Legal

Privacy Policy

This Privacy Policy explains how VisibleMax collects, uses, stores, shares, and protects personal information when you use our website and AI visibility software.

Effective date: August 6, 2026
Last updated: August 6, 2026

These pages are provided for transparency and operational clarity. They are not legal advice. VisibleMax is not yet legally incorporated; entity name, registered address, and governing law must be updated after incorporation and reviewed by qualified counsel before relying on these policies for commercial launch, regulatory filings, or customer contracts.

1. Who we are

VisibleMax ("VisibleMax," "we," "us," or "our") is the operating name of the product that provides AI visibility software — helping you understand how AI assistants represent your brand, generate improvement assets, and track visibility over time. Our primary public site is https://visiblemax.site.

Legal entity status. VisibleMax is not yet legally incorporated. Until incorporation is complete, these policies refer to the product by its operating name. After incorporation, we will update this Policy with the registered legal entity name, registered address, and governing law. Placeholder for counsel update: [PLACEHOLDER — update after incorporation: registered legal entity name, registered address, and governing law / venue].

For privacy inquiries and data-subject requests, contact [email protected]. For security incidents or vulnerability reports, contact [email protected] or see our Bug bounty program.

Depending on your relationship with us, VisibleMax typically acts as a data controller for account, billing metadata, product analytics (when consented), and website visitor data, and as a processor (or equivalent) for customer content you submit for scanning and analysis.

2. Scope

This Policy applies to:

  • Our marketing website, documentation, and related public pages
  • The VisibleMax application (accounts, projects, scans, reports, plans, Content Studio, monitoring, and free tools)
  • Communications we send about the Service (transactional and, where permitted, product updates)

It does not control the privacy practices of third-party AI platforms you interact with through probes (OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini), Perplexity, xAI (Grok), DeepSeek), payment processors, or other websites you visit. Those parties have their own policies.

At launch, VisibleMax does not offer Enterprise plans, team / multi-seat collaboration, MCP integrations, or a Chrome extension. This Policy describes the shipped Free and Pro Early Adopter product only.

3. Information we collect

3.1 Account and profile information

When you create or manage an account, we may collect:

  • Name, email address, and authentication identifiers
  • Password hashes or OAuth identifiers (via our auth provider, Supabase)
  • Project or company profile details you provide
  • Profile preferences and onboarding answers you provide

3.2 Website URLs and customer content you submit

To provide the Service, you may submit website URLs, domains, brand names, competitor references (up to the Pro limit), prompts, and related configuration. We process that information to crawl, analyze, probe, and report on AI visibility.

3.3 Crawl, scan, and probe data

When you run scans or related jobs, we may process:

  • Publicly reachable page content, metadata, headers, sitemaps, and technical signals from URLs you authorize us to fetch
  • Extracted entities, findings, scores, recommendations, and generated assets (for example FAQ drafts, schema snippets, or llms.txt drafts)
  • Probe prompts and model responses returned by third-party AI providers used to deliver the Service
  • Job status, timestamps, error messages, and usage metering related to those runs

You should only submit URLs and content you are authorized to have scanned. Do not submit secrets, credentials, or confidential materials that are not needed for the Service.

3.4 Usage and device data

We automatically collect certain technical data, such as:

  • IP address, approximate location derived from IP, browser type, device type, and operating system
  • Pages viewed, feature usage, referring URLs, and interaction events (including optional PostHog analytics when you consent — see Cookie Policy)
  • Log data needed for security, debugging, rate limiting, and reliability

3.5 Billing and payment information

Paid subscriptions are processed by Polar, which acts as merchant of record / payment processor for applicable purchases. At launch, the sole paid offer is VisibleMax Pro Early Adopter ($50/year, with a 7-day free trial). Polar typically collects payment method details, billing contact information, tax information, and transaction records. VisibleMax receives subscription status, plan entitlements, invoices or receipt metadata, and related billing events needed to unlock paid features. We do not store full payment card numbers on VisibleMax servers.

3.6 Cookies and similar technologies

We use cookies and similar technologies for essential authentication (including Supabase session cookies), security, preferences, and — where you consent via our cookie banner — optional PostHog product analytics. Details are in our Cookie Policy.

3.7 Communications

If you email us at [email protected], we process the content of that correspondence and associated metadata to respond and improve support quality. Support is provided through this address only; we do not maintain separate sales or Enterprise support channels at launch.

4. How we use information (purposes)

We use personal and account data to:

  • Provide, operate, maintain, and improve the Service
  • Authenticate users, manage projects, and enforce Free and Pro entitlements (including the lifetime Free scan and Pro trial / annual billing)
  • Run crawls, analyses, AI probes, asset generation, monitoring, and related workflows you request
  • Process subscriptions, trials, usage limits, cancellations, and billing events via Polar
  • Send transactional messages (security alerts, receipts, product notices)
  • Monitor abuse, prevent fraud, enforce our Terms of Service, and protect the Service
  • Analyze aggregated or consented usage to improve reliability, UX, and product roadmap
  • Comply with law and respond to lawful requests

5. Customer data is not used to train AI models

VisibleMax does not use customer data to train AI models. VisibleMax does not use customer data to train AI models. Customer site content and account data may be processed by third-party AI providers solely to deliver product features (analysis, probing, and asset generation). Customer site content, account data, scan results, and probe outputs are processed solely to deliver the features you request — not to train VisibleMax models or to authorize third-party providers to train on your customer data for their own general-purpose models through our use of their APIs, to the extent we control that configuration.

When we send prompts or context to third-party AI providers to deliver a feature, those providers process that traffic under their own terms. We configure providers for product delivery, not for training on your customer data. See AI Transparency for the provider list and related limitations.

6. Legal bases (GDPR-style)

If the EU/UK GDPR or similar laws apply, we rely on one or more of the following bases:

  • Contract — to provide the Service you request (account, scans, billing entitlements)
  • Legitimate interests — to secure the Service, prevent abuse, improve product quality, and communicate service updates, balanced against your rights
  • Consent — where required for optional PostHog analytics cookies, certain marketing messages, or other consent-gated processing
  • Legal obligation — where we must retain or disclose information to comply with applicable law

7. How we share information

We do not sell personal information. We share data only as described below:

  • Service providers / subprocessors that process data on our behalf (hosting, database/auth, billing, email, job orchestration, caching/rate limits, AI inference, optional analytics)
  • Corporate transactions (merger, acquisition, or asset sale), subject to appropriate confidentiality — including after incorporation when a legal entity is formed
  • Legal and safety disclosures when required by law or necessary to protect rights, users, or the public
  • With your direction — for example when you export data or publish a public shareable report

8. Processors and subprocessors

Depending on configuration and feature use, VisibleMax may engage the following categories of providers:

  • Vercel — application hosting, edge/network delivery, and serverless compute
  • Supabase — authentication, database, and related backend storage services
  • Polar — payments, subscriptions, trials, invoices, and merchant-of-record functions
  • AI model providers — third-party large language model APIs used for analysis and probing: OpenAI (ChatGPT); Anthropic (Claude); Google (Gemini); Perplexity; xAI (Grok); DeepSeek
  • Trigger.dev — background job orchestration for long-running scans and workflows
  • Resend or similar email providers — transactional email delivery when email notifications are enabled
  • Upstash — Redis-backed rate limiting, metering, or ephemeral counters when configured
  • PostHog — optional product analytics, gated by cookie consent (see Cookie Policy)

AI providers receive prompts and context necessary to return analysis or probe results. Customer data is not used to train AI models. See AI Transparency.

9. International transfers

VisibleMax and its providers may process data in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as standard contractual clauses or provider terms that include them) and apply reasonable safeguards. Exact transfer arrangements and governing law will be confirmed after incorporation and counsel review. Placeholder: [PLACEHOLDER — update after incorporation: registered legal entity name, registered address, and governing law / venue].

10. Retention

We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Typical patterns:

  • Account data — retained while your account is active; deleted or anonymized within a reasonable period after deletion requests, subject to legal holds
  • Scan and report data — retained according to plan limits (including the Free lifetime scan entitlement), product needs, and your deletion requests
  • Billing records — retained as required for tax, accounting, and fraud prevention (often via Polar)
  • Security logs — retained for a limited operational window unless needed for investigations

11. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data, and to object to certain processing. You may also withdraw consent where processing is consent-based (including optional analytics).

To exercise rights, email [email protected] from the address associated with your account and describe your request. We may need to verify identity before fulfilling requests.

12. California privacy notice (CCPA/CPRA-style)

If you are a California resident, you may have rights to know what personal information we collect, request deletion, correct inaccurate information, and opt out of "sale" or "sharing" for cross-context behavioral advertising as those terms are defined by law.

VisibleMax does not sell personal information for money. We do not knowingly engage in cross-context behavioral advertising as a core part of the product. Optional PostHog analytics, when enabled by consent, is used for product improvement — not for selling personal information.

Categories of personal information we may collect include identifiers (email, account ID), commercial information (subscription / trial status), internet activity (usage logs), and customer content you submit for scanning. We use these categories for the business purposes described above.

To submit a California request, contact [email protected]. You may designate an authorized agent subject to verification requirements.

13. Children's privacy

The Service is directed to businesses and professionals. We do not knowingly collect personal information from children under 16 (or the higher age required in your jurisdiction). If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.

14. Security

We implement administrative, technical, and organizational measures designed to protect personal information. No method of transmission or storage is perfectly secure. More detail is available on our Security page. Report vulnerabilities to [email protected] or via Bug bounty. We do not claim SOC 2 or similar certifications at this time.

15. Changes to this Policy

We may update this Privacy Policy from time to time, including after incorporation when entity details are finalized. We will post the updated version with a revised "Last updated" date. Material changes may be communicated by email or in-product notice when appropriate.

16. Contact

Privacy and data requests: [email protected]
Security: [email protected]
Website: https://visiblemax.site

Related policies