1. Who we are
Visibility Zone LLC ("we," "us," "our," or "Company") is a software company that provides API-based content analysis and a visibility platform for monitoring how AI assistants and search engines represent your brand.
Our registered address is 1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States. We are governed by the laws of the State of New Mexico.
This Privacy Policy applies to:
- Our REST API service that analyzes images, audio, text, and performs multimodal search;
- Our visibility platform that monitors AI assistant responses, app-store reviews, SEO rankings, local business signals, brand mentions, and marketplace pricing;
- Our website (visibilityzone.com) and related online services.
2. Information we collect
Account and subscription information
When you sign up for our services, we collect:
- Your name, email address, and contact details;
- Company name and business information;
- Authentication credentials (passwords, API keys);
- Your subscription plan, purchase history, and billing information.
API request content
When you use our API, we receive and store:
- Images, audio files, and text you submit for analysis;
- Metadata about your requests (timestamps, file types, processing parameters);
- API response data and analysis results;
- Error logs and debugging information.
Platform monitoring data
Our visibility platform collects and ingests:
- Publicly available brand mentions, product names, and pricing information from AI assistants (such as ChatGPT, Google Gemini, Perplexity, and Google AI Overview);
- Public app-store reviews and ratings;
- Search engine rankings and SEO signals;
- Public Google Business Profile and local search data;
- Publicly available product pricing and visibility data from online marketplaces.
Technical and usage data
We automatically collect:
- Your IP address, browser type, operating system, and device information;
- Pages and features you access, time spent, and actions taken;
- API usage metrics, request frequency, and call patterns;
- Crash reports and performance data.
Website and cookie data
When you visit our website, we collect:
- Information stored in cookies and similar tracking technologies (see our Cookie Policy);
- Form submissions (such as contact requests);
- Email communications and support inquiries.
Third-party sources
We may receive information about you from:
- Payment processors and billing platforms;
- Analytics providers;
- Business partners and integrations you authorize.
3. How we use your information
The table below explains how we use your information, which data categories are involved, and our legal basis under the General Data Protection Regulation (GDPR) and similar laws:
| Purpose | Data categories | Legal basis (GDPR) |
|---|---|---|
| Providing and operating our services | Account info, API content, usage data, technical data | Contract |
| Processing payments and managing billing | Billing information, account data | Contract; legal obligation |
| Debugging, troubleshooting, and detecting abuse | API content, technical data, error logs | Contract; legitimate interests |
| Improving our products and platform accuracy | Aggregated or anonymized usage data; technical performance | Legitimate interests |
| Customer support and account management | Account info, communication records | Contract; legitimate interests |
| Marketing and product communications | Name, email, account information | Consent; legitimate interests |
| Compliance with legal obligations and law enforcement | Any data as required by law | Legal obligation |
| Fraud prevention and security | Technical data, usage patterns, IP address | Legitimate interests; legal obligation |
| Analytics and understanding user behavior | Usage data, technical data (aggregated or anonymized) | Legitimate interests; consent (for cookies) |
Legitimate interests
Where we rely on legitimate interests, we consider: the necessity of processing for our business, whether you have a reasonable expectation of the processing, and the impact on your privacy. You have the right to object to legitimate-interests processing (see Section 9).
4. Your information and your relationship to us
When we are a data processor
For our API service and visibility platform, your business is the customer who uses our services to analyze or monitor data. In this relationship:
- Your company is the data controller (responsible for determining why and how data is processed);
- We are the data processor (processing data on your behalf, under your instructions);
- Any content you submit to our API—images, audio, text, and related metadata—is processed under a Data Processing Agreement that governs our obligations.
For details on data processing terms, including data subject rights and subprocessors, please contact us or request our Data Processing Agreement.
When we are a data controller
For our website, marketing communications, billing information, and account management, we are the data controller. This Privacy Policy governs how we handle that information.
No use for general model training without consent
We do not use any API request content or customer data to train general-purpose AI models without your explicit written permission. Any such use would require a separate, signed agreement. This commitment applies regardless of whether the data is aggregated, anonymized, or pseudonymized.
5. Who we share your information with
Subprocessors and service providers
We work with third-party service providers (cloud hosting providers, email delivery providers, payment processors, analytics platforms, and monitoring tools) that may access your information to perform services on our behalf. These providers are contractually bound to protect your data and use it only as necessary to provide their services.
For a current list of subprocessors, visit Subprocessors.
Legal compulsion
We may disclose information if required by law, court order, government request, or similar legal process. Where permitted by law, we will notify you of such requests unless we are legally prohibited from doing so.
Business transfers
If we are involved in a merger, acquisition, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will provide notice of any such change and any choices you may have regarding your information.
Aggregated and anonymized data
We may share aggregated, anonymized data and insights with partners and the public for research, benchmarking, or marketing purposes. Such data cannot identify you personally.
6. International data transfers
Transfers to the United States
Visibility Zone is based in the United States. If you are located in the European Union, United Kingdom, or Switzerland, your information will be transferred to and processed in the United States, where data protection laws differ from those in your country of residence.
Legal mechanisms for transfers
To the extent required under GDPR, UK GDPR, or Swiss law, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to lawfully transfer personal data from the EU and UK to the United States. We also incorporate the UK Addendum to SCCs for transfers from the UK and comply with the Swiss-US adequacy requirements under the Federal Data Protection Act.
No adequacy decision
The United States has not received an adequacy decision from the European Commission or UK authorities. By using our services, you understand that your data will be processed in the United States and may be subject to US legal processes that differ from those in the EU or UK.
7. How long we retain your information
API request payloads
API request content (images, audio, text, and analysis results) is retained for a maximum of 30 days to enable debugging, error investigation, and abuse detection. After 30 days, this content is automatically deleted.
Account and subscription data
Account information (name, email, contact details, subscription plan, and authentication credentials) is retained for the lifetime of your account. If you close your account, we retain account data for 7 years to comply with tax, accounting, and legal obligations, then delete it.
Billing and transaction records
Billing information is retained for 7 years as required by tax and accounting regulations.
Platform monitoring data
Data collected by our visibility platform (AI assistant responses, rankings, reviews, pricing information) is retained while your subscription is active. Upon subscription termination, this data is retained for 90 days to allow account recovery, then deleted.
Technical and analytics data
Technical logs, error reports, and analytics data are retained for 90 days, then deleted or anonymized.
Legal holds
If we receive a legal hold, government request, or similar directive, we will retain the requested information for the period required by law.
8. Security
Encryption in transit
All data transmitted between your devices and our servers is encrypted using TLS 1.2 or higher.
Encryption at rest
Sensitive data stored on our servers, including API payloads and authentication credentials, is encrypted at rest using industry-standard encryption protocols.
Access control and least privilege
We use role-based access controls and the principle of least privilege. Only employees, contractors, and service providers who need access to your information to fulfill their job function are granted such access.
Logging and monitoring
We maintain comprehensive logs of access to systems and data, and monitor for suspicious activity and unauthorized access attempts.
No guarantee of absolute security
No security system is impenetrable. While we implement reasonable safeguards to protect your information, we cannot guarantee absolute security. You use our services at your own risk. In the event of a data breach, we will notify affected individuals as required by law.
No certifications claimed
We do not hold and do not claim to hold SOC 2, ISO 27001, HIPAA, PCI-DSS, or any other formal security certifications or attestations. The security practices described above represent our current security measures; they are not certified or independently audited.
9. Your privacy rights under GDPR and UK GDPR
If you are located in the European Union or United Kingdom, you have the following rights regarding your personal data:
Right of access
You have the right to request a copy of your personal data and information about how we process it.
Right of rectification
You have the right to request that we correct inaccurate or incomplete information about you.
Right of erasure (right to be forgotten)
You have the right to request deletion of your personal data, subject to certain exceptions (such as legal obligations, contractual necessity, or our legitimate interests).
Right to restrict processing
You have the right to ask us to limit how we process your information while a dispute is resolved or while we verify accuracy.
Right to data portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to object
You have the right to object to processing of your personal data on the basis of legitimate interests, including for marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds or legal obligations.
Right to withdraw consent
If we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before you withdrew consent.
Right to lodge a complaint
You have the right to lodge a complaint with your local data protection supervisory authority (such as the Information Commissioner's Office in the United Kingdom or your national data protection authority in an EU member state).
10. Your privacy rights under US state laws
California CCPA and CPRA
If you are a resident of California, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:
- Right to know: You have the right to request what personal information we collect, use, and share about you.
- Right to delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to correct: You have the right to request that we correct inaccurate personal information.
- Right to opt out of sharing: You have the right to opt out of our sharing of your personal information for cross-context behavioral advertising or sale.
- No sale or sharing: We do not sell your personal information and do not share it for cross-context behavioral advertising. We therefore do not offer a "sale" or "sharing" opt-out, and you do not need to submit a deletion request for this purpose.
- No financial incentive programs: We do not offer financial incentives, discounts, or other benefits in exchange for the collection, retention, or sharing of personal information.
- Authorized agents: You may designate an authorized agent to submit requests on your behalf if you provide them with written power of attorney.
- Non-discrimination: We will not discriminate against you for exercising your rights. This means we will not deny you service, charge you different prices, or provide you with different quality of service based on your exercise of privacy rights.
Other state privacy laws
If you are a resident of Virginia, Colorado, Connecticut, Utah, or Texas, comparable privacy laws (Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, and Texas Data Privacy and Security Act) grant you similar rights: the right to know what data is collected, the right to delete and correct personal data, the right to opt out of targeted advertising, and the right to access in a portable format. We honor these rights for residents of these states to the same extent as described above for California residents.
11. Children and young people
Our services are not directed to children under the age of 18, and we do not knowingly collect personal information from anyone under 18 years old. If we become aware that we have collected personal information from a child under 13, we will delete such information promptly and cease marketing to that individual, consistent with the Children's Online Privacy Protection Act (COPPA).
If you believe we have collected information from a child, please contact us immediately at [email protected].
12. Do Not Track and Global Privacy Control
Some browsers include a "Do Not Track" (DNT) feature, and some browsers and plugins support the Global Privacy Control (GPC) signal. While we honor GPC signals from your browser as a signal to opt out of our sharing of personal information, we do not alter our data practices in response to DNT headers due to their lack of standardization and universal support.
To opt out of sharing, you may also submit a rights request as described in Section 14.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last updated" date at the top of this page and, where required by law, by posting a notice on our website or sending you an email. Your continued use of our services after such changes constitutes your acceptance of the updated Privacy Policy.
14. How to contact us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a concern about how we handle your information, please contact us:
Visibility Zone LLC
Attn: Privacy
1209 Mountain Road PL NE, STE N
Albuquerque, NM 87110
United States
Email: [email protected]
We will respond to all verified privacy rights requests within 45 days. If you submit a request under the CCPA or CPRA, we may take up to an additional 45 days to respond if necessary. Under GDPR and UK GDPR, we will respond within one calendar month, extendable by two further months if the request is complex.