Legal

Privacy Policy

Last updated: May 13, 2026

This Privacy Policy explains how outAnswer ("outAnswer", "we", "us", or "our") collects, uses, and protects personal information when you use our Generative Engine Optimization platform and managed services (the "Service").

We act as a data controller for personal information about visitors, prospects, and account holders, and as a data processor for the information you submit to the Service about your business and audiences.

1. Information we collect

Information you provide

  • Account information — name, email, password, company name, role
  • Billing information — billing address, tax ID, and payment details (processed by our payment provider; we do not store full card numbers)
  • Workspace data — the brands, competitors, keywords, prompts, and content you configure inside the Service
  • Communications — messages you send to support, sales, or via our forms

Information we collect automatically

  • Usage data — pages visited, features used, actions taken, timestamps
  • Device and log data — IP address, browser type, operating system, referrer, error logs
  • Cookies and similar technologies — see the Cookies section below

Information from third parties

  • AI engines — queries we run against ChatGPT, Perplexity, Claude, Google AI Overviews, and similar services on your behalf, and the responses they return
  • Authentication providers — basic profile data when you sign in with Google, Microsoft, or similar (only what you authorize)
  • Public data — web pages, citations, and metadata we crawl to score AI visibility

2. How we use information

We use personal information to:

  • Provide, operate, and improve the Service
  • Authenticate accounts and prevent fraud or abuse
  • Process payments and manage subscriptions
  • Send transactional emails (receipts, security notices, product updates relevant to your account)
  • Send marketing emails (only if you opted in or as permitted by law — you can unsubscribe at any time)
  • Provide customer support
  • Analyze usage to fix bugs, prioritize features, and improve performance
  • Comply with legal obligations

We do not sell your personal information. We do not use Your Content to train public foundation models.

3. Legal bases (EEA / UK)

Where GDPR applies, we rely on the following legal bases:

  • Contract — to deliver the Service you subscribe to
  • Legitimate interests — to secure the Service, improve it, and run minimal direct marketing to existing customers
  • Consent — for optional cookies, marketing emails to prospects, and any sensitive processing
  • Legal obligation — for tax, accounting, and regulatory requirements

You can withdraw consent at any time without affecting the lawfulness of prior processing.

4. Sharing and disclosure

We share personal information only with:

  • Service providers ("sub-processors") that help us run the Service — hosting (Vercel, AWS), database (Supabase / managed Postgres), email (Resend or similar), analytics (PostHog), payments (Stripe or similar), and AI model providers (OpenAI, Anthropic, Google, Perplexity, etc.)
  • Professional advisors — auditors, lawyers, accountants — under confidentiality
  • Authorities — when required by law, valid legal process, or to protect rights and safety
  • Successors — in connection with a merger, acquisition, or sale of assets (we will notify you)

A current list of sub-processors is available on request.

5. International transfers

We are based in the European Union, but some sub-processors are located outside the EEA, including in the United States. When we transfer personal information internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or equivalent mechanisms.

6. Data retention

We keep personal information for as long as your account is active, plus a reasonable period after to comply with legal obligations, resolve disputes, and enforce our agreements.

After account closure, we delete or anonymize Your Content within 90 days, except where retention is required by law (for example, invoices for tax purposes).

7. Security

We implement technical and organizational measures designed to protect personal information, including encryption in transit, restricted access, logging, and regular reviews. No system is perfectly secure, but we work hard to keep yours safe.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your information
  • Restrict or object to certain processing
  • Port your data to another provider
  • Withdraw consent
  • Lodge a complaint with a data protection authority

To exercise these rights, email us at hello@outanswer.com. We respond within 30 days.

9. Cookies

We use a small number of cookies:

  • Essential — authentication, security, and load balancing (always on)
  • Analytics — anonymous usage data to improve the Service (consent-based in the EEA / UK)
  • Preferences — locale, theme, and other settings you choose

You can manage cookie preferences in your browser or through our cookie banner.

10. Children

The Service is not intended for users under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy. If changes are material, we will notify you by email or in the Service before they take effect. The "Last updated" date at the top reflects the latest revision.

12. Contact

For privacy questions or requests, contact:

outAnswer Email: hello@outanswer.com