Legal
Privacy Policy
What personal data we collect, why, who else sees it, how long we keep it, and how to use your rights. It is written to be checked against the product, not to sound reassuring.
Last updated 17 September 2026 · Seen in Search is a product of FactoryJet Private Limited
Who is responsible for your data
Seen in Search is run by FactoryJet Private Limited, 70/1, Willow Herbs, Brookefield, Tigalarpalya, Kundalahalli, Bengaluru, Karnataka - 560037, India. For your personal data we are the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). Questions about this policy or your data go to [email protected], or to our Grievance Officer, Bhavesh Barot (details below).
What we collect
- Your account
- Your work email address, your name if you gave us one, and the domain part of your email. If you set a password we store a scrypt hash of it, never the password. Sign-in links and one-time codes are stored only as hashes, so we cannot read them back either. If you invite colleagues, we store their email addresses to send the invitation.
- Your reports
- The domain you asked us to measure, the questions we put to answer engines, and their answers — including the verbatim text, because that text is the evidence behind your score. Also the competitors named in those answers, the sources cited, and the fixes we derived.
- Payments
- Your plan, what you paid and when, invoices, and the reference numbers the payment provider gives us. We never see or store your full card number or UPI PIN — the payment provider collects those directly.
- Consent records
- When you agree to our terms at sign-up, we record when and which version. When you tick “I agree” before a payment, we also record the plan, the exact words you agreed to, the version of this policy, and a one-way hash of your IP address.
- Connections you set up
- If you connect a website, Google Search Console, Google Analytics or another platform, we store the access it grants, encrypted, and the data we read through it. Google connections are read-only.
- Your IP address
- Recorded with a scan and with rate-limit counters, for abuse protection only. It is never used to profile you, and it is erased 30 days later — see retention.
- Messages
- What you send us by email, so we can answer it.
We also record a handful of product events — a scan started, a report unlocked — so we can tell whether the product works. These are stored in our own database. We do not use any third-party analytics.
Why we use it
- to create and secure your account and sign you in;
- to run the scans and build the reports you ask for;
- to take payments, issue invoices and meet tax and accounting law;
- to send you the emails the service needs (sign-in links, receipts, a finished report);
- to send optional alerts, only if you switch them on;
- to prevent abuse, fraud and attacks, and to keep the service working;
- to meet our legal duties and respond to lawful requests.
We process your data on the basis of the consent you give when you sign up or pay, and, where the DPDP Act allows it without consent, for legitimate uses such as meeting a legal obligation. You can withdraw consent at any time (see your rights). Withdrawing does not affect what was done before, and we may not be able to keep providing the service without the data it needs.
Who else sees it
Running a scan means asking other companies questions on your behalf, so this list is part of the product rather than an afterthought. Each receives only what it needs for its job.
- DataForSEO
- Puts our buyer questions to ChatGPT, Google AI Overviews and Perplexity and returns their answers. Receives the questions and the domain being measured. The AI tools themselves (run by companies such as OpenAI, Google and Anthropic) see those questions, not your account details.
- AI model providers
- Plan the questions, read the answers for sentiment and competitor names, and draft the findings. They receive the brand and domain, text we fetched from the scanned site, and the engines’ answers — not your email or payment details. We use an OpenAI-compatible model host (currently Runware, running a DeepSeek model) and, when enabled, Anthropic.
- Razorpay
- Takes all of our payments, from buyers in India and elsewhere. Receives your name, email, the amount, and the payment details you enter on its checkout.
- Resend
- Delivers our email. Receives your email address and the message.
- Cloudflare
- Serves seeninsearch.com, protects it from attacks, runs the anti-bot check on the scan form, and stores our encrypted database backups in its EU region.
- Hetzner
- Hosts the servers our application and database run on, in the European Union.
- Neon
- Hosted our database, in its Singapore region, until September 2026. A copy of data from before that move remains there until we finish closing that database.
- Healthchecks.io
- Is told whether our nightly backup ran. It receives no personal data.
- Google, GitHub or Microsoft
- Only if you choose to sign in with them, or connect Google Search Console or Google Analytics. For sign-in we ask for your email address and name and nothing else, and we never post anything.
- Your own platforms
- If you connect a website (for example WordPress), we send the changes you approve to it. That platform is yours or your provider’s.
We do not sell your data, and we do not share it for advertising. We may also disclose data when the law requires it, for example to a court or government authority, or to a company that takes over our business (which must then protect it the same way).
Where your data is processed
Our servers are in the European Union, and some of the companies above process data in other countries, including the United States. Transfers outside India are allowed under the DPDP Act except to countries the Government of India restricts, and we will follow any such restriction.
Who can read a report
A report you paid for is private when it finishes. It lives at its own address, but until you publish it that address returns “not found” to everyone but you. Publishing is a button on the report page, and you can unpublish again at any time from the same place.
Free teaser scans and scans run for you through one of our partners work the other way round: nobody bought them, their purpose is to be shared, and they are readable by anyone with the address from the moment they finish. No report of any kind is offered to search engines — our robots.txt asks every crawler to stay out of report addresses — but a report that nobody owns is not private either.
We publish pages built from those ownerless scans. A brand profile, a category leaderboard, a head-to-head between two brands: each one carries scores, the brands the engines named, and a link to the report the figures came from. Only scans with no owner are ever used. A report that belongs to a signed-in customer is never included — not while it is private, and not after they publish it, because sharing a link is not the same as asking to be ranked in public. A measurement drops out of these pages automatically once it is more than 90 days old.
Reports quote what answer engines said about a brand. If a report or one of those pages mentions your company and you want it taken down, write to [email protected]. A takedown removes the brand from every published page at once and keeps it out of future ones.
What we email you
Almost everything we send is transactional: a sign-in link, a confirmation, a password reset, a receipt, a report you started. Each one is the direct result of something you did, so there is nothing to opt into and nothing to switch off short of deleting the account.
There is one exception, and it is opt-in. If you monitor a domain, we can email you when something we measured changes. We do not send any of it unless you turn it on. No category is on by default.
- Visibility drops
- When your AI visibility score falls further than run-to-run noise explains. Never sent for a change caused by a different set of engines answering.
- Competitor movement
- When a brand we have not seen before starts showing up in answers about your category, or when one overtakes you on a prompt you track.
- Lost citations
- When a site that used to be cited alongside your brand stops being cited.
- Digest
- One email collecting the alerts you chose, instead of one email each. This is how the alerts above arrive unless you set a category to immediate.
We record the moment you turned each one on and which version of this page was in force at the time. You can turn any of them off from your settings, or with the unsubscribe link at the bottom of every one of those emails — that link needs no sign-in. There is no marketing list.
How long we keep it
A daily job enforces most of this; it is not a promise we keep by hand.
- Sign-in tokens
- Deleted after 24 hours. They stop working within 30 minutes.
- Expired sessions
- Deleted once they expire. A session lasts 30 days.
- Rate-limit records
- Deleted after 7 days.
- IP addresses
- Erased from scans and events after 30 days.
- Raw engine responses
- Blanked after 90 days. The parsed evidence your report displays stays with the report, so old reports keep working.
- Your account and reports
- Kept until you delete them, or until we close the account.
- Payment, invoice and consent records
- Kept after an account is deleted, for as long as Indian tax, accounting and company law requires, and to deal with disputes. They are no longer linked to your account once it is deleted.
- Free-report limit
- To allow one free report per business and per email, we keep a one-way, salted hash of the email and domain, even after deletion. It cannot be turned back into the address.
- Backups
- Encrypted nightly backups are kept for a limited time and then deleted on a rolling basis.
How we protect it
All traffic uses HTTPS. Passwords are stored as scrypt hashes, website credentials are encrypted, backups are encrypted, and access to our servers is restricted. No system is perfectly secure. If a personal data breach happens, we will tell the people affected and the Data Protection Board of India as the DPDP Act requires.
Your rights
Under the DPDP Act you can:
- get a summary of the personal data we hold about you and who we shared it with;
- correct, complete or update it;
- have it erased, unless the law requires us to keep it — you can delete your account yourself from Your data;
- withdraw consent at any time, as easily as you gave it;
- nominate a person to use these rights for you if you die or become unable to;
- complain to our Grievance Officer, and then, if you are not satisfied, to the Data Protection Board of India.
To use any of these, email [email protected] from the address on your account. We may ask you to confirm who you are. We aim to respond within 30 days, and always within the time the law sets. If you live outside India, you may have similar rights under your own law — ask us and we will help.
Children
Seen in Search is a business service for adults. We do not knowingly collect data from anyone under 18. If you think a child has given us data, email [email protected] and we will delete it.
Changes to this policy
The date at the top shows the current version. If we make an important change, we will tell you by email or in the app before it applies, and ask for your consent again where the law requires it.
Contact and Grievance Officer
FactoryJet Private Limited, 70/1, Willow Herbs, Brookefield, Tigalarpalya, Kundalahalli, Bengaluru, Karnataka - 560037, India. Privacy questions and requests: [email protected].
Grievance Officer: Bhavesh Barot, Grievance Officer — [email protected], +91 9699977699. We acknowledge a complaint within 48 hours.
FactoryJet Private Limited · 70/1, Willow Herbs, Brookefield, Tigalarpalya, Kundalahalli, Bengaluru, Karnataka - 560037, India