This is the public AuthorityPrompt Privacy Policy document. It is served as static HTML and does not require JavaScript, login, cookies, VPN, or a regional access path.
Privacy Policy
Effective Date: March 28, 2026
Last Updated: March 28, 2026
This Privacy Policy describes how AuthorityPrompt, Inc. ("AuthorityPrompt," "we," "us," or "our") collects, uses, discloses, and protects the personal information of individuals ("you" or "User") who access or use our website at authorityprompt.com, platform, applications, APIs, and related services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Email address, full name, and company name when you register or log in via one-time passcode (OTP).
- Company Profile Data: Business name, website URL, domain, industry, region, description, FAQs, use cases, online presence links, contacts, and other information you enter into your AI Knowledge Profile.
- Verified Claims: Factual statements, supporting evidence, source URLs, and metadata you submit through the Verified Claims feature.
- Content and Articles: Text, HTML, URLs, and other materials you upload, import, or create through the Publishing and Trusted Sources features.
- Communications: Any information you provide when contacting us via email, support forms, or other channels.
- Payment Information: If you purchase a subscription, payment is processed by Stripe, Inc. We do not store your credit card number. We receive your Stripe customer ID, subscription status, and transaction metadata.
1.2 Information Collected Automatically
- Device and Browser Data: IP address, browser type, operating system, device identifiers, screen resolution, and language preferences.
- Usage Data: Pages visited, features used, click patterns, session duration, referring URLs, and interactions with the Service.
- Log Data: Server logs including timestamps, HTTP method, request path, response status, and latency.
- Analytics: We use Google Analytics 4 (GA4) to collect aggregated usage statistics. GA4 may set cookies on your device. You can opt out at https://tools.google.com/dlpage/gaoptout.
1.3 Information from Third-Party Integrations
If you connect third-party services, we may receive:
- Google Analytics 4: Measurement ID, property ID, OAuth access and refresh tokens, and analytics reports.
- Google Search Console: Site URL, OAuth tokens, search queries, impressions, clicks, and position data.
- Cloudflare: Zone ID, account ID, API token, traffic data, and bot analytics.
These tokens are stored securely and used solely to provide the features you requested.
1.4 Cookies and Similar Technologies
We use the following types of cookies:
- Essential Cookies: Required for authentication and core functionality (e.g., session tokens in localStorage).
- Analytics Cookies: Google Analytics cookies to understand Service usage (can be opted out).
We do not use advertising or tracking cookies. We do not participate in cross-site behavioral advertising.
2. How We Use Your Information
We use personal information for the following purposes:
- Provide the Service: Create and manage your account, generate AI-readable formats, process verified claims, and deliver all platform features.
- Authentication and Security: Send OTP codes, verify identity, detect fraud, and protect against unauthorized access.
- Improve the Service: Analyze usage patterns, diagnose technical issues, and develop new features.
- Communicate with You: Respond to support requests, send service-related notices, and provide product updates.
- Generate AI Formats: Use your Company Profile Data to generate JSON-LD, Markdown, YAML, HTML, TXT, and JavaScript files that are designed to be publicly accessible to AI systems and search engines.
- Comply with Law: Fulfill legal obligations, respond to lawful requests, and enforce our Terms of Service.
We process your information based on: (a) performance of a contract (providing the Service you requested), (b) your consent, (c) our legitimate business interests, and (d) compliance with legal obligations.
3. How We Share Your Information
We do not sell your personal information. We have not sold personal information in the preceding 12 months.
We may share information in the following circumstances:
3.1 Service Providers
We engage third-party vendors who process data on our behalf under contractual obligations of confidentiality:
- Hosting: Our Service is hosted on Replit (development) and dedicated servers (production).
- Payment Processing: Stripe, Inc. processes payments. See Stripe's Privacy Policy.
- Analytics: Google LLC provides analytics via Google Analytics 4. See Google's Privacy Policy.
- Email: SMTP providers deliver OTP codes and service communications.
- AI/LLM Providers: We send queries to OpenAI, Anthropic, Google (Gemini), Perplexity, xAI, and Groq to perform LLM visibility audits. These queries may include your company name and public business information but do not include your personal data.
3.2 Public AI Formats
Important: When you generate and publish AI-readable formats (JSON-LD, Markdown, YAML, HTML, TXT, JS), and when you deploy the AuthorityPrompt JS script on your website or use the Ingest Generator URLs, the Company Profile Data contained in those files becomes publicly accessible. This is the intended functionality of the Service — making your business information discoverable by AI systems, search engines, and RAG pipelines.
3.3 Legal Requirements
We may disclose personal information when required by law, subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
3.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such transfer.
3.5 With Your Consent
We may share information for other purposes with your explicit consent.
4. Your Privacy Rights
4.1 Rights for All Users
Regardless of your location, you may:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your account and associated data by contacting us.
- Withdraw consent for optional data processing.
- Export your data in a portable format.
4.2 California Residents — CCPA/CPRA Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights:
- Right to Know: You may request the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain legal exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share (as defined by CCPA/CPRA) your personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by CPRA.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
Categories of personal information collected in the past 12 months:
- Identifiers (name, email address, IP address)
- Commercial information (subscription status, payment metadata)
- Internet or electronic network activity (usage data, log data)
- Professional or employment-related information (company name, role)
To exercise your rights, contact us at [email protected]. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf.
4.3 Other U.S. State Privacy Rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out. Contact us to exercise these rights.
4.4 Nevada Residents
Under Nevada Revised Statutes Chapter 603A, Nevada residents may opt out of the sale of certain covered information. We do not sell your covered information. To submit an opt-out request, contact us at [email protected].
5. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained until you delete your account.
- Company Profile data: Retained until you delete the company or your account.
- Authentication logs: Retained for up to 12 months for security purposes.
- Analytics data: Aggregated and anonymized data may be retained indefinitely.
When data is no longer needed, we delete or anonymize it within 90 days, unless retention is required by law.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- HTTPS/TLS encryption for all data in transit
- Encrypted storage for OAuth tokens and API keys
- JWT-based authentication with time-limited tokens
- Database access controls and connection pooling
- Regular security assessments
Despite our efforts, no system is 100% secure. You acknowledge that you provide information at your own risk. If you become aware of a security vulnerability, please contact us immediately at [email protected].
7. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.
8. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected information from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at [email protected].
9. Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals. There is no industry standard for how to respond to DNT signals. We do not currently respond to DNT signals. However, we do not engage in cross-site tracking or behavioral advertising.
10. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date at the top.
- For material changes, we will notify you via email or an in-platform notice at least 30 days before the changes take effect.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us:
AuthorityPrompt, Inc.
Email: [email protected]
Website: https://authorityprompt.com
For California-specific inquiries, you may also contact us with the subject line "CCPA Request."