Legal

Privacy Policy

Effective: August 22, 2026 · Wilphia LLC · hello@answergist.com

Who we are

Answergist is operated by Wilphia LLC, a Washington, USA company, which is the data controller for the personal data this policy covers. Contact: hello@answergist.com.

Information we collect

Your email address (to send audit reports and sign-in links, and as your account identifier); the product URL you submit for an audit; your IP address, used for rate limiting; scan results, including the engine answers our audits generate about the scanned site; your payment status from Stripe (we never see your card number); and, if you sign in with Google, the email address Google confirms — nothing else from your Google account.

Information we do not collect

We don't run analytics trackers or ad pixels, we don't buy data about you, and we don't set cookies beyond the three listed below.

How we use your information

To run your audit and email you the report; to operate accounts, subscriptions, and billing; to send the weekly re-scan report emails paid plans include (you can turn these off in your account); to keep the service secure and enforce rate limits; and to comply with legal obligations. We don't use your data to train AI models.

Legal bases

Where GDPR or similar laws apply, we process your data on these bases: performance of a contract (running audits and subscriptions you asked for); legitimate interests (security, rate limiting, improving the service); consent (where required — you can withdraw it anytime); and legal obligation (tax and accounting records).

Who we share it with

Only the service providers that operate Answergist, each bound by their own data-protection terms: Stripe (payments), Resend (email delivery), Neon (database hosting), Vercel (application hosting), and Inngest (job processing). Each scan also sends its questions to the AI engines it measures — ChatGPT (OpenAI), Perplexity, and Google AI Overviews (Google) — those questions are about the scanned product, not about you, but the engine operators process them under their own policies. We don't sell your personal data, and we don't share it for cross-context behavioral advertising.

Public scorecards and the Visibility Index

Every audit report lives at its own unguessable URL and is excluded from search-engine indexing on its own — that's the default for every report, listed or not. Anyone who holds the link can view it; treat the link as shareable, not private.

If a site's verified owner lists it on the public Visibility Index, we publish a separate summary for that domain — score, per-engine breakdown, last-scanned date — on an indexable page that search engines can crawl and show in results, and that summary links to the full report. Listing is opt-in and reversible from the owner's account; an unlisted site's report stays reachable only by its own unguessable link.

Sponsored placement clicks

Clicking a sponsored listing's link on our front-page board or sponsor pages increments a per-domain click counter — an aggregate total, not a per-visit or per-visitor record. We don't set a cookie for this, and we can't tell from it who clicked or how many times any one visitor did.

Cookies

We set three cookies, all essential: ag_session (keeps you signed in; expires after 30 days), ag_signed_in (a yes/no hint that lets the site header show “Account” instead of “Sign in”; contains no personal data), and ag_oauth_state (protects Google sign-in against forgery; lives 10 minutes and only during sign-in). No analytics or advertising cookies — which is why there's no cookie banner.

Data retention

Audit and scan data is kept to power caching, trend history, and the public Visibility Index. Account data is kept while your account exists. Sign-in tokens expire after 15 minutes and are stored only as hashes. When you delete your account we delete your personal data within 30 days, except records we must keep for tax or accounting.

Security

All traffic is encrypted in transit (TLS). Sign-in links are single-use and stored hashed, so a database leak can't yield usable links. Sessions are signed cookies. Card details go directly to Stripe and never touch our servers. No system is perfectly secure, but we design so that a breach exposes as little as possible.

If there's a breach

If a data breach affects your personal data, we'll notify you and the relevant authorities without undue delay, as applicable law requires, and tell you what happened and what we're doing about it.

International transfers

We're a US company and process data in the United States. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on our providers' safeguards, including Standard Contractual Clauses and, where applicable, Data Privacy Framework certifications.

Your rights

Depending on where you live, you can request access to, correction of, deletion of, or a portable copy of your personal data, object to or restrict certain processing, and withdraw consent. Email us at the address below; we'll respond within 30 days. If you're in the EEA or UK, you can also complain to your data-protection authority.

US state privacy rights

If you live in California or another US state with a privacy law, the same rights apply: know, access, correct, delete, and portability. We don't sell personal data or share it for cross-context behavioral advertising, so there's nothing to opt out of — and we never discriminate against you for exercising your rights. Authorized agents may submit requests on your behalf with proof of authorization.

Children

Answergist isn't directed at anyone under 16, and we don't knowingly collect data from them.

Changes to this policy

We may update this policy as the service changes. We'll post the revised policy here with a new effective date, and for material changes we'll email account holders before they take effect.

Contact

Questions, rights requests, or a copy of our data-processing agreement for business customers: hello@answergist.com.