1. Scope & who this policy covers
eOdessa Interactive LLC builds and operates Visible, an AI search visibility platform that shows businesses how ChatGPT, Claude, Gemini, Perplexity, Google AI Overview, and Copilot mention, cite, and rank their brand. This policy applies to:
- Our marketing website at eodessa.com, including this page, our blog, comparison pages, and landing pages;
- Our web application at visible.eodessa.com, including any account, dashboard, and API/MCP access; and
- Any related support, sales, or marketing communications between you and us.
eOdessa Interactive LLC is a limited liability company organized under the laws of the State of California, USA, and is the data controller (or, under U.S. state law, the "business") responsible for the personal data described in this policy. If your organization's team members use Visible under your company's account, your company is generally the controller for the data it submits to the Service, and we act as a processor/service provider on its behalf — see Section 7.
This policy does not cover third-party websites, apps, or services that we link to (including the AI platforms we track, such as ChatGPT or Perplexity) — those services have their own privacy policies.
2. Information we collect
2.1 Information you provide directly
- Account & authentication data — name, email address, and login credentials when you register or sign in (authentication is handled by our identity provider; we never see or store your raw password).
- Company & team data — your company name, team member email addresses and roles (Admin/Moderator) when you invite teammates, and, if you accept an invitation to a second company, your membership and role in that company too.
- Brand & competitor data — the brand name, website, industry, geography, language, logo, product/FAQ content, and competitor names/domains you configure for tracking.
- Tracked prompts & content you submit — the questions you choose to track, sitemap URLs, and server/CDN access logs you optionally upload for crawler-bot analytics.
- Billing information — when you subscribe to a paid plan, our payment processor collects your payment card and billing address on our behalf; we retain only high-level billing metadata (plan, status, invoice history), not your full card number.
- Communications — messages you send us through the contact form, email, or in-app support, including any information you choose to include in them.
2.2 Information collected automatically
- Usage & log data — pages visited, features used, timestamps, referring URLs, and general diagnostic/error logs generated while you use the Service.
- Device & connection data — IP address, browser type and version, operating system, and device identifiers.
- Cookies and similar technologies — see Section 6.
2.3 Information generated by the Service
- AI response data — the answers returned by third-party AI platforms to your tracked prompts, and the mentions, citations, sentiment classifications, and scores we derive from them (see Section 3).
- Crawler & site-audit data — data generated when Deep Scan crawls a website you've authorized us to analyze, including page content, structure, and technical findings.
3. How AI processing works
Visible's core function requires sending your tracked prompts and brand/competitor names — never your account password or billing details — to third-party AI platforms so we can observe and score how they respond. Depending on which platforms you enable, this may include:
- OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini and, via a search-data provider, Google AI Overview), Perplexity, and Microsoft (Copilot) — to run your tracked prompts and retrieve their responses.
- Anthropic (Claude) specifically — to classify the sentiment of each brand mention we detect, and to extract brand/entity information from a website you ask us to analyze for prompt suggestions.
These platforms process the prompt text and any brand names you've configured under their own privacy policies and terms; we do not control how they further process that data, though we do not authorize them to use it to identify you personally. We select platforms that offer business/API-tier terms where available and avoid embedding unnecessary personal data in the prompts we send.
What we don't send
We do not send your account password, payment details, or team members' personal contact information to any AI platform. Only the brand, competitor, and prompt-configuration data needed to run a visibility check is sent.
4. How we use your information
- To provide, operate, and maintain the Service, including running your tracked prompts, computing your Visibility Score, and generating dashboards, reports, and recommendations;
- To manage your account, team memberships, and subscription, including billing and invoicing;
- To communicate with you about your account, respond to support requests, and send service-related notices (e.g., a teammate invitation, a completed scan, or a billing receipt);
- With your consent or where legally permitted, to send product updates or marketing communications, which you can opt out of at any time;
- To monitor, secure, debug, and improve the Service, including analyzing aggregate usage trends;
- To detect, prevent, and address fraud, abuse, security incidents, and technical issues;
- To comply with legal obligations and enforce our terms of service.
5. Legal basis for processing (EEA/UK/Switzerland)
If you are located in the European Economic Area, the UK, or Switzerland, we rely on the following legal bases under the GDPR/UK GDPR:
- Performance of a contract — to create your account, run the Service you've signed up for, and process payment for a paid plan;
- Legitimate interests — to secure and improve the Service, prevent fraud, and understand aggregate usage, balanced against your rights and interests;
- Consent — for non-essential cookies and optional marketing communications, which you can withdraw at any time;
- Legal obligation — where we must retain or disclose data to comply with the law.
6. Cookies & similar technologies
We use cookies and similar technologies for the following purposes:
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Keep you signed in and remember your active company/session | Authentication session, active-company selection |
| Analytics | Understand aggregate visitor traffic and site performance | Google Analytics (GA4) |
| Advertising | Measure the effectiveness of our own ad campaigns | Google Ads conversion tracking |
We do not use non-essential cookies to build cross-site advertising profiles of you, and we do not sell the information collected via cookies. Google's use of analytics and advertising cookies is governed by Google's Privacy Policy; you can opt out of Google Analytics using the Google Analytics opt-out browser add-on, and manage Google Ads personalization at adssettings.google.com. You can also block or delete cookies through your browser settings at any time, though strictly necessary cookies are required for the app to keep you signed in.
Our servers do not currently respond to browser "Do Not Track" signals, as no common industry standard for honoring them has been adopted; we will revisit this if one is.
7. How we share information
We do not sell your personal information. We share information only in the following circumstances:
7.1 Service providers (subprocessors)
We use vetted third-party providers to operate the Service, each bound by contract to use your data only to provide services to us:
| Provider category | Purpose |
|---|---|
| AI platforms (OpenAI, Anthropic, Google, Perplexity, Microsoft) | Run tracked prompts and generate the AI answers Visible measures; Anthropic additionally powers sentiment classification and entity extraction |
| Cloud hosting & storage (Amazon Web Services) | Application hosting, database storage, and file/object storage (e.g. uploaded logs, crawl artifacts) |
| Payment processing (Stripe) | Securely process subscription payments; we do not store full card numbers |
| Identity & authentication infrastructure | Secure login, session, and password management |
| Transactional email delivery | Send account, invitation, and billing-related emails |
| Website analytics & advertising (Google) | Aggregate site-traffic analytics and ad-campaign measurement — see Section 6 |
7.2 Other disclosures
- Within your organization — data you submit under a company account is visible to other members and Admins of that company, consistent with the role-based access you and your teammates configure;
- Legal & safety — if required by law, subpoena, or legal process, or to protect the rights, property, or safety of eOdessa, our users, or the public;
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections; and
- With your direction — anywhere else you explicitly direct us to share your data (e.g., a future integration you choose to enable).
8. International data transfers
We and our service providers may process and store personal data in the United States and other countries outside your own. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on recognized safeguards such as Standard Contractual Clauses or equivalent mechanisms offered by our providers.
9. Data retention
- Account & company data is retained for as long as your account is active, and for a reasonable period afterward to allow reactivation, resolve disputes, and comply with legal obligations, after which it is deleted or anonymized.
- Tracked-prompt scoring history is retained according to your subscription tier's published history window (currently 30 days on Free, 12 months on Basic, and 24 months on Pro), after which older records are automatically purged.
- Raw AI response text is retained for a limited window (currently 90 days) and then pruned automatically, independent of the scoring history derived from it.
- Uploaded crawler/access logs are retained for a limited window (currently 90 days) and then automatically deleted.
- Billing records are retained as required by applicable tax and accounting laws.
You may request earlier deletion of your account data at any time — see Section 11.
10. How we protect your information
We use administrative, technical, and physical safeguards designed to protect personal data, including encryption of sensitive data at rest, encrypted connections in transit (TLS), access controls scoped by company and role, and authenticated service-to-service communication between internal systems. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work to continually evaluate and improve these safeguards.
11. Your privacy rights
11.1 If you are in the EEA, UK, or Switzerland (GDPR)
You have the right to: access the personal data we hold about you; correct inaccurate data; request erasure; restrict or object to certain processing; receive a copy of your data in a portable format; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority.
11.2 If you are a California resident (CCPA/CPRA)
You have the right to: know what personal information we collect, use, and disclose about you; request deletion of your personal information; request correction of inaccurate information; and not be discriminated against for exercising these rights. We do not sell or "share" (as defined by the CPRA) personal information for cross-context behavioral advertising, so there is no sale/share opt-out to exercise.
11.3 Other jurisdictions
If you live in a U.S. state or country with its own data privacy law (e.g., Virginia, Colorado, Connecticut, or others), we will honor equivalent rights that law grants you, to the extent applicable.
11.4 How to exercise your rights
Email visible@eodessa.com with your request. We may need to verify your identity before fulfilling it, and we will respond within the timeframe required by applicable law. If your data was submitted to us by your employer's or organization's Visible account, we may direct your request to that organization's account Admin where they are the controller of that data.
12. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us at visible@eodessa.com and we will delete it.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We'll update the "Last updated" date above, and for material changes we'll provide additional notice (such as an in-app notification or email) where required by law.
14. Contact us
If you have questions about this policy or how we handle personal data, reach out and we'll respond from a real person on the team:
Data protection contact
Email
visible@eodessa.com
Company
eOdessa Interactive LLC
Product
visible.eodessa.com