PaperHorse

Privacy Policy

Effective date: May 28, 2026

This Privacy Policy explains what data Am I Findable ("we", "our") collects, how we use it, who we share it with, and the choices you have. We've tried to keep this in plain language. If anything is unclear, email us at the address at the bottom of the page.

What we collect

Account information. When you create an account we store your email address and an opaque user identifier via AWS Cognito. Cognito handles password storage and authentication; we never see your password.

Subscription information. If you subscribe to a paid plan, we store a Stripe customer reference, your current subscription tier (Standard, Pro, Enterprise), and your subscription state (active, canceled, past due). We do not store your card number, CVV, or expiry date. Stripe holds your payment method directly.

Analysis input. When you run an analysis, we store the URL you submit, any brand name or competitor overrides you provide, and the AI-discovery prompts generated for your report.

Analysis output. We store the AI engine responses, citations, mention metrics, recommendations, and supporting analytical outputs produced by your report.

Re-audit email (optional). If you opt in to re-audit reminders, we store the email address you provide for the sole purpose of sending you a transactional reminder when your report is ready for a refresh. We do not use this address for marketing.

Usage data. We store basic activity records: when you ran reports, how many you've run in the current billing period, and which features you used. We use this to enforce subscription quotas and to debug issues.

Cookies and local storage. We use cookies and browser local storage to keep you signed in (Cognito session tokens) and to remember display preferences within the app. We do not use third-party advertising cookies.

How we use it

We use your data to generate and display your reports, send you transactional emails (re-audit reminders, billing receipts), enforce subscription quotas, debug issues, and improve the service through aggregate analytics.

We do not sell your data to third parties.

We do not use your data to train AI models. Each AI provider we integrate with has its own data-use policy; we send only the data necessary for each call and do not opt your data into training datasets.

Third-party services

We use these third-party services to run Am I Findable:

  • AWS. Cognito for authentication, ECS Fargate for compute, EFS for storage. AWS receives all data necessary to run the service.
  • Stripe. Subscription billing. Stripe receives your name, billing email, and payment method directly. We receive a customer reference and subscription state.
  • OpenAI. Used for business inference, prompt generation, mention classification, recommendations, and for automated web search (via OpenAI's Responses API with the web_search tool) to find specific URLs referenced in your recommendations.
  • Anthropic. Used for one of the four AI engines we sample for your report (Claude).
  • Google. Used for one of the four AI engines we sample (Gemini).
  • Perplexity. Used for one of the four AI engines we sample.

Each AI provider receives only the data necessary for that call: the prompt being tested, your brand name, the recommendation context. None receive your account credentials, subscription details, or other customers' data.

Automated web search

When generating recommendations, our system uses OpenAI's web_search tool to find specific URLs (such as Reddit threads, forum posts, or articles) relevant to each recommendation. The web_search tool is operated by OpenAI; we receive only the URLs and surrounding context it returns. We do not separately crawl third-party sites on your behalf.

Shareable report links

Each completed report has a public URL of the form /report/<uuid>. Anyone with this URL can view the report contents, including the analyzed URL, AI responses, mention metrics, and recommendations. Your account email, subscription details, and any re-audit email you provided are not exposed on this public URL. The UUID is unguessable and reports are not enumerable, but you should still be deliberate about who you share these links with.

Data retention

Reports are stored until you delete them. You can delete reports from your dashboard at any time. Deleted reports are soft-deleted for 30 days, after which they are permanently purged from our database.

Account data is retained while your account is active. If you delete your account by emailing us, we will purge your account data and any associated reports within 30 days, except where retention is required by law (e.g., billing records for tax compliance).

Your rights

You can access your data at any time through the dashboard. You can delete individual reports from the dashboard. You can request deletion of your entire account by emailing us at the address below.

If you are a resident of the European Union, United Kingdom, or California, you have additional rights under GDPR, UK GDPR, or CCPA, including the right to access, correct, port, or delete your personal data, and the right to object to certain processing. To exercise these rights, email us at the address below.

Security

We use HTTPS for all data in transit and encrypted storage for data at rest (AWS EFS encryption). Authentication runs through AWS Cognito; we do not handle passwords directly. We do not store payment card data — Stripe holds that. URLs you submit are validated to prevent server-side request forgery, and analysis traffic is rate-limited per IP and per account.

Children's privacy

Am I Findable is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect data from children. If you believe we have collected such data, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. If we make a material change, we will email you and post a notice in the app at least 14 days before the change takes effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

Contact

Questions or requests? Email support@amifindable.com.