direct relationship with website visitors and cannot identify individual visitors from Signal Data. If you contact GeoScript directly, we will direct you to the appropriate website operator.
4. How GeoScript Uses Signal Data
Signal Data is the core input to GeoScript's AI search behavior dataset — the largest structured dataset of AI search behavior ever assembled, covering 144M+ queries across 6 AI engines, 300+ industries, and 4,000+ cities. Here is how Signal Data is used:
4.1 Providing the Services to Customers
Signal Data collected from a customer's monitored websites is used to generate that customer's visibility scores, citation reports, engine breakdowns, trend data, and optimization recommendations within their GeoScript dashboard. This is the primary purpose for which the Script is installed.
4.2 Industry Benchmarks and Comparative Analytics
Signal Data is aggregated across all monitored websites in the same industry category and geography to generate benchmark comparisons (e.g., "your citation rate vs. the HVAC industry average in Phoenix"). Individual customer data is never disclosed in benchmark outputs; only aggregate statistics are used.
4.3 Product Improvement and Feature Development
GeoScript analyzes patterns in aggregated Signal Data to identify: which content structures are more likely to be cited, how citation rates vary by engine, how AI crawl behavior changes over time, and what optimization actions have measurable impact. These insights are used to improve recommendations for all customers.
4.4 Research Publications and Market Intelligence
GeoScript may publish aggregated, anonymized research reports (e.g., "State of AI Search Visibility" reports) derived from Signal Data. No individual customer, website, or business identity is disclosed in these publications. All published statistics are at the market, industry, or engine level.
4.5 What GeoScript Does NOT Do With Signal Data
- Sell raw Signal Data to any third party;
- Use Signal Data to serve advertising to website visitors on other platforms;
- Disclose which individual business is ranked, cited, or monitored in any external publication;
- Share individual customer's citation data with other GeoScript customers;
- Use Signal Data for any purpose unrelated to the Services.
5. Subprocessors
GeoScript uses the following third-party service providers (subprocessors) that may process personal data or Signal Data on our behalf. All subprocessors are bound by data processing agreements requiring them to process data only on GeoScript's instructions and to implement appropriate security measures.
For EU/EEA customers: GeoScript ensures appropriate safeguards (Standard Contractual Clauses or Data Privacy Framework certification) are in place for all subprocessors that receive personal data from the EU/EEA.
| Subprocessor | Service | Data Processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account data, Signal Data, billing records, usage data | US (AWS us-east-1) |
| Stripe | Payment processing | Billing data (name, card details, billing address, transaction history). Card numbers not stored by GeoScript. | US |
| Pinecone | Vector database for AI search indexing | Aggregated Signal Data (vectorized), content embeddings | US |
| Vercel | Application hosting and deployment infrastructure | Log data, IP addresses (transient), request metadata | US (edge globally) |
| Upstash | Redis caching, rate limiting, job queues | Session tokens, rate-limit counters, transient query data | US |
| OpenAI | AI engine querying (visibility monitoring) | Business name, city, industry (used to construct visibility queries). No personal data of end-users. | US |
| Anthropic | AI engine querying (visibility monitoring) | Business name, city, industry (query construction only) | US |
| Perplexity AI | AI engine querying (visibility monitoring) | Business name, city, industry (query construction only) | US |
| Google (Gemini / AI Overviews) | AI engine querying (visibility monitoring) | Business name, city, industry (query construction only). Google Analytics if enabled. | US |
| Email delivery provider (TBD) | Transactional and marketing email delivery | Name, email address, communication preferences | US |
GeoScript will provide at least 10 days' notice to customers who have signed a DPA before adding a new subprocessor that processes personal data covered by that DPA. Notice will be sent to the email address on file for the account. Customers who object to a new subprocessor addition may terminate their subscription without penalty within the notice period.
6. Data Security
GeoScript applies the following technical and organizational security measures:
Encryption in transit
All data transmitted between your browser, the Script, and GeoScript servers uses TLS 1.2 or higher. Unencrypted connections are rejected.
Encryption at rest
All data stored in Supabase (PostgreSQL) and Pinecone is encrypted at rest using AES-256. Backups are encrypted.
Access controls
Role-based access control (RBAC) limits data access to authorized GeoScript engineers on a need-to-know basis. Customer data is logically segregated.
Authentication
Multi-factor authentication (MFA) is required for all GeoScript administrative access. Customer accounts support MFA via Supabase Auth.
Script integrity
The GeoScript Script is served from a versioned, integrity-checked CDN endpoint. Customers can use Subresource Integrity (SRI) hashing to verify the Script has not been tampered with.
Incident response
GeoScript maintains an internal incident response plan. In the event of a confirmed data breach affecting personal data, we will notify affected customers within 72 hours of becoming aware, and notify relevant supervisory authorities as required by GDPR.
Penetration testing
GeoScript conducts or commissions security reviews of its infrastructure. Enterprise customers may request the most recent security assessment summary.
Vendor security
All subprocessors are evaluated for security compliance before use. GeoScript monitors subprocessor security notices and updates this policy accordingly.
7. Data Retention and Deletion
7.1 Retention Schedule
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (active subscription) | Duration of subscription + 60 days | Service delivery; grace period for re-activation |
| Account data (deleted account) | 60 days from deletion request | Audit trail; allows account recovery if deletion was accidental |
| Signal Data — customer-specific reports and dashboards | Duration of subscription + 60 days | Service delivery; historical trend data requires continuity |
| Signal Data — raw dataset (anonymized, aggregated) | Indefinitely | Owned by GeoScript; core dataset asset; not subject to deletion (see §7.2) |
| Billing records and invoices | 7 years | Tax and accounting compliance (IRS requirements) |
| Support tickets and communications | 3 years from last interaction | Customer support quality and dispute resolution |
| Security and access logs | 13 months rolling | Security investigation; GDPR guidance on log retention |
| Backups | 30 days rolling (daily backups) | Disaster recovery; backups are encrypted and access-controlled |
| Waitlist and checker submissions | Until product launch or 24 months, whichever is earlier | Founding partner program management; deleted or converted to account on launch |
7.2 Signal Data and the Right to Deletion
By installing the Script, customers irrevocably assign all Signal Data to GeoScript (Terms of Service §6.1). This means:
- Customer-level deletion: When a customer cancels their subscription, GeoScript deletes the customer's account data and their individually attributed report data within 60 days. The Script stops collecting data immediately on cancellation.
- Raw Signal Data: The underlying Signal Data (AI crawler events, referral signals, citation events) contributed to GeoScript's dataset is not deleted upon customer cancellation. This data is anonymized and forms part of GeoScript's proprietary dataset, which is owned by GeoScript regardless of the customer relationship.
- End-user deletion requests: If a website visitor submits a deletion request to GeoScript, GeoScript cannot identify individual visitors within Signal Data (Signal Data does not contain names or email addresses). GeoScript will direct such requests to the website operator. If the website operator provides a verified identifier that can be matched to Script-collected data, GeoScript will delete that specific record upon verification.
7.3 How to Request Data Deletion
Customers may request deletion of their account and report data by:
- Emailing hello@geoscript.ai with subject line "Data Deletion Request"
- Including the email address associated with the account and a description of what data to delete
- GeoScript will confirm receipt within 5 business days
- Deletion will be completed within 30 days of verification (60 days for account data)
8. Cross-Border Data Transfers
GeoScript is based in the United States. All primary infrastructure (Supabase/AWS) is located in the US. If you are a customer in the EEA, UK, or Switzerland, your personal data is transferred to and processed in the US.
Transfer mechanisms in place:
- Standard Contractual Clauses (SCCs) — Controller to Processor, Module 2
GeoScript uses the European Commission's 2021 SCCs for data transfers from the EEA to US subprocessors. These are incorporated into our agreements with Supabase, Vercel, and other processors that receive EEA personal data. - EU-U.S. Data Privacy Framework (DPF)
Where a subprocessor is certified under the EU-U.S. DPF (e.g., Stripe, Google), we rely on their certification as an additional or alternative transfer mechanism.
Customers who require a copy of the SCCs or a Transfer Impact Assessment (TIA) for their own compliance obligations may request these at hello@geoscript.ai.
9. Data Processing Agreement (DPA)
A Data Processing Agreement is available to any GeoScript customer who:
- Processes personal data of EU/EEA data subjects via the Script;
- Is subject to GDPR and needs to document GeoScript's role as a data processor under Article 28;
- Requires contractual data protection commitments for enterprise procurement, security audits, or regulatory compliance.
The GeoScript DPA covers: processing instructions, confidentiality obligations, subprocessor authorization and notification, data subject request assistance, breach notification (72-hour commitment), data return/deletion at contract end, audit rights, and applicable SCCs for cross-border transfers.
To request a DPA, email hello@geoscript.ai with the subject line "DPA Request". We will respond within 5 business days.
10. Customer Compliance Responsibilities
When customers install the GeoScript Script on websites (including client websites for agency customers), they take on certain data compliance responsibilities:
Privacy notices
Customers must update their website(s) privacy policy or notice to disclose that GeoScript (or a third-party AI analytics service) collects AI search behavior data via a Script on the site. The disclosure must meet the requirements of applicable law (e.g., GDPR Art. 13, CCPA).
Consent (where required)
In jurisdictions where the Script's data collection triggers a consent requirement (e.g., where the Script's use of IP addresses or session data constitutes personal data processing under ePrivacy rules), customers are responsible for obtaining and documenting that consent before the Script fires.
Authorization for client websites
Agency customers who install the Script on their clients' websites must have written authorization from those clients to do so, and must ensure that those clients' privacy notices are updated accordingly.
Accuracy of monitored site data
Customers are responsible for ensuring the businesses and websites they add to GeoScript for monitoring are businesses they have authority to monitor. Installing the Script on a website without authorization is a violation of the Terms of Service.
Data subject requests from website visitors
If a visitor to a monitored website submits a GDPR or CCPA data rights request to the customer, the customer is responsible for responding. Where fulfilling the request requires deleting GeoScript-collected data, customers should contact GeoScript with the verified request details.
11. Changes to This Policy
GeoScript may update this Data Policy as our subprocessors, infrastructure, or data practices change. Material updates will be communicated with at least 30 days' notice via email to the address on the account. The subprocessor list (Section 5) may be updated with 10 days' notice for new subprocessors that process personal data.
Customers with a signed DPA who object to a new subprocessor addition have the right to terminate their subscription without penalty within the 10-day notice period.
12. Contact
For data policy questions, DPA requests, deletion requests, or subprocessor inquiries:
GeoScript, Inc.
Data Inquiries
hello@geoscript.ai
Related documents: Terms of Service · Privacy Policy
This Data Policy was last updated in August 2026. Prior versions are available upon request.