Privacy Policy
Effective: March 5, 2026 · Last updated: March 20, 2026
DekAI ("we," "us," or "our") operates the dekai.ai platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect your email address and, optionally, your name. We use magic-link (passwordless) authentication — we do not store passwords.
1.2 Business Information
You provide your business name, city, state, vertical category, website URL, and phone number. This information is used to run AI visibility audits on your behalf.
1.3 Payment Information
Payment is processed by Stripe. We do not store credit card numbers. We receive your Stripe customer ID and subscription status.
1.4 AI Probe Data
We send only your business name and public geographic information to third-party AI models (OpenAI, Anthropic, Google Gemini, Perplexity) to analyze how AI assistants mention your business. We never send personally identifiable information (PII) such as your email address, phone number, or payment details to any AI model.
1.5 Automatically Collected Information
We collect standard server logs (IP address, browser type, pages visited) for security and service improvement. We hash IP addresses before storing consent records.
1.6 Google Analytics
We use Google Analytics 4 ("GA4") to understand how visitors interact with our website. GA4 collects data such as pages visited, session duration, device and browser type, and approximate geographic location. This data is collected via first-party cookies set by our domain.
Google processes this data on our behalf under the Google Analytics Terms of Service. To learn more about how Google uses data from sites that use Google Analytics, visit google.com/policies/privacy/partners.
Opt-out: You can opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on, by declining analytics cookies via our cookie consent banner, or by enabling Global Privacy Control in your browser.
1.7 Google Analytics & Search Console Integration
If you choose to connect your Google Analytics (GA4) or Google Search Console account to DekAI, we request read-only access via Google OAuth 2.0. Specifically, we request the following scopes:
analytics.readonly— Read your GA4 property data (sessions, engagement, conversions, traffic sources)webmasters.readonly— Read your Search Console data (search queries, impressions, clicks)
We use this data to:
- Estimate AI influence on your customer discovery
- Compare AI visitor quality against your site average
- Identify conversion patterns from AI-referred traffic
- Compute your AI Discovery Funnel
Data handling: We sync aggregated metrics daily and store them as snapshots in our database. We do not store raw Google Analytics user-level data. We do not access, store, or process any personally identifiable visitor data from your GA4 property.
Your control: You can disconnect your Google account at any time from your DekAI dashboard settings. Upon disconnection, we stop all data syncing immediately and delete stored snapshots within 30 days.
Compliance: Our use of Google API data adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell, lease, or share your Google data with third parties, except as necessary to provide the Service (see Subprocessors).
2. How We Use Your Information
- Service delivery: Running AI visibility audits, generating reports, computing scores
- Communication: Sending reports, alerts, and account-related emails
- Billing: Processing payments via Stripe
- Improvement: Analyzing aggregate, anonymized usage patterns
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process personal data under the following legal bases:
- Performance of contract (Art. 6(1)(b)): Processing necessary to deliver the Service you subscribed to
- Legitimate interests (Art. 6(1)(f)): Aggregate analytics to improve the Service, provided these do not override your fundamental rights
- Consent (Art. 6(1)(a)): For optional analytics cookies (when implemented) — you may withdraw consent at any time
4. Your Rights
4.1 All Users
- Access a copy of your personal data
- Request correction of inaccurate data
- Request deletion of your account and data
- Export your data in a portable format (JSON)
4.2 EEA Residents (GDPR)
- Right to restriction of processing
- Right to object to processing based on legitimate interests
- Right to data portability
- Right to lodge a complaint with your local data protection authority
4.3 California Residents (CCPA/CPRA)
Notice at Collection: We collect identifiers (email), business information (name, location), and internet activity (usage logs) for the purposes described in Section 2.
Your Privacy Choices: You have the right to:
- Know what personal information we collect and how it is used
- Delete your personal information
- Opt out of the sale or sharing of personal information — we do not sell your personal information
- Non-discrimination for exercising your privacy rights
To exercise these rights, email privacy@dekai.ai or use the data export/deletion features in your account settings.
4.4 Canadian Residents (PIPEDA)
Our Privacy Officer can be reached at privacy@dekai.ai. You have the right to access your personal information, challenge its accuracy, and withdraw consent for non-essential processing.
4.5 Brazilian Residents (LGPD)
You have the right to data portability. Upon request, we will provide your data in a structured, machine-readable format within 15 business days. Contact privacy@dekai.ai.
5. Data Sharing & Subprocessors
We share data only with service providers necessary to operate the platform. See our Subprocessor List for a complete inventory. We do not sell personal data to third parties.
6. AI-Specific Disclosures
DekAI uses large language models (LLMs) from OpenAI, Anthropic, Google, and Perplexity to analyze AI visibility. These models receive:
- Your business name
- Your city and state
- Your business vertical (e.g., "personal injury law")
They do not receive your email, phone number, payment information, or any other PII. AI-generated recommendations in our reports are informational only and should be reviewed by a qualified professional before implementation.
For details on the AI models used, see our reports' Methodology section or our Subprocessor List.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account, plus 30-day grace period |
| Probe results & reports | 12 months from generation |
| Free audit data | 90 days from completion |
| Consent records | 5 years (regulatory requirement) |
| Server logs | 90 days |
| GA4 / Search Console snapshots | 12 months from sync, or 30 days after disconnection |
8. Security
We implement industry-standard security measures including HTTPS encryption, secure authentication (magic links with expiry), hashed IP storage, and access controls. See our Data Processing Addendum for technical details.
9. Cookies
We use essential cookies for authentication and security, and analytics cookies (Google Analytics) to understand site usage. Analytics cookies are off by default and require your consent. See our Cookie Policy for a full list of cookies, including GA4 cookies, and how to manage your preferences.
10. International Transfers
Your data may be processed in the United States and Canada. We have executed Standard Contractual Clauses (SCCs) approved by the European Commission (2021/914) with each subprocessor that processes personal data outside the EEA. Copies of executed SCCs are available upon request to privacy@dekai.ai.
11. Children's Privacy
DekAI is a B2B service not directed at individuals under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We will notify registered users by email at least 30 days before any material changes. The "Last updated" date at the top reflects the most recent revision.
13. Contact
Privacy Officer: privacy@dekai.ai
DekAI · Ontario, Canada · For mailing address, contact privacy@dekai.ai