Privacy Policy
Last updated: 23 September 2026
1. Who we are and what this covers
SignalKit (signalkit.ai and app.signalkit.ai) tracks how AI assistants mention, rank and cite brands. This policy covers the personal data we collect when you visit our site, create an account, use the product, or connect a third-party integration such as Google Analytics or Google Search Console. It applies to every plan.
For account data we are the data controller. For the brands, prompts, and integration data you bring into the product, we act as your processor. The GDPR-specific detail is on our Data Protection page.
2. Information we collect
Account information. Your email address, name and profile image, managed through our authentication provider (Clerk), plus your account settings and notification preferences.
Billing information. Payment is handled by Stripe. We store a Stripe customer reference and invoice history; we never see or store card numbers.
Data you enter. The brands, competitors, domains, prompts and regions you configure, and the site URL you submit for a free audit.
Measurements we generate. The answers AI platforms return to your prompts, and what we compute from them: brand mentions, positions, sentiment, citations, scores and alerts.
Connected integrations. If you connect Google Analytics, Google Search Console, Google Merchant Center, Shopify, Cloudflare or Slack, we receive data from those services as described in sections 4 and 5.
Usage and technical data. How you use our site and dashboard (section 9), and server logs containing request metadata, timestamps and error reports.
3. How we use information
To provide the service: run your prompts against the AI platforms you track, store and present the results, send the alerts and digests you ask for, bill your subscription, and support you. To keep the service working: detect abuse, diagnose errors, and measure which features are used. To tell you about SignalKit, only where you have agreed to that. We do not sell personal information, and we do not use it for advertising.
4. Google user data
This section applies if you connect Google Analytics, Google Search Console or Google Merchant Center to a SignalKit project. It describes how we access, use, store and share the data we obtain through Google APIs.
What we request. Each integration asks for one scope, and nothing else:
- Google Analytics —
analytics.readonly: list the GA4 properties you can access, and read reports from the one you choose. - Google Search Console —
webmasters.readonly: list the properties you can access, and read search performance data from the one you choose. - Google Merchant Center —
content: list the Merchant Center accounts you can access, and read the product listings of the one you choose. Google offers this scope only in a form that also permits writes; SignalKit never creates, changes or deletes a listing, and issues read requests only.
Each is granted separately, on Google's consent screen, and can be withdrawn separately. SignalKit changes nothing in your Google account. Google Analytics can alternatively be connected by adding a SignalKit-owned service account as a Viewer on your property; in that case no Google token of yours is stored at all.
What we retrieve and store. From Google Analytics: a daily report over the property you selected, broken down by session source and medium, landing page, hostname, country, session channel group, device category and date, with session, engagement, key-event and revenue totals — aggregated figures, not individual visitors. From Search Console: daily clicks, impressions, click-through rate and position by search query, page, country and device. From Merchant Center: for each product in the account you selected, its identifier, title, product type, link and price, re-read once a week — no orders, no customers, no account settings. We also store the property or account you selected and the OAuth access and refresh tokens, encrypted (AES-256-GCM) before they reach our database. No endpoint of ours ever returns a token.
How we use it.To show you, in your own dashboard, how much of your site's traffic comes from AI assistants and what it is worth; to place that beside the visibility measurements SignalKit collects; to show what your site earns in Google search; and, if you run a site audit on a project with Google Analytics connected, to include the AI-attributed share of your traffic in that audit. Merchant Center product listings are used for one purpose: to recognise your products by name in the answers AI assistants give, so you can see which products they recommend, in what position and at what quoted price. With separate, revocable permission from an organization owner or administrator, we may also use selected Search Console and Analytics measurements to ground content you ask an AI model to write.
With whom we share, transfer or disclose it. Google user data is stored and processed by the infrastructure providers that run SignalKit: Neon (database, encrypted at rest) and Hetzner (application servers, Germany). When you run a site audit on a project with Google Analytics connected, an aggregated summary — the share of sessions and revenue attributed to AI assistants and the top AI referrers — is sent through Cloudflare AI Gateway to Anthropic, the model vendor that writes the audit narrative. No row-level data, no search queries, no property identifiers and no Google account details are included, and Anthropic's commercial API terms do not allow it to train models on that data. To recognise products in an answer, the product identifiers and titles from your catalogue are sent with that answer to Anthropic the same way; prices, links and account details are not included. If your organization separately enables Google data for content AI, relevant Search Console queries, clicks, impressions and page URLs, and aggregated Analytics page visits and key events may be included in content-generation prompts. Those prompts go to the selected model provider through SignalKit's managed route, or to OpenAI, Anthropic or Z.AI through your own provider key. The provider's own terms and account settings govern its processing. You can revoke this permission in Content; new connections require a separate grant. Otherwise Google user data is shared only with people you add to your SignalKit company, in reports and exports you generate, and where the law requires it (section 5).
What we never do. We do not sell Google user data. We do not use it for advertising, or to build profiles of your visitors. We do not use it to develop, improve or train generalised artificial-intelligence or machine-learning models. We do not transfer it to third parties except as stated above. Our staff do not read it except to support you at your request, to investigate abuse or a security incident, or to comply with the law.
Retention and deletion. Search Console data is kept for 90 days on a rolling basis. Google Analytics summaries are kept for as long as the project exists. A Merchant Center catalogue is replaced at each weekly read and kept for as long as the connection exists. Disconnecting an integration from your project settings deletes the stored tokens immediately and asks Google to revoke SignalKit's access, unless another of your connections still uses the same Google sign-in; the Search Console history and the imported catalogue, with every product match made from it, go with it, and the Analytics summaries already collected stay on the project until you delete the project or your account. You can also revoke SignalKit's access at any time from your Google Account permissions page or, for a service-account connection, by removing the account from your property. Deleting a project or closing your account deletes all of its Google-sourced data.
Limited Use. SignalKit's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. How we share information
Service providers. We use the subprocessors below to run SignalKit. Each receives only what its role needs, under a contract that binds it to protect the data. We review the list annually and update this page when it changes.
- Neon — managed PostgreSQL database
- Hetzner — application hosting (Germany)
- Clerk — authentication and account identity
- Stripe — payment processing; card details never reach SignalKit
- OpenAI, Anthropic, Google (Gemini), xAI, Perplexity, and Z.AI — AI providers used for measurement or content generation. A customer-key content call goes directly to the provider selected by your account. Content calls can include brand material and page evidence you provide.
- SerpAPI — Google AI Overviews retrieval; receives prompt text only
- Cloudflare — AI request routing (AI Gateway) and DeepSeek model hosting, edge proxy and TLS termination for public sites, Turnstile abuse prevention for free audits, and crawl data only if you connect the integration using credentials you supply.
- Inngest — background jobs
- Resend — transactional email (alerts, digests)
- Sentry — error monitoring
- PostHog — product analytics (EU hosting)
- Google Analytics 4 — usage analytics for signalkit.ai
- DataForSEO — search-volume data, and a weekly Google search for each tracked prompt's search keyword to see whether an AI Overview shows and whom it cites. It receives the keyword, country and language; no customer account data is sent.
- Google (Analytics and Search Console APIs) — only if you connect an integration, and only to read your own property's data using the access you grant. Google is the source of that data, not a recipient of it.
AI platforms. The prompts you track are sent to the AI platforms you select, through Cloudflare AI Gateway or directly, exactly as written. They receive the prompt text and nothing that identifies you or your account. Their answers are stored by us as your measurements. Content you ask AI to write is sent with its brief and selected supporting evidence to the model provider you choose. Google measurements are included only after the separate permission described in section 4.
Cloudflare (integration). If you connect Cloudflare with an API token you create, we read crawl and traffic analytics for the zone you select. The token is stored encrypted and the analytics stay on your project.
Slack (integration). If you connect Slack, the SignalKit Slack app asks for two permissions: chat:write, to post the notifications you set up into the channels you choose, and channels:read, to list the names of your workspace's public channels so you can pick one by name. We store the workspace name and each chosen channel's ID and name. SignalKit never reads messages, member lists or private channels. The bot token is stored encrypted; disconnecting deletes it, and removing the app from your workspace revokes it.
At your direction. People you invite to your SignalKit company see the projects you grant them. Reports you export, links you share, and API keys or MCP connectors you create carry your data to wherever you point them.
Legal and corporate. We disclose information where the law requires it, to protect the rights, safety or property of SignalKit or others, or to a successor in a merger, acquisition or sale of assets, in which case this policy continues to apply and we will notify you.
6. Data retention
Account data is kept for as long as your account exists. Measurements (AI answers and what we compute from them) are kept for as long as the project they belong to exists, so that your history stays comparable over time. Search Console data is kept for 90 days; raw AI traffic pixel visits for 30 days. Anonymous free-audit reports expire after 30 days; their IP addresses are removed after seven days. Diagnostic activity is kept for 90 days. Cleanup runs daily. Records needed to prevent duplicate messages or explain changes to your prompts and measurement settings are retained with the project. Database backups are kept daily for 14 days and weekly for a further 8 weeks. When you delete a project, its data is deleted with it. When you ask us to close your account, we stop all processing at once and delete your data within 30 days, except what we must keep for tax and accounting.
7. Security
Data is encrypted in transit (TLS) and at rest. Integration tokens are encrypted with AES-256-GCM before storage; API keys are stored as one-way hashes. Every query is scoped to your account, and access to production systems is limited to named engineers over an identity-bound private network. If a breach affects your personal data, we will notify you without undue delay.
8. Your rights
You can view and update your profile and settings in the app. You can disconnect any integration from project settings, and delete any project. To access, export, correct or delete your personal data, or to close your account, email hello@signalkit.ai and we will respond within 30 days. EU and UK residents have additional rights, described on the Data Protection page.
9. Cookies and site analytics
We use essential cookies for sign-in and session management. On signalkit.ai and in the dashboard we also use Google Analytics 4 and PostHog (EU-hosted) to understand how the site and product are used. Both set analytics cookies and record page views and feature use; PostHog does not create a person profile for you. Neither runs on pages opened through a shared report link. You can block analytics cookies in your browser, and most ad and tracker blockers stop both.
10. AI traffic pixel (optional)
If you install our tracking snippet on your own site, we record, per pageview: the page path — with any query string, fragment and embedded credentials removed before it is stored — the AI assistant the referrer resolved to, and, only where our hosting injects a verified country header, a two-letter country.
We do not set cookies or use any browser storage, we do not create a visitor or device identifier, we do not fingerprint, and we do not store or transmit IP addresses or user-agent strings. There are no sessions and no conversion tracking. Raw visit records are deleted after 30 days.
This telemetry is a floor, not a total: ad blockers, consent tooling and assistants that strip the referrer all remove visits from it. Installing the snippet does not remove your own consent obligations — omitting IP addresses is not the same as being exempt from consent. The snippet posts only to SignalKit, so it adds no sub-processor.
11. Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we use or share your data, we will notify account holders by email before it takes effect.
12. Contact
For privacy questions or requests, email hello@signalkit.ai.