Privacy Policy

The short version: we collect the minimum needed to run your scan and, if you ask, to email you the result. We do not sell your data or run ad trackers. Everything below is the detail.

Effective 6 June 2026

We never sell or share your data

No data brokers, no ad networks.

No advertising trackers

Only cookieless, privacy-first analytics.

Card details never touch our servers

Payments run entirely through Stripe.

Delete your data anytime

One email to misha@noetio.com.

Who we are

Noetio helps businesses measure and improve how AI search engines cite them. This policy explains the personal data we handle through this website and its scan, report, and scheduling features, and the choices you have over it.

What we collect

Free visibility check: the domain you submit, the AI-engine responses about that domain, and standard technical logs (IP address, user agent) from our hosting provider.

Email (optional): if you ask us to send the scan snapshot, we store your email address solely to send that snapshot and related follow-up about it.

Paid orders: handled by Stripe. We receive your email and order details and never see or store full card data.

In the language of US privacy law, the categories we collect are identifiers (email, IP address), the domain you submit, internet and network activity (technical logs), and commercial information (orders). We collect no sensitive categories.

How we use it

To run the scan you requested and show you the result.

To deliver reports you purchased and provide support.

To send the snapshot you asked for by entering your email. Any further marketing happens only if you opt in.

To operate and secure the service, including hosting logs and abuse prevention.

Cookies and analytics

We do not use advertising or cross-site tracking cookies, and we do not build advertising profiles about you.

For usage measurement we use Vercel Web Analytics and Vercel Speed Insights, which are privacy-first and cookieless. Stripe and Cal.com may set functional cookies only when you actively use their payment or scheduling features.

Who we share it with

We share data only with the processors that run the service: Vercel (hosting and analytics), Stripe (payments), OpenAI, Google, and Perplexity (the domain you submit is included in AI-engine prompts), Supabase (EU-hosted application database), Cal.com (call scheduling if you book), and our email provider for transactional messages.

We do not sell, rent, or trade your personal information, and we do not use it for cross-context behavioral advertising.

How long we keep it

Scan results are cached for up to 7 days for performance. Order and invoice records are kept as long as US commercial and tax law requires. Snapshot emails are kept until you ask us to delete them.

How we protect it

Data is encrypted in transit with HTTPS/TLS on every page. Payments are processed by Stripe, which is certified to PCI-DSS Level 1, the highest card-security standard. The site and its data run on Vercel infrastructure, with access limited to the people who operate the service.

Our strongest safeguard is holding as little personal data as the service needs, so there is little to expose in the first place.

Your choices and rights

You can request access to, a copy of, correction of, or deletion of your personal data, and opt out of any marketing, at any time by emailing misha@noetio.com. We verify your identity and then respond within 30 days (GDPR) or 45 days (US state laws), which we may extend once by a further 45 days where the law permits and only with notice to you.

US residents, including under California's CCPA and CPRA and the laws of Virginia, Colorado, Connecticut, and Texas: we do not sell or share your personal information, we honor your rights to know, access, correct, delete, and opt out, and we do not discriminate against you for exercising any of them.

If we decline a request, you may appeal by replying to our decision, and we will review it and respond within the period your state's law allows.

EU and EEA visitors (GDPR)

If you are in the EU or EEA, our legal bases are: performing the scan and orders you request and pre-contractual steps (Art. 6(1)(b)); your consent for any further marketing (Art. 6(1)(a)); and our legitimate interest in operating and securing the service (Art. 6(1)(f)).

Because our processors are in the United States, transfers rely on those processors' certification under the EU-US Data Privacy Framework or on Standard Contractual Clauses. You may lodge a complaint with your local supervisory authority at any time.

Children

Noetio is built for businesses and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, email misha@noetio.com and we will delete it.

Changes to this policy

When we change this policy we post the updated version here with a new effective date and revise the summary at the top. For material changes we give notice by a reasonable means before they take effect.

Contact

Privacy questions or requests: misha@noetio.com. We acknowledge requests promptly and respond within the timeframes above.

Noetio is a service operated by Auraqu, Inc., a Delaware C-corporation and the data controller for the personal data described in this policy. Registered address: 131 Continental Dr, Suite 305, Newark, DE 19713, USA.

See if AI search engines cite your brand

Noetio measures and fixes your visibility in ChatGPT, Perplexity, and Google AI answers.

Run the free scan →