Legal

Privacy Policy

Last updated: May 14, 2026

Detectabli is an AI search visibility platform that helps businesses understand, measure, and improve how their brand appears across answer engines and AI-powered search tools. This policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have over it. We apply GDPR-equivalent protections to all users as the higher standard, regardless of where they are located.

01

Who We Are

Detectabli is a trade name of Unlocked AEO Inc. ("Detectabli", "we", "our", or "us"), a company incorporated in Ontario, Canada.

Registered address: Toronto, Ontario, Canada

Privacy contact: contact@detectabli.com

General contact: contact@detectabli.com

To exercise your rights or ask a question about this policy, email contact@detectabli.com with the subject line DATA PROTECTION REQUEST. We will respond within 30 days.

02

Scope of This Policy

This policy explains how we process personal data when you: visit our website at detectabli.com; sign up for, onboard onto, or use the Detectabli platform; communicate with us, schedule a meeting, or contact support; pay for a subscription; apply for a role with us; or connect a third-party tool (e.g. Google Search Console, an MCP client) to your workspace.

This policy does not apply where we process personal data as a processor on behalf of a customer — for example, data that one of our customers inputs into the platform about their own end users. In those cases the customer is the controller, and processing is governed by our Data Processing Addendum and Master Subscription Agreement.

Our regulatory framework: Detectabli is governed by Canadian privacy law — the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. Because we serve customers globally, we apply GDPR-equivalent protections to all users as the higher standard, including the legal basis, transfer, and rights provisions described below.

03

What Data We Collect and Why

A. Data you provide to us

Account and contact data: When you create a Detectabli account or request a demo, we collect your name, work email, company name, job title, and (optionally) phone number. We use this to provision your workspace, authenticate you, and manage your account. Legal basis: performance of a contract — Art. 6(1)(b) GDPR.

Billing data: If you purchase a paid plan, we collect billing name, billing address, VAT/tax ID (where applicable), and an email for receipts. We do not store payment card data ourselves — card details are collected and stored directly by our payment processors, Stripe and Whop. We receive only a payment token, the card brand, the last four digits, and the expiry month/year for reconciliation and display. Legal basis: performance of a contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c).

Communications: If you email us, chat with our support team, fill out a form, or respond to a survey, we receive the contents of those communications along with whatever identifiers you choose to share. Legal basis: performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f).

Careers: If you apply for a role at Detectabli, we collect your CV, cover letter, contact details, professional history, and any interview notes or evaluations our team produces. We retain unsuccessful applications for 12 months so we can consider you for future roles, unless you ask us to delete them sooner or to keep them longer. Legal basis: pre-contractual steps — Art. 6(1)(b); legitimate interests — Art. 6(1)(f).

B. Data we collect when you use the platform

Platform usage data: We collect information about how you use Detectabli — features accessed, actions taken, queries run, dashboards viewed, session metadata, and error logs. This data is tied to your user ID or aggregated. We use it to operate the service, debug issues, monitor performance, and improve the product. Legal basis: performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f).

AI visibility tracking data: This is the core of what Detectabli does. We generate and execute synthetic prompts against AI platforms on your behalf (ChatGPT, Perplexity, Google AI Overviews, Claude, Gemini, and others), capture the responses, and return structured visibility, citation, and competitor data to your workspace. This data is about your brand's presence in AI search outputs — it does not contain personal data about you or your end users. Legal basis: performance of a contract — Art. 6(1)(b).

Connected third-party data: If you connect a third-party tool to your workspace (for example, Google Search Console, Google Analytics, or an SEO data source), we access data from that tool solely to deliver the feature you requested. We do not store this data beyond what is necessary to complete the task — it is processed in-flight and then discarded or cached for a short window for performance. Legal basis: performance of a contract — Art. 6(1)(b).

Competitive intelligence data: To power competitive benchmarking, citation tracking, and AI-visibility scoring, we process publicly available web content and the public outputs of AI platforms. This content may incidentally include names or other identifiers of individuals who appear in public-facing content — for example, named authors, executives, or company representatives. We do not seek to collect personal data about these individuals. We apply minimisation controls to limit it, and only retain identifiers for 90 days maximum. You have the right to object to this processing at any time by contacting contact@detectabli.com. Legal basis: legitimate interests — Art. 6(1)(f) GDPR.

C. Data collected automatically

Device and location data: When you visit our website or use the platform, we receive your IP address, device type, browser type and version, operating system, and approximate (city/country-level) location inferred from your IP. We use this for security, debugging, and aggregate server-side analytics. Legal basis: legitimate interests — Art. 6(1)(f).

D. Marketing communications

If you subscribe to our newsletter, request a demo, or are an existing customer, we may send you product updates, educational content, case studies, and occasional promotional emails. We track open and click engagement to measure what's useful. You can unsubscribe from any marketing email via the link at the bottom. You will still receive transactional emails (billing, security alerts, important product changes) as long as you have an active account. Legal basis: consent — Art. 6(1)(a) for newsletter subscribers; legitimate interests — Art. 6(1)(f) for soft opt-in to existing customers, subject to local rules.

04

How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, meet legal obligations, resolve disputes, and enforce agreements. The specific periods are:

Account and contact data: duration of contract, plus 90 days.

Billing and financial records: 6 years (Canada Revenue Agency requirement).

Platform usage data: pseudonymised within 30 days; aggregates retained up to 24 months.

Raw AI platform queries and responses (with any identifiers): up to 90 days, then anonymised or deleted.

Aggregated AI visibility metrics, scores, and citation history: duration of contract, so customers can see historical trends.

Connected third-party data: not retained — discarded after use.

Competitive intelligence content (personal identifiers only): 90 days maximum.

Support and communications records: 24 months after the last interaction.

Marketing records: duration of consent or relationship, plus 24 months.

Unsuccessful job applications: 12 months.

Backups: up to 35 days before being overwritten.

Where we are legally required to keep records longer — for example, financial records for tax purposes — we will do so.

05

Who We Share Your Data With

We share data only with vetted service providers ("sub-processors") that help us deliver the platform. Each is bound by a Data Processing Agreement requiring them to keep your data confidential, secure, and used only for the purposes we instruct.

The categories of service providers we rely on include: cloud hosting and database infrastructure; payment processing (currently Stripe and Whop); authentication for secure login; email delivery for transactional and marketing communications; customer relationship management (CRM); product analytics and error monitoring; customer support tools; meeting scheduling for demos and customer calls; AI model providers (LLM APIs) used to generate the synthetic queries that power Detectabli's core visibility tracking; and data enrichment for limited business contact information.

A current, complete list of named sub-processors is available on request by emailing contact@detectabli.com. We will provide reasonable advance notice of any new or replacement sub-processor that materially changes how your data is processed.

We do not sell your personal data. We do not share your data with third parties for their own marketing purposes.

We may also disclose data to professional advisors bound by confidentiality; in connection with a merger, acquisition, or sale of assets; where required by law (and where lawful, we will notify you first); or to protect rights, property, or safety of Detectabli, our users, or others.

06

International Transfers

Detectabli operates globally, and some of our sub-processors are based outside your country. Where we transfer personal data internationally — including transfers from the UK, EEA, or other regulated jurisdictions to the United States or elsewhere — we rely on one or more of the following safeguards: Standard Contractual Clauses (SCCs) approved by the European Commission, with the UK International Data Transfer Addendum where applicable; adequacy decisions where one is in force for the destination country; or EU–US Data Privacy Framework certification, where the recipient is certified.

Details of the transfer mechanism in place for each sub-processor are available on request from contact@detectabli.com.

07

How We Protect Your Data

We take security seriously. Our measures include: encryption of data in transit (TLS) and at rest; role-based access controls with least-privilege defaults; multi-factor authentication for all internal systems; regular security reviews and dependency scanning; audit logging of access to production systems; and vendor due diligence before onboarding any new sub-processor.

If we become aware of a personal-data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay, in line with our legal obligations.

No system is perfectly secure, and we cannot guarantee absolute security of any data transmitted to or stored on our platform.

08

Cookies and Similar Technologies

Detectabli does not currently use cookies or similar tracking technologies on our website or within the platform.

If we introduce cookies in the future — for example, to support a third-party analytics tool, marketing measurement, or persistent login preferences — we will update this policy in advance, publish a Cookie Policy listing every cookie and its purpose, and (where required by law) ask for your consent through a cookie banner before any non-essential cookie is set.

We do not respond to "Do Not Track" browser signals, as there is no agreed industry standard for how to do so.

09

MCP (Model Context Protocol) Integration

Detectabli publishes a Model Context Protocol (MCP) server that lets third-party AI assistants (Claude.ai, Claude Desktop, Cursor, ChatGPT, and other MCP-compatible clients) read data from your Detectabli workspace on your behalf.

Read-only access: The MCP server exposes read-only tools. It cannot create, modify, or delete data in your workspace.

Scope of data: Connected clients can query the projects you own — project metadata, AI visibility metrics, prompt performance, citation and source data, competitor benchmarks, and audit findings. They cannot access other workspaces or other users' data.

Authentication via OAuth 2.1: You authorise access on an explicit consent page that lists every permission being granted. Your Detectabli API key is stored encrypted on our MCP server and is never exposed to the client — the client only ever receives an OAuth access token.

Third-party client responsibility: Once data is returned to the connected client, its handling is governed by that client's privacy policy (for example, Anthropic for Claude, OpenAI for ChatGPT). Review the client's policy before connecting.

Revocation: You can revoke MCP access at any time from Settings → Integrations by removing the connection or rotating the API key.

Logs: We log MCP request metadata (timestamp, endpoint, HTTP status, latency) for security and debugging. We do not log the contents of tool responses.

10

Your Rights

Depending on where you live, you may have the following rights in relation to your personal data: access the personal data we hold about you; correct inaccurate or incomplete data; delete your data (the "right to be forgotten"); restrict how we process your data in certain circumstances; receive your data in a structured, machine-readable format (portability); object to processing based on legitimate interests, including our competitive intelligence processing; and withdraw consent at any time where processing is based on consent.

To exercise any of these rights, email contact@detectabli.com with the subject line DATA PROTECTION REQUEST. We will respond within 30 days at no charge. Deletion requests are cascaded to our sub-processors.

If you are not satisfied with our response, you have the right to complain to your local supervisory authority: in Canada (federal), the Office of the Privacy Commissioner of Canada (priv.gc.ca · 1-800-282-1376); in Ontario, the Information and Privacy Commissioner of Ontario (ipc.on.ca); in the UK, the Information Commissioner's Office (ico.org.uk); or your local EU Data Protection Authority. We would welcome the opportunity to resolve any concern directly — please contact us first.

11

Automated Decision-Making

We do not use your personal data for solely automated decision-making, including profiling, that produces legal or similarly significant effects on you (as defined in Article 22 GDPR).

The AI-driven scoring and recommendations that Detectabli produces are designed to inform your team's decisions, not to make consequential decisions about individual people on your behalf.

12

Children's Privacy

Detectabli is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under the age of 18. If we learn we have collected personal data from a child, we will delete it.

If you believe a child has provided us with personal data, contact contact@detectabli.com.

13

Changes to This Policy

We will notify you of material changes by email or in-app notice before they take effect. The Last updated date at the top of this page always reflects the current version. Previous versions are available on request from contact@detectabli.com.

14

Contact

For any questions, concerns, or requests regarding this policy or our data practices, please contact us:

Unlocked AEO Inc. (trading as Detectabli)Toronto, Ontario, Canada