Last updated: 30 July 2026
Account data. Your name, email address and authentication credentials. If you sign in with Google we receive your email, name and profile image from Google, nothing else.
Free AI visibility check. The check is email gated. When you run one we store the domain you entered and the email you gave, create an account for you, send you a one click login link, and keep the resulting report so you can share it by link. That report page is public to anyone holding the link.
Usage data. The brands and domains you track, the prompts generated for them, the reports and analyses you run, and your plan and billing status.
AI crawler visits, if you install the collector. Covered separately in section 4 because it works differently from everything else here.
To produce a report we call third party services with the domain or keywords you asked about:
Measuring AI visibility means asking the assistants questions, so this is the part worth reading carefully.
To run a check we send your public homepage content, your brand and category, and the generated buyer questions to OpenAI, Anthropic, Google and Perplexity, depending on which engines your plan covers. We use their business APIs, not consumer accounts.
We do not send your account details, your billing data, your Search Console data or anything from another customer. We ask about public information about your brand, which is by definition what the engines already answer with.
If you install our collector, it runs on your own server and inspects each incoming request. It only sends us a request whose user agent matches a known AI crawler such as GPTBot or PerplexityBot. Your human visitors are matched, discarded locally, and never transmitted to us. There is no cookie, no visitor identifier and no page content involved.
For each crawler visit we receive the user agent, the path, a timestamp and the source IP. The IP is used only to check the request against the crawler operator's published address ranges, and is never stored. What we keep is a daily count per crawler per page.
We do not sell your personal data. We do not use your data to train models. We do not use Google Ads API data for anything other than providing keyword research to you.
Data is stored in a PostgreSQL database hosted on Neon in the EU. All connections are encrypted with SSL. Passwords are hashed with bcrypt at a cost factor of 12, and authentication and unsubscribe tokens are signed with HMAC-SHA256.
Under GDPR you can access, correct, export or delete your personal data. You can revoke any third party connection such as Google Search Console at any time, unsubscribe from non transactional email from any email we send, and delete your account and its data. Email info@ladderfox.com and we will action it.
Our use of Google APIs follows the Google Ads API Terms and the Google API Services User Data Policy.
If we change how we handle data we will update this page and its date. For anything privacy related, contact info@ladderfox.com.