This Privacy Policy explains what personal data we process when you visit https://brandometer.ai or use Brandometer (the “service”), why we process it, who receives it and what rights you have. It follows the EU General Data Protection Regulation (GDPR) and the UK GDPR and applies to every visitor and user, wherever they live.
1. Who is responsible for your data
1.1. The controller of your personal data is the operator of the service: Individual entrepreneur Vladislav Ivanov (IP Ivanov Vladislav Aleksandrovich) · INN 781698861800 · OGRNIP 324784700366200, registered in the Russian Federation (“we”, “us”).
1.2. Contact for all privacy questions and requests: support@brandometer.ai. We do not publish a postal address; all correspondence is by email.
1.3. We are not required to appoint a data protection officer. Privacy requests are handled by the operator personally.
2. What data we collect
2.1. We collect only what the service needs.
| Category | What we collect |
|---|---|
| Account | Email address; password (stored only as a salted hash, never in readable form); interface language; time zone; notification settings; your referral code and, if you were invited, the account that invited you; dates of sign-up and last activity. |
| Sign-up and security | The IP address from which the account was created. IP addresses are also processed briefly in memory to limit the rate of requests (sign-up, login, free check); these counters are not stored. |
| Billing | Billing details if you provide them (company name, tax or VAT ID, country, address, contact person); your top-up, bonus and invoice requests; the history of credits granted, spent and refunded; payment amounts and dates. We do not collect or store payment card data. |
| Project data | Brand names and their variants, website domain, competitor names, business category, country and language of the project, prompts, run schedule; the AI answers received for your prompts, the sources they cite, the metrics and reports built from them, and generated action plans. |
| Website verification | The mailbox on your domain to which we send the verification code. |
| Telegram (optional) | If you link the Telegram bot: your chat ID and username, your notification preferences and the messages you send to the bot (they are forwarded to support). |
| Feedback and support | Messages you send from the service, files you attach to them, and your email correspondence with support. |
| Free check on the home page | The IP address from which the check was made, the brand name and the prompt you entered. No account is needed. |
| First-touch attribution | The source of your first visit (a class such as “search” or “AI assistant”, the referring site and the page you landed on) and the referral code from an invitation link. They are saved in your browser and sent to us only if you sign up. |
| Visit statistics | For a visit to a public page: the page path, the host of the referring site and the class of the source. No IP address, no cookie and no identifier is stored, so these records are not linked to a person. |
| Technical logs | Server, application and mail server logs. They can contain IP addresses, the time and address of a request and email delivery events. |
| Email delivery records | For each email we send: recipient, subject, time and delivery status. The full text of the email is kept for 3 days only. |
2.2. We do not ask for and do not need special categories of data (such as health data, political opinions or religious beliefs).
2.3. Most of the data comes from you. AI answers come from the third-party AI services to which your prompts are sent (section 4).
3. Why we use your data and on what legal basis
3.1. The legal bases below refer to Article 6(1) of the GDPR and the UK GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating your account, logging you in, running checks, storing results and building reports | Account and project data | (b) performance of the contract with you |
| Service messages: email confirmation, password reset, verification codes, answers to your requests, run notifications in Telegram if you link it | Email address, Telegram chat ID | (b) contract |
| Credits, top-up requests, invoices and refunds | Account and billing data | (b) contract; (c) legal obligations (tax and accounting records) |
| Support and feedback | Messages, attachments, correspondence | (b) contract; (f) legitimate interest in improving the service |
| Protecting the service and its free allowances from abuse: rate limits, one free check per IP address, detecting duplicate sign-ups made to collect bonuses, fraud prevention | Sign-up IP address, free-check IP address, technical logs | (f) legitimate interest in security and fair use |
| Understanding which channels bring visitors and customers | First-touch attribution, visit statistics | (f) legitimate interest in measuring our marketing with as little data as possible |
| Remembering your language and time zone | Preferences | (b) contract; (f) legitimate interest in a usable interface |
| Occasional product emails to customers, for example a reminder to repeat a check together with a bonus offer | Email address, date of your last run | (f) legitimate interest in telling customers about the service they already use; you can opt out at any time |
| Newsletters and other marketing emails that are not related to your use of the service | Email address | (a) your consent, which you can withdraw at any time |
| Establishing, exercising or defending legal claims; answering lawful requests of authorities | Data relevant to the matter | (f) legitimate interest; (c) legal obligation |
3.2. Marketing email. Every product or marketing email contains an unsubscribe link that works in one click, without logging in. You can also object by writing to us. Service messages (email confirmation, password reset, verification codes, answers to your requests) are part of the service and are not marketing.
3.3. Where we rely on legitimate interests, we have weighed them against your rights and expectations. You can object to this processing at any time (section 9).
3.4. An email address and a password are required to create an account; without them we cannot provide the service. All other data is optional.
3.5. We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. Automated anti-abuse checks may limit free bonuses or the free check.
4. Prompts and AI providers
4.1. To measure AI visibility we send the prompts of your project to the AI engines you selected and store their answers. A prompt is a marketing question of the kind a customer might ask, for example “best accounting software for a small business”.
4.2. A prompt is sent without your name, email address, IP address or any account identifier. The request can include the language and country of the project, so that the engine answers as it would for a user in that market.
4.3. Prompts, AI answers, brand names and competitor names are also sent to an AI provider that classifies each answer (for example, whether the brand is recommended or only mentioned) and generates prompt suggestions and action plans.
4.4. Do not put personal data into prompts, brand names or other project fields. The service does not need it, and whatever you enter there is passed to third-party AI providers. If your brand is itself a personal name, it is processed as part of these requests.
4.5. AI answers are stored as received. They may name people, for example public figures. We do not control the content of AI answers and do not use it to build profiles of the people mentioned.
5. Who receives your data
5.1. We share personal data only with providers that help us run the service, and only as far as their task requires.
| Category | Provider | What it receives | Location |
|---|---|---|---|
| Hosting | A hosting provider with data centers in Germany | All data of the service: database, uploaded files, mail server | Germany (EU) |
| Content delivery, DNS, protection against attacks | Cloudflare, Inc. | IP address and request data of every visitor, in transit | United States; global network |
| Backup storage | Backblaze, Inc. | Backup copies of the database, mailbox and uploaded files | United States |
| Email delivery | Our own mail server on the hosting above. If direct delivery to your mailbox provider fails, the message may be re-sent through a third-party email delivery service | Recipient address and the content of the message | Germany (EU); the delivery service may be outside the EU |
| AI engines that answer prompts | OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini), Perplexity AI, xAI (Grok), DeepSeek, Mistral AI (Le Chat), Alibaba Cloud (Qwen) | Prompt text, language and country of the project — no account data | United States, China, France, Singapore |
| Answer classification, prompt suggestions, action plans | DeepSeek | Prompts, AI answers, brand and competitor names, business category | China |
| Search data | Providers of Google search results data (used for Google AI Overviews); Google’s public autocomplete service (used for prompt suggestions) | Prompt text or keywords, country and language — no account data | Varies by provider |
| Telegram notifications (only if you link the bot) | Telegram | Chat ID and the text of notifications | Global network |
5.2. Only the engines you select in a project receive its prompts. The current line-up is shown on the pricing page. When an engine of a new provider is added, this table is updated.
5.3. Online payment is not connected yet (see the Terms of Service). When a payment provider is connected, it will be added to this table before it is used.
5.4. We may disclose data to public authorities or courts when the law requires it, to professional advisers bound by confidentiality, and to a successor if the service is transferred to another operator. In the last case you will be told in advance.
5.5. We do not sell personal data and do not share it for advertising. You can ask us for the current list of providers by email.
6. International transfers
6.1. The database, files and mail server of the service are located in Germany.
6.2. We, the operator, are established in the Russian Federation and access the data from there to run and support the service. Neither the European Commission nor the United Kingdom has issued an adequacy decision for Russia.
6.3. Some of the providers in section 5 are located in other countries without an adequacy decision, including the United States (unless the provider is certified under the EU–US Data Privacy Framework), China and Singapore. AI engines and search data providers receive only what section 4 describes.
6.4. For these transfers we rely on:
- an adequacy decision, where one exists;
- standard contractual clauses (and the UK addendum) included in the provider’s data processing terms, where the provider offers them;
- where neither is available, Article 49(1)(b) of the GDPR: the transfer is necessary to perform the contract with you. A prompt cannot be measured without sending it to the AI engine you selected.
6.5. You can ask us by email for more information about the safeguards that apply to a particular provider.
7. How long we keep your data
| Data | Retention period |
|---|---|
| Account data, project data, AI answers, reports, credit history, sign-up IP address, email delivery records | For as long as your account exists. After you ask us to delete the account, the data is deleted or anonymized within 30 days. |
| Full text of sent emails | 3 days |
| Free check: IP address, brand name and prompt | For as long as the free check is offered: this record is what enforces the limit of one free check per IP address. It is deleted earlier at your request. |
| Feedback messages and attachments | Until the account is deleted or until you ask us to delete them |
| Email correspondence with support | Up to 3 years after the last message |
| Billing and payment records, invoices | For the period required by tax and accounting law (5 years) |
| Telegram chat ID and username | Until you unlink Telegram or the account is deleted |
| Technical logs | Rotated automatically; normally not longer than 30 days |
| Backups | Daily copies are overwritten after 7 days; monthly copies are kept for up to 12 months |
| Visit statistics | Kept in aggregate; they are not personal data |
| Data in your browser | See section 10 |
Data that we must keep by law, or that we need for a legal claim, is kept for as long as that reason exists, even after the account is deleted.
8. Security
8.1. Connections to the service are encrypted. Passwords are stored only as salted hashes. Access to the server and the database is limited to the operator. The service runs in an isolated environment behind a firewall, and backups are made every night.
8.2. A login session is valid for 14 days; a password reset link is valid for 2 hours.
8.3. No system is perfectly secure. If a breach creates a risk for you, we will notify you and the competent authority as the law requires.
9. Your rights
9.1. Under the GDPR and the UK GDPR you have the right to:
- access your data and receive a copy of it;
- rectify inaccurate or incomplete data;
- erase your data (delete the account);
- restrict processing in certain cases;
- receive your data in a portable format or have it sent to another provider;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent where processing is based on it, without affecting what was done before;
- lodge a complaint with a supervisory authority (section 9.5).
9.2. Some of this you can do yourself in the service: change the language, time zone and billing details, export run results as PDF or CSV, delete projects, unlink Telegram, and unsubscribe from product emails with the link in each email.
9.3. For everything else, write to support@brandometer.ai from the email address of your account. If the request comes from another address, we may ask you to confirm your identity.
9.4. We answer within one month. For a complex request this period can be extended by two more months; we will tell you if that happens. Requests are free of charge unless they are manifestly unfounded or excessive.
9.5. You can complain to the data protection authority of the country where you live or work, or where you think the infringement happened. In the EEA, the authorities are listed on the website of the European Data Protection Board; in the United Kingdom it is the Information Commissioner’s Office. We would appreciate the chance to resolve the issue first.
9.6. Residents of US states with privacy laws, including California: we do not sell personal information and do not share it for cross-context behavioral advertising. You can use the rights in this section in the same way.
10. Cookies and local storage
10.1. The service sets one cookie and a few entries in your browser’s storage. They are strictly necessary or functional, so no consent banner is shown.
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
bm_lang |
Cookie | Remembers the interface language you chose, so that the home page opens in it. Functional. | 1 year |
bm_lang |
Local storage | The same preference for the pages of your account. Functional. | Until you clear it |
token |
Local storage | Keeps you logged in. Strictly necessary. | Until you log out; the session expires after 14 days |
tz |
Local storage | Your time zone, used to show dates and times. Functional. | Until you clear it |
acq1 |
Local storage | First-touch attribution: the source of your first visit. Sent to us only if you sign up. Functional. | Until you clear it |
ref1 |
Local storage | Referral code from an invitation link, needed to grant the referral bonus. Functional. | Until you clear it |
trk1 |
Session storage | Prevents counting the same visit twice in the visit statistics. Functional. | Until you close the browser tab |
10.2. We use no advertising or cross-site tracking cookies and no third-party analytics scripts. Visit statistics are first-party and cookieless, and they are stored without an IP address.
10.3. Cloudflare, which delivers the site, may set its own strictly necessary security cookies (for example __cf_bm or cf_clearance) to tell people from bots.
10.4. You can delete cookies and storage entries in your browser settings at any time. If you delete token, you will be logged out.
11. Children
The service is intended for businesses and professionals. An account may be created only by a person aged 18 or older. We do not knowingly collect data of children under 16. If you believe a child has given us personal data, write to us and we will delete it.
12. Changes to this policy
We may update this policy. The current version is always published on this page with the date of the last update. If a change materially affects how we use your data, we will tell you by email or in the service before it takes effect.
13. Language and contact
13.1. The English version of this policy is the authoritative one. Translations are provided for convenience.
13.2. Questions about personal data: support@brandometer.ai.
13.3. Related documents: Terms of Service, Credits & Refund Policy.