Privacy Policy
Last updated
This policy explains what personal data Laudia collects when you use laudia.ai, why we collect it, and the rights you have. We keep this short and specific: we collect very little.
What we collect, and why
When you use the free audit, here is what we collect directly:
- Your email address and the website you submit, when you unlock the full AI-engine report. We use them to run the report, email it to you, and, as the form says, follow up once about your results and Laudia. Legal basis: to provide the report you asked for, and the notice you see when you submit the form. Every email carries an unsubscribe link, and we record which notice wording you saw and when.
- Your details when you register interest in a paid plan: your email, your company or website, and, if you add them, your name, a comment, and the early-test-customer preference. We use them to contact you about that request. Legal basis: your consent when you submit the form. Please do not put sensitive personal information in the comment field; we do not ask for any.
- Your IP address, used only in the moment to rate-limit abuse and to run the Cloudflare Turnstile spam check. It is not written to our database. Legal basis: our legitimate interest in keeping the free audit available and free of abuse.
- Basic error logs, if something breaks, so we can fix it. We switch off automatic collection of IPs and request bodies, so they are not used to gather personal data. Legal basis: our legitimate interest in a reliable service.
Your account, when you subscribe
If you subscribe to a paid plan, we additionally hold your account email (sign-in works by emailed link, no password), your workspace and its settings, and the record of your subscription. Payment details, your card or your Shopify billing relationship, stay with Stripe or Shopify; we never see or store card numbers.
Your brand profile holds the facts you enter about your business so we can measure and draft accurately: your services, market, business address, opening hours, and, if you choose to add one, the name of the person your brand is built around. Enter only what you are comfortable with; the service works without a person's name. Legal basis: performing the subscription you asked for.
The website you audit
When you submit a domain, we fetch its public pages, the same pages anyone can view, to compute your Laudia Score. We then ask public AI assistants how they describe that brand.
For the free audit, only the public brand name and domain reach those AI assistants; your email never does. For subscribers, the brand-profile facts you enter can additionally be included in our requests to those providers, to draft content for your brand. The details, including the providers' commitment not to use your data for their own purposes, are in our Data Processing Agreement.
When you connect your online store
If you subscribe and connect your store or CMS (for example Shopify or WordPress), you authorise Laudia to publish the fixes you approve, and we publish nothing without your explicit approval of the exact change. On WordPress this runs through the Laudia Connect plugin you install; on Shopify through our app's own storage and a theme extension you activate, so we never touch your theme's files.
If you connect your Google Analytics property, we read only aggregated daily traffic figures (visit and key-event counts by source and day) to show you which visits came from AI assistants. We do not receive or store your visitors' personal data, and none of your customers' personal data reaches or stays with us.
Legal basis: performing the subscription service you asked for. You can disconnect at any time, which deletes the stored access. If you uninstall our Shopify app, or ask us to erase this data, we delete it, and we honour Shopify's data-erasure requests.
Cookies and local storage
We use functional storage that the site needs to work: your language, your currency choice, the country your connection comes from (derived from your IP address, and used to set the currency we show and the language we offer), and display preferences. These are necessary and are not used for advertising.
We count page visits and free-audit runs anonymously, without cookies or any identifier, which needs no consent. An audit run is counted against the website address that was audited, never against you. For deeper analytics we use PostHog (on EU servers), and only after you accept: this uses cookies and may include your approximate location (country, derived from your IP), your device and browser, and a session replay of your visit with all form fields masked (we never capture what you type). Once you unlock a free audit report or sign in, we link this record to your email address, so what you do on the website and what you do in the product read as one visit rather than two. It is never used for advertising, we do not sell your data, and you can decline or withdraw at any time.
Who processes data for us
We rely on a small set of service providers to run laudia.ai. Each processes data only on our instructions.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and file storage (your report, lead record, account) | Switzerland (Zurich) |
| Stripe | Card payments and subscription billing | USA / global |
| Shopify | Store connection, and billing when you subscribe through the Shopify App Store | Canada / USA |
| Infomaniak | Email inbox and domain hosting | Switzerland |
| Vercel | Website hosting and the app runtime | EU (Frankfurt) |
| Upstash | Short-lived cache and rate-limiting | EU (Frankfurt) |
| Inngest | Runs the audit and monitoring pipelines in the background | USA |
| Resend | Sends your report and service emails | USA |
| Cloudflare | Spam and bot protection (Turnstile) | USA / global |
| Sentry | Error monitoring (automatic collection of personal data switched off) | USA |
| PostHog | Product analytics + session replay, only after you accept | EU (Frankfurt) |
| Reading the aggregated analytics you connect (Google Analytics) | USA / global | |
| Anthropic, OpenAI, Google, Perplexity | The AI assistants we query about public brands; content drafting for subscribers runs on Anthropic | USA |
Where your data is stored
Your report and your lead record are stored in Switzerland (Zurich), our email and domain run on Swiss infrastructure (Infomaniak), and the app itself runs in the EU (Frankfurt). Switzerland is recognized by the EU as providing an adequate level of data protection.
A few of the providers above are based in the United States or use global infrastructure. Where data reaches them, the transfer is covered by the EU Standard Contractual Clauses or an equivalent safeguard.
One small exception worth naming: the report we email you loads its fonts from Google Fonts when you open it, so opening the report requests those font files from Google. The site itself serves its fonts from our own hosting.
How long we keep it
Your report stays available for 30 days. After that the private link expires and the report can no longer be opened. The short-lived rate-limiting record tied to your IP expires within about an hour.
We keep your email and submitted details to operate and improve the free audit and to follow up as described above. You can ask us to delete them at any time, and we will. We also review inactive lead records ourselves and delete them after at most 24 months of inactivity.
For subscribers: the raw AI answers behind your weekly measurements are kept for 60 days; your scores and findings remain part of your workspace's history while you subscribe. When your subscription ends, we delete your workspace data on request, keeping only what bookkeeping law requires us to retain.
If you opt out of emails, we keep just your email address on our do-not-contact list, together with when and how you opted out, so the opt-out sticks.
Follow-up emails and opting out
When you unlock a report, we email it to you and may follow up once about your results. Beyond that, we email you only when you asked us to, for example after you register interest in a paid plan or in early access.
Our automated emails carry a one-click unsubscribe link, and for any email from us, a plain reply saying no works just as well. Either way we put your address on our do-not-contact list and stop.
If we wrote to you and you never used laudia.ai: we occasionally contact businesses individually, using publicly available business contact details and grounded in a real audit of that business's public website. Legal basis: our legitimate interest in offering a relevant service. Reply once and we stop, permanently, the same way.
If you book an intro call through the booking link we sometimes offer, the booking itself runs on Cal.com under Cal.com's own privacy terms.
Your rights
You can ask to access, correct, or delete your data, to restrict or object to its processing, or to receive it in a portable form. Where we rely on consent, you can withdraw it at any time. Just write to hi@laudia.ai.
You can also complain to a data-protection authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU or EEA, your local supervisory authority.
Security
Data is encrypted in transit. Access is restricted, the database enforces row-level security, and report files sit behind unguessable links that expire. We design the audit so it never needs your customer or patient data.
Changes
If we change this policy, we will update the date above and, for material changes, make it clear on the site.
Who is responsible
The controller for the data described here is BlockNovum GmbH (Swiss limited liability company), Josefstrasse 112, 8005 Zürich, Switzerland.
For any privacy question or request, contact hi@laudia.ai.