Privacy Policy
Last updated: 2026-08-09
Who we are
Answerly Tracker ("we", "the service") measures whether a brand is mentioned or cited in AI answers (ChatGPT, Gemini, Google AI Overview) and, optionally, correlates that with the brand's own Search Console and Analytics data. The service is operated by Answerly / chyzh.agency. Contact: [email protected].
What we collect
- Account: your email address (used for magic-link sign-in) and your organization/project settings.
- AI-visibility measurements: the prompts you track and the responses AI engines return for them.
- Google data (only if you connect it): read-only Search Console query aggregates and read-only GA4 traffic aggregates for the property you select.
Google user data — how we use it
If you connect Google, we request the read-only scopes webmasters.readonly (Search Console) and analytics.readonly (GA4). We use this data solely to show you your own site's search queries and traffic inside the app and to correlate them with AI visibility. We never modify anything in your Google account. Answerly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not transfer it to others except as needed to provide the feature at your request.
How we store & protect it
Data is stored in our Postgres database (Supabase, EU region). Your Google OAuth refresh token is encrypted at rest with AES-GCM; the encryption key is held only in server environment secrets, never in the database, and no client-facing route ever returns the token. Access tokens are short-lived and requested on demand.
Third parties
To measure AI visibility we send your tracked prompts (not your Google data) to AI providers (OpenAI, Google Gemini, Perplexity) and a SERP provider. Your connected Google data is not sent to these providers. Infrastructure: Cloudflare (hosting), Supabase (database), Resend (sign-in email).
Your controls & retention
You can disconnect Google at any time from the project page — this revokes our stored token and stops all Google data pulls. You may also revoke access at myaccount.google.com/permissions. You can request deletion of your account and data by emailing [email protected]; we delete it within 30 days. Imported Google aggregates are kept only while the connection is active.