Legal
Privacy Policy
Last updated 3 August 2026.
This policy explains what personal data Visora handles when you use the marketing website, create an account, purchase an AI Visibility Audit or subscribe to monitoring.
1. Who we are
Jamie Champion trading as Visora provides AI Visibility measurement software. For the personal data described in this policy we act as the data controller, except where we process customer data on your instructions as part of delivering the service, where we act as a processor. Contact: privacy@visora.app, United Kingdom.
2. What information we collect
- Account data: name, email address, organisation name, role and authentication metadata.
- Business data you provide: business name, website, services, locations, sector and named competitors.
- Analysis data: the customer questions generated for your business, the AI responses recorded during testing, the observable signals audited, and the scores and recommendations produced.
- Free preliminary check data: the website domain submitted and the estimated score produced, stored so a repeat check can be served from our records rather than re-running the AI.
- Commercial data: plan, purchase history and subscription status. Card details are handled by Stripe and are never stored by Visora.
- Technical data: IP address, device and browser information, and application logs needed to operate, rate-limit and secure the service.
- Support data: messages you send us and the records needed to respond.
3. Why we collect it and our lawful basis under UK GDPR
We do not sell personal data, we do not carry out automated decision-making producing legal effects, and we do not permit your business data to be used to train third-party AI models where the provider offers that control.
- To provide the service you purchased, run audits and deliver reports — Article 6(1)(b), performance of a contract.
- To operate, secure, monitor, rate-limit and improve the platform and prevent abuse — Article 6(1)(f), legitimate interests.
- To send service, security and billing communications — Article 6(1)(b), performance of a contract.
- To send marketing communications — Article 6(1)(a), consent, withdrawable at any time.
- To meet accounting, tax and legal obligations — Article 6(1)(c), legal obligation.
4. How reports are generated
To produce an audit we generate representative customer questions for your sector and locations, submit those questions to third-party AI assistants, and record which businesses were named in each response. We also review publicly available signals about your business, such as your website, structured data, listings, citations and reviews.
The prompts sent to AI providers contain the business details you supply, which are typically business information rather than personal data. Do not enter personal data into business fields if you do not want it included in testing.
5. Third parties who process data for us
Each provider is engaged under a written agreement requiring them to process data only on our instructions and to apply appropriate security measures. Where data is transferred outside the UK or EEA, we rely on approved transfer mechanisms such as UK International Data Transfer Addendum, Standard Contractual Clauses or an adequacy decision.
We publish material changes to this list before they take effect. To be notified of subprocessor changes, email privacy@visora.app.
- Lovable Cloud (Supabase infrastructure) — Application hosting, authentication and the Postgres database holding your account, business and report data. (EU / UK region hosting).
- Lovable AI Gateway — Routes Visora's testing and drafting prompts to the underlying AI model providers listed below. (EU / US).
- OpenAI — Generates representative customer questions and produces the assistant responses recorded during visibility testing. (US, under Standard Contractual Clauses).
- Anthropic, Google and other assistant providers — Additional AI assistants queried during visibility testing where included in your plan. (US / EU, under Standard Contractual Clauses).
- Stripe — Payment processing, subscription billing and the self-serve billing portal. Card details are handled by Stripe and never stored by Visora. (US / EU, under Standard Contractual Clauses).
- Resend — Delivery of account, authentication, billing and report notification emails from notify.visora-intelligence.app. (EU / US).
6. Data retention periods
- Account data: retained while your account is active and for up to 12 months after closure.
- Analysis and report history: retained for the life of the account so trends stay comparable, and deleted on request.
- Free preliminary check records: retained for up to 12 months from the date of the check.
- Billing and tax records: retained for 6 years, as required by UK tax and accounting law.
- Application, security and rate-limit logs: retained for up to 12 months.
- Support correspondence: retained for up to 24 months after the enquiry closes.
7. Security measures
No system can be described as completely secure, and we make no absolute security claims. Report a suspected vulnerability to security@visora.app. Where a personal data breach is likely to result in a risk to your rights, we notify the ICO within 72 hours and notify you without undue delay where the risk is high.
- Authenticated accounts with breached-password protection, and access scoped by organisation membership and role.
- Row-level database policies so one organisation cannot read another organisation's data.
- Encryption in transit (TLS) and at rest by our infrastructure providers.
- Least-privilege internal access, with privileged operations restricted to server-side code.
- Rate limiting and abuse monitoring on AI analysis and free checks.
8. Your rights
To exercise any right, email privacy@visora.app. We respond within one month. You may also complain to your local supervisory authority, which in the UK is the Information Commissioner's Office (ico.org.uk).
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Erase your data where we no longer need it.
- Restrict or object to processing based on our legitimate interests.
- Receive a machine-readable export of your account and report data.
- Withdraw consent to marketing at any time, without affecting prior processing.
9. Deletion and export
You can request deletion of your account, business records and analysis history at any time. Deletion removes your data from live systems immediately and from encrypted backups within 30 days, except where we must retain records for legal reasons.
10. Cookies
Browser storage and cookies are described in our Cookie Policy, including which categories require consent and how to withdraw it.
11. Contact and changes
Questions about this policy: privacy@visora.app. General enquiries: hello@visora.app.
We update this policy when our practices change. Material changes are communicated by email or in-product notice, and the revision date above is always current.
Visora provides a proprietary AI Visibility benchmark based on observed testing and published methodology. It is not an official ranking or score issued by OpenAI, Google, Microsoft, Anthropic, Perplexity or any other AI provider.
Visora is an independent platform and is not affiliated with, endorsed by or sponsored by OpenAI, Google, Microsoft, Anthropic, Perplexity or any other AI platform unless explicitly stated.