Privacy notice · Version 2026-09-09 · Effective 7 September 2026
What we collect, and what we do with it.
The short version: we keep what you type into the scan form only to run the scan and email you the result. We do not sell it, we do not hand it to advertising networks, and this site stores nothing in your browser. The rest of this page is the long version.
Who we are
This site and the service behind it are operated by AIChoosingYou LLC, a Delaware limited liability company, at Delaware, USA - “we”, “us”, “AI Choosing You”. We decide why and how the information described here is used, which makes us the controller of it.
One address reaches us for everything on this page, including a request to see or delete your data: [email protected].
This is a service for businesses. It is not intended for consumers, for personal or household use, or for anyone under 18.
What we collect
When you ask for a free scan
The form asks for five things, and stores exactly those five: your business name, your city and state, your website (or the fact that you have none yet), your trade, and a work email address. Nothing on the form is optional-but-hidden, and there are no fields you cannot see.
Stored beside them is what any web server receives with a request: your browser’s user-agent string, and the country, region and city our host works out from the connection your request arrived on. If you reached us by clicking a link in one of our emails, the short code in that link is stored too, so we know which message brought you and can stop emailing you about it.
If you display our badge
If you take part in the badge programme we store the address of the one page you gave us and the result of each daily check - seen, not found, or unreachable - so that the discount can be applied to your invoice. When a visitor to your site loads the badge image, their browser reaches our server for that image, the way it reaches any image on a page; we keep only an aggregate count of how often each badge was drawn and from which site, never that visitor’s IP address, and the image sets no cookie and stores nothing on their device.
If someone invited you
An invite link carries a short code in the address (?r=). If you arrive with one and then send the form, we store that code beside your request, so we know which of our customers referred you and can credit them a free month when you buy. That is the whole of it: the customer who invited you is shown counts - how many people opened their link, ran a scan, or bought - and never your name, your business, your city or your email. Nothing is written to your browser; delete the code from the address and the page behaves like any other visit.
When you become a customer
An order adds what an order needs: what you bought, what you paid, the invoice and its references, the correspondence about the work, whatever you tell us about your business so the work is right, and the reports and monitoring history we produce for you. We never see or store your card number.
About your business, from public sources
The work itself is reading what is already public: your website, your Google Business Profile and other public listings, public reviews, and what consumer AI assistants answer when they are asked the questions your customers ask. That material is about a business rather than about a person, but a small business is often named after the person who runs it, so we treat it with the same care.
If we emailed you first
We send cold outreach to businesses that fit a trade and a city. The contact details in those campaigns come from public business listings, from the businesses’ own websites, and from commercial business-listing data providers - never from a scraped consumer list, and never from anyone who has told us to stop. We hold a business name, a business address or city, a business website and a business mailbox, plus which messages we sent and whether they were delivered.
Every one of those emails carries a working unsubscribe link and our postal address. Using it, or replying with “stop”, or writing to [email protected], puts the address on a suppression list within ten business days and normally the same day. That list is the one thing we keep for good: it is the only way to be sure we never import you again.
What we use it for
- running the scan you asked for and emailing you the result;
- preparing, delivering and correcting a report, a plan, a site or the monitoring you bought;
- invoicing, taxes, refunds and the records our accountants and tax authorities require;
- answering you when you write to us;
- keeping the form from being abused, and keeping one free scan per business;
- knowing which of our own pages and emails work, from counts rather than from profiles;
- contacting businesses about the service, subject to the unsubscribe above.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use what you send us to train an AI model of our own, and we do not paste it into a public AI service.
No patient data
Several of the trades we measure are medical. Do not send us patient names, appointments, records, images, diagnoses, treatment or insurance details, or any other patient-identifiable information.
We do not ask for protected health information, we do not offer a Business Associate Agreement, and we are not designed to act as a HIPAA business associate. If we find we have received such material by accident, we restrict access to it and delete it as soon as we reasonably can, with a target of 72 hours, and it is never used in a report or in any other processing.
Who else touches it
We keep the list of companies that process this data deliberately short, and every one of them is named here:
| Company | What it does for us |
|---|---|
| Cloudflare, Inc. (United States) | Hosts the site, runs the form’s code, holds the database the form writes to, and sits in front of the site as its network and security layer. |
| Forward Email LLC (United States) | Delivers the notification and result emails that the form triggers. |
| Our outreach platform | Sends and tracks the cold-email campaigns described above. Named on request at [email protected]. |
We also send questions to consumer AI assistants - ChatGPT, Gemini, Perplexity, Claude, DeepSeek and Mistral - because that is the measurement. Those questions are the ones your customers would type, such as the best studio of your kind in your city. The only thing about you that can appear in one is your business’s public name or its city. Your email address, and anything else you typed into the form, is never sent to them.
Beyond that, we disclose information only to our professional advisers, or when the law requires it, or when it is necessary to establish or defend a legal claim.
We are a United States company using United States providers, and the data is processed in the United States.
Cookies, and how we count visits
There are no cookies. This site sets none, writes nothing to your browser’s storage, and loads no code belonging to another company - no third-party analytics product, no advertising pixel, no chat widget, no hosted fonts. The cookie page shows you how to verify that in four steps, and lists every address a page here calls.
We do count what happens on our own pages, with our own code, posting to our own address at /api/e. Two short messages per visit at most: one when a page opens, one as you leave. Each carries the page you were on, whether you are on a phone or a desktop, a random number made for that single page load and stored nowhere, the site that referred you, the campaign code if you arrived from one of our emails, and a few named events such as having reached the prices or opened the form. It carries nothing you typed, and no identifier that outlives the page.
Those events go to Cloudflare’s Analytics Engine, which holds them as aggregate counts rather than as records about a person, and they are never written to the database that holds form submissions. If your browser sends Do Not Track or Global Privacy Control, none of the counting runs.
How long we keep it
| What | How long |
|---|---|
| A scan request that does not become an order, and the technical data stored with it | 24 months after the last contact with you |
| Customer records: orders, invoices, delivered reports, monitoring history | While you are a customer, then 7 years for tax and accounting |
| Email you send us and our replies | 24 months after the thread is closed |
| Outreach contact details and send history | 24 months after the last message, unless you become a customer |
| Unsubscribe and suppression records | Kept indefinitely - it is the only way to keep you off future lists |
| Our host’s rolling backups | Up to 30 days |
A shorter period required by law wins over this table. A deletion you ask for is done within 30 days in the live systems; copies inside backups age out within the following 30 days.
Your choices
Write to [email protected] and you can ask us to show you what we hold about you, correct it, delete it, or stop emailing you. We may need to check that you are who you say you are, and that you speak for the business, before we act. We will not treat you worse for asking.
Depending on where you are, the law may give you further rights over this information, including the right to complain to a regulator. Nothing on this page takes away a right you have by law.
How it is protected
Access is limited to the people who need it, credentials are scoped and held on the server side, traffic is encrypted in transit, and the code that receives the form is the only path into the database. No system is perfectly secure, and we will not claim otherwise. If a breach affects you, we will tell you and any regulator that has to be told, as quickly as we reasonably can.
Changes
If this notice changes, the version and date at the top change with it, and we will say what moved. If a change means we want to use information we already hold for something new, we will tell you before that starts.
Version 2026-09-09 · effective 7 September 2026 · questions to [email protected] · see also the Terms of Service and the contact page.
The exact text of this version is fingerprinted (SHA-256) in /legal/versions.json, and every scan you submit records which version was live.