Legal

Privacy Policy

Last updated September 6, 2026

This is a starting template, not legal advice. Review and adapt it with qualified counsel before relying on it.

This policy explains what information maketrend.ai collects, why we collect it, and the choices you have. It applies to our website and to the maketrend.ai application.

Information we collect

We collect the following categories of information:

  • Account information: the email address and authentication details used to sign in.
  • Workspace inputs: the business name, website, services, areas, confirmed facts and enquiry goals you enter. Earlier workspaces may also contain competitor records.
  • Connected integrations: access tokens you choose to connect (for example Google Search Console, GitHub, or a CMS). These are encrypted server-side and shown back to you only as labels.
  • Usage data: scans, audits, actions, and related activity generated as you use the product.

How we use information

We use the information above to:

  • provide and operate the service, including scans and GEO audits;
  • generate evidence-backed actions and verify their results;
  • secure accounts, prevent abuse, and meet legal obligations;
  • communicate with you about your account and the service.

We do not sell your personal information.

Business data and optional legacy contribution

The service-business AEO workflow keeps each business’s evidence, reviews and enquiry records within its authorized scope. It does not automatically contribute those records to cross-customer learning.

Earlier workspaces may have separately configured contribution settings. Those historical choices remain subject to their recorded purpose, policy and withdrawal controls; they are not enabled by creating a service-business workspace.

Public website inspection and enquiry records

A website check reads a bounded selection of public pages and retains limited page text, status and findings. Anonymous results are tied to a browser cookie and expire after 24 hours. Saving an inspection requires authenticated business access.

Enquiry imports accept source event identifiers, enquiry identifiers, event stages, times, qualification and optional service, area, referral and job-value fields. Contact names, email addresses, telephone numbers and private message-body columns are not part of the supported import format.

Subprocessors

We rely on the following third parties to run the product. Each receives only the data needed for its function.

Core infrastructure

Convex hosts our backend, database, authentication, and stored report artifacts. Our web application is served through our cloud deployment provider.

Payments

Stripe processes subscriptions and invoices. Card details are handled by Stripe and are not stored on our servers.

Email

Resend delivers transactional and report emails.

AI answer engines and search data

The service-business workflow sends the selected customer question and its declared locale to configured OpenAI, Google Gemini or Perplexity APIs. Results identify the actual API and model; they are not presented as captures of consumer applications. Earlier workspaces may use separately configured providers. Account credentials and enquiry rows are not supplied in these answering requests.

Integrations you connect

When you connect Google Search Console, GitHub, or WordPress, we access them only for the scope you grant and only to perform the actions you approve.

Data retention

Service-AEO anonymous checks expire after 24 hours; temporary import rows normally expire after seven days. Raw inspected page text and answer bodies are retained for 90 days. Normalized observation and enquiry history and completed improvement/publication history use a 12-month retention window.

Current business facts and evidence still needed by active work remain available while that work is active. A business owner can request deletion with a seven-day cancellation window. Cleanup removes the business’s content, review links and connection credentials in bounded jobs; separate payer, necessary security and payment-processor records may remain. Ending a business does not automatically cancel a separate subscription.

Earlier workspaces retain their separately configured retention controls. Backup expiry and legally required payment retention follow the applicable provider and account policies.

Security

Private business data is scoped by business roles or an exact verified-recipient review grant on backend reads and writes. Connected secrets are encrypted at rest and are never returned to the browser in plain text.

Your choices and rights

You may request access to, correction of, or deletion of your personal information, and you may disconnect any integration at any time from Settings. To make a request, contact us using the address below.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the date at the top of this page.

Contact

Questions about this policy can be sent to contact@maketrend.ai.