NewContinuous monitoring is live — weekly deep reports, daily pulse & alerts
Visitd

Legal

Privacy Policy

Last updated: July 25, 2026

The short version

We collect the minimum needed to run the product: your email if you give it to us, one strictly-necessary login cookie if you create an account, and the scan data you ask us to produce. No advertising trackers, no third-party tracking cookies, no selling data. [COMPANY LEGAL NAME] is the data controller.

What we collect

Waitlist & scans: the email address and website URL you submit, plus an optional source tag telling us which campaign brought you (from UTM parameters in the link you clicked). We use your email to deliver your report and product updates about it — one-click unsubscribe, no spam.

Accounts: email, optional name, and a securely hashed password (scrypt — we can't read it).

Payments: handled entirely by Dodo Payments, our Merchant of Record. We receive confirmation that a scan was paid for — never your card details.

Scan results: the domain, scores, engine answers and structural findings for every scan. This dataset is the product: it persists, powers the public AI Visibility Index (domain + score), and feeds aggregate statistics. Scan results describe websites, not people.

Cookies

One cookie: visitd_token, set only when you log in, used only to keep you logged in. It is strictly necessary for the account feature, which is why no cookie banner is required for it. We set no analytics, advertising or cross-site tracking cookies. If we enable analytics, we use a cookieless, privacy-friendly tool (Plausible) that stores nothing on your device and collects no personal data.

Who we share data with

Only the processors that make the product work: our hosting provider, Dodo Payments (checkout), our email delivery provider (your report), and the AI engine APIs we query — engine queries contain buyer questions about a website's category, not your personal data. We never sell personal data.

Retention

Account and waitlist data: kept until you ask us to delete it. Scan results: kept indefinitely — they power the public index and the longitudinal dataset. The auth cookie expires on its own (default 7 days).

Your rights (GDPR and equivalents)

You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it (along with your account and waitlist entry). Email support@getvisitd.com from the address in question and we'll act on it within 30 days. If you believe we've mishandled your data, you can also complain to your local data protection authority.

Site owners: to remove your domain from the public index, use the same address.

Changes

Material changes to this policy will be posted here with a new date.

Questions about any of this? Email support@getvisitd.com — a human reads it. See also Terms, Privacy and Refunds.