Legal
Privacy Policy
Effective 2026-09-02. This describes what ProvenVisible actually stores, not what a product of this type could theoretically store. Every category below maps to a real table in our database.
Este texto se publica solo en inglés. No se ha traducido porque un texto legal que no ha sido revisado por un abogado en ese idioma no debería presentarse como vinculante. Aviso KVKK turco.
Data controller: Aygün Gönlüşen, trading as DSA Bilişim (sole proprietor, Turkish tax ID VKN 4080408038, Sarıgazi V.D. tax office), Cumhuriyet Mah. Yonca Sk. No: 11-13 Inner Door No: 2, Cekmekoy/Istanbul, Turkiye. Contact: [email protected].
What we collect and why
| Category | What it is | Why | How long |
|---|---|---|---|
| Account | Email address (either typed by you or verified by Google when you sign in with Google). | Identifies your account and is the address we use to reach you about your sites. | Until you delete your account. |
| Site profile | Domain, brand name, aliases, competitors, market, language, business type, detected platform. | Every audit, prompt and report is scoped to a site; the profile is what makes the output specific to you. | Until you delete the site. |
| Crawled pages of your own site | URLs, HTTP status and headers, page HTML, extracted text, publication dates. | The audit runs on the real page, not on a summary. Findings quote the page, so the page has to be stored. | Recent crawls are kept so audits can be compared over time; older crawls are removed. |
| Audit output | Findings, scores, generated fixes, applied-change records, and mobile screenshots when a page covers the screen with a layer. | The report and the evidence loop are built from these records. | Kept while the site exists — audit history is the basis for measuring whether a fix worked. |
| Answer-engine tracking | Prompts you track, the raw answers returned by answer engines, and the mentions and citations parsed from them. | Visibility is measured from the real answer text; storing it is what allows a metric to be re-derived instead of trusted blindly. | Kept while the site exists. |
| Google Search Console and Analytics data | Property selection, daily clicks, impressions, average position per page and per query, and (if you connect it) GA4 session counts. | Proves that a fix moved classic search, not only AI answers. | Kept while the connection exists; removed when you disconnect the site. |
| Connection credentials | Google refresh token, connector site tokens, and provider keys. | Read Search Console on a schedule and publish approved fixes through your connector. | Encrypted at rest (AES-256-GCM) and deleted when you disconnect. |
Analytics runs only if you accept it. We use Google Analytics 4 to see which pages get read; the script is not loaded and no analytics cookie exists until you press accept on the banner, and withdrawing consent deletes those cookies. There is still no advertising pixel and no tag manager. See the cookie policy.
Content from your own website
An audit downloads pages of the site you registered and stores their HTML and text so findings can quote the real page. If your pages contain personal data — author names, contact details, customer reviews — that data is stored with them. You control this: it is the site you asked us to analyse, and deleting the site deletes the crawls. We do not crawl sites you have not registered, except for the light, unauthenticated fetch used by the public free tools.
Google user data
If you connect Google, we request read-only scopes: Search Console (webmasters.readonly), Analytics (analytics.readonly) and your email address. No write scope is requested, so nothing in your Google account can be changed through ProvenVisible.
We store the refresh token encrypted (AES-256-GCM), the email address of the connected account, the property you selected, and the metrics Google returns for that property. Disconnecting deletes the token and the property selections; the permission itself remains in your Google account until you remove it there.
ProvenVisible’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google data is used only to provide the features you connected it for, it is never sold, never used for advertising, and never used to train machine-learning models. Human access is limited to what you explicitly request in support, to a security investigation, or where the law requires it.
Where your data is stored
Our servers and database are located in Turkey. Some processing happens at the sub-processors listed below, which operate outside Turkey — mainly in the United States. If you are in the European Economic Area or the United Kingdom, that means your data may be transferred outside your jurisdiction; those transfers rely on the transfer mechanisms agreed with each provider.
Sub-processors we actually use:
| Provider | Purpose | What is sent | Location |
|---|---|---|---|
| Anthropic (Claude) | Brand identification during onboarding, content-quality analysis, and the narrative section of the report. | Text extracted from your own site's pages and the site profile. | United States |
| OpenAI only if you enable it | Runs your tracking prompts against ChatGPT to record whether your site is mentioned. | The prompt text you configured. Your site content is not sent. | United States |
| Perplexity only if you enable it | Runs your tracking prompts against Perplexity. | The prompt text you configured. | United States |
| DataForSEO only if you enable it | Reads Google AI Overviews results for your tracking prompts. | The prompt text you configured. | United States / European Union |
| Resend | Sends the emails the product has to send: address verification, password reset, and change notices. | Your email address and the contents of that message. No site content and no audit data. | United States / Asia-Pacific |
| Paddle only if you enable it | Merchant of record for paid plans: runs the checkout, charges the card, collects sales tax and VAT, issues the invoice, and handles refunds and chargebacks. | Your email address, billing country and the payment details you enter at checkout. Paddle collects payment details directly; they never reach our servers. Your site content and audit data are not sent. | United Kingdom / European Union / United States |
| Google (Search Console, Analytics, OAuth) only if you enable it | Verifies that you own the domain and reads search performance you already own. | OAuth tokens and the metrics Google returns for your property. | United States / global |
If the business changes hands
If the service is reorganised, merged or sold, your data moves to the successor under these same commitments — it is not sold separately as a data set. Account holders are told before that happens, so anyone who would rather not continue can delete their account first.
Google Analytics 4 is a further processor, but only for visitors who accept analytics: it receives page addresses, approximate location derived from IP, and device or browser type. It never receives your account data, your site content or anything you connected.
What we never do
- We do not sell your data, and we do not share it for advertising.
- We do not use your data — or Google’s — to train machine-learning models.
- We do not write anything to your website unless you approve that specific change first.
- We do not request write access to any account you connect.
Your rights
You can ask for a copy of your data, correction of anything wrong, deletion, restriction of processing, or to object to processing. Deleting a site removes its crawls, audits, findings, prompts, answers and search metrics. Deleting your account removes everything associated with it.
If you are in Türkiye, these rights come from Article 11 of the KVKK; the Turkish-language notice is here. If you are in the EEA or UK, they come from Articles 15–22 of the GDPR. Requests go to [email protected].
Security
Tokens and provider keys are encrypted at rest with AES-256-GCM. Connector requests are signed and single-use, and every payload is checked against an allow-list in three separate places before anything is published to your site. Sessions are cookie-based and signed; the cookie is HTTP-only.
Changes
If this policy changes in a way that affects what we collect or who processes it, we will update the effective date at the top and tell account holders by email before the change takes effect.