Privacy Policy
Last updated: 16 July 2026
1. Who is responsible for your data
The data controller is Alexander Kalinko, a sole trader based at Gaujas street 5C, Mārupe, LV-2167, Latvia, operating as ClearSignal. For any privacy question or request, contact hello@getclearsignal.io.
2. What we collect
- Order and audit data: your email address, the website address you submit, competitor website addresses, and the audience/ICP description you provide.
- Payment data: handled by Stripe. We receive confirmation of payment and limited transaction details. We never receive or store your card number.
- Report data: the generated report, the AI answers collected during the scan, and the publicly available website content analysed.
- Technical data: standard server and security logs, and data used for rate limiting.
We do not ask you for special categories of personal data. Please do not submit them.
3. Why we use it, and on what legal basis
- To perform our contract with you (Art. 6(1)(b) GDPR): running the audit, producing and delivering the report, and providing support.
- Our legitimate interests (Art. 6(1)(f) GDPR): keeping the service secure, preventing abuse, and improving the quality of our reports.
- Legal obligation (Art. 6(1)(c) GDPR): keeping records required for accounting and tax.
We do not sell your data, and we do not use it for advertising.
4. Automated processing and AI
Producing your report involves automated analysis and AI models. Specifically, the website address and business name you submit, and content publicly available on that website, are sent to the AI providers listed below so we can test how those engines describe your business and generate the report text.
Every report is reviewed by a person before it is delivered. The processing does not produce legal or similarly significant effects on any individual within the meaning of Art. 22 GDPR.
5. Who we share it with (sub-processors)
We use the following providers to deliver the service:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Website and application hosting | USA / EU |
| Supabase | Database storing your order, audit inputs and report | Stockholm, Sweden (EU) |
| Stripe | Payment processing | USA / EU |
| Resend | Sending the report delivery email | USA / EU |
| Trigger.dev | Running the audit as a background job | USA / EU |
| Firecrawl | Fetching your publicly available website content | USA |
| Anthropic (Claude) | Analysing content and generating report text | USA |
| OpenAI | Testing how the engine answers questions about your category | USA |
| Perplexity | Testing how the engine answers questions about your category | USA |
| Testing how the engine answers questions about your category | USA | |
| Upstash | Rate limiting to prevent abuse | USA / EU |
6. International transfers
Several of the providers above are located in the United States. Where personal data is transferred outside the EEA, the transfer is based on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism offered by that provider.
7. How long we keep it
- Audit reports and order data: kept for 12 months so you can access your report, then deleted or anonymised.
- Accounting records: kept for the period required by law in Latvia.
- Free score submissions: kept for 12 months.
You can ask us to delete your data earlier — see below.
8. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, and receive it in a portable format. To exercise any of these, email hello@getclearsignal.io. We will respond within one month.
You also have the right to lodge a complaint with your local data protection supervisory authority.
9. Cookies
We use only what is necessary to run the site: a session cookie for our own administration area, and technical data required for security and rate limiting. We do not use analytics, tracking or advertising cookies, and we do not embed third-party tracking scripts. If this changes, we will update this policy and ask for your consent where required.
10. Security
Data is transmitted over encrypted connections and stored with the providers listed above. Access to reports is limited to you, via the link we send, and to our administration area.
11. Changes
We may update this policy. The current version is always published on this page with its date.