Privacy Policy
Effective May 15, 2026
1. Who we are
Visibly (“we”, “us”, “our”) is an AI-citation monitoring service that tracks brand visibility across large language models and AI search engines. Our service is operated as a solo developer project. Questions: markorakovicwork@gmail.com
2. What we collect
- Account data — email address and display name provided at sign-up.
- Brand & keyword data — brand names, domains, and keywords you add for tracking.
- Scan results — AI engine responses and citation scores generated when we query AI engines on your behalf.
- Usage data — page views, feature interactions, and error events (via Sentry).
- Billing data — subscription status and payment events from LemonSqueezy. We do not store card numbers; all payment data is held by LemonSqueezy.
3. How we use it
- To provide the core service: running AI engine queries, computing citation scores, and displaying your dashboard.
- To send transactional emails (account verification, password reset, billing notifications) via Supabase Auth.
- To detect and diagnose errors via Sentry.
- To process subscription payments via LemonSqueezy.
We do not sell your data. We do not use your data for advertising.
4. Data processors
We share data with the following sub-processors to deliver the service:
- Supabase — authentication and database (hosted on AWS us-east-1).
- OpenAI — AI engine queries. Your keyword and brand data is sent to OpenAI to generate citation results.
- Sentry — error monitoring. Error events may include request data.
- LemonSqueezy — payment processing and subscription management.
- Vercel — application hosting and edge network.
5. Data retention
We retain your data for as long as your account is active. If you delete your account, your account data, brand data, keyword data, and scan results are deleted from our database. Residual copies in backups are purged within 30 days. Log data held by Sentry and Vercel is subject to their respective retention policies.
6. Your rights
You may request access to, correction of, or deletion of your personal data at any time by emailing markorakovicwork@gmail.com. You can delete your account directly from Settings → Account. We will respond to data requests within 30 days.
7. Cookies
We use a single authentication cookie set by Supabase to maintain your logged-in session. We do not use third-party tracking or advertising cookies.
8. Security
Access to your data is restricted by row-level security policies enforced at the database level. Data in transit is encrypted via TLS. Passwords are hashed and never stored in plaintext.
9. Children
The service is not directed to children under 16. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy. We will email you if we make material changes. The effective date at the top of this page will reflect the most recent revision.
11. Contact
For privacy questions or data requests: markorakovicwork@gmail.com