Privacy Policy
The plain-English version
We collect only what we need to run your audits and bill you: your email, the URLs you audit, and the results. We don't sell it, we don't share it with advertisers, and we don't feed it to third-party AI training. When you delete an audit, it's gone. When you close your account, we delete everything within 30 days.
What's different about us: we send the pages you ask us to audit to Anthropic (Claude) to generate the analysis. That's how the product works. Anthropic doesn't train on the data we send them under our API terms.
1. Who we are
Semantic Spy is a product of And Zeros LLC, based in Santa Fe, New Mexico, USA. When this policy says "we," "us," or "our," it means And Zeros LLC. When it says "you," it means the person or company using Semantic Spy through an account you created.
You can reach us any time at hello@andzeros.com.
2. What we collect
Information you give us directly
- Account information — your email address, display name, and password (stored hashed, never in plain text).
- Audit inputs — the URLs you enter, the target keywords, the competitor URLs, the page goal you select, and any optional geographic region.
- Billing information — when you upgrade to a paid tier, our payment processor (Stripe) collects and stores your payment method. We never see or store your full card number.
- Team information — if you invite teammates, we store their email address and role.
Information we generate as you use the product
- Audit results — the analysis output, scores, action plans, entity gaps, and any fixes we generate, all tied to your account.
- AI citation tests — the prompts you test, which AI models you tested them against, whether your page was cited, and what was quoted.
- Usage records — which audits you ran, when, and how many credits they consumed (shown on your Profile as plan and credit limits).
Information collected automatically
- Session and log data — IP address, browser type, timestamps of sign-ins, and basic error logs. We do not use any third-party analytics or advertising trackers on the product.
3. Why we use it
We use your information only for the following purposes:
- To run your audits. We send the URLs you audit to third-party services (see below) to fetch page content, pull SERP data, and generate the analysis.
- To deliver results and history. Your audits are stored so you can revisit them, compare over time, and export as PDF.
- To bill you. Credit consumption, subscription state, and invoices are tracked per account.
- To operate the product. Error logs and rate-limit checks keep the service running reliably.
- To reach you when we need to. Product notifications (billing, security, plan changes) go to your account email. We do not send marketing email unless you explicitly opt in.
- To improve the product. Aggregated usage (which routes are called most, average audit length) helps us prioritize. This is aggregate — we don't tie it back to any individual account.
We do not use your data to train any AI model, nor do we share it with any third party for their training purposes.
5. How long we keep it
- Audit history is kept in your account indefinitely until you delete it or close your account.
- Deleted audits are removed from our active database immediately and purged from encrypted backups within 30 days.
- Closed accounts are fully deleted within 30 days of your cancellation request, including all audits, AI-citation test history, and team data.
- Billing records (invoices, subscription state) are retained for 7 years to comply with US tax and accounting requirements, even after account closure.
- Sign-in and security logs are kept for 90 days for fraud detection and incident response.
6. Your rights
Regardless of where you live, you can:
- Access everything we have on you — request a full export at any time.
- Correct your account details directly from the Profile page.
- Delete individual audits, or close your account entirely (which deletes everything except billing records — see Section 5).
- Export your audit history as CSV or individual audits as PDF, on demand.
- Opt out of any non-essential email. Product/billing notices are required to operate the account; everything else is optional.
If you're a resident of California (CCPA), Virginia (VCDPA), or the EU/UK (GDPR), you have additional statutory rights including the right to non-discrimination for exercising them. Email hello@andzeros.com to exercise any of these — we'll respond within 30 days.
8. Security
- All connections use HTTPS/TLS. Data in transit is encrypted end-to-end.
- Passwords are hashed using industry-standard algorithms (bcrypt / scrypt). We never see or store your plain-text password.
- Database access is protected by row-level security — you can only ever read or modify data belonging to your own account.
- Admin access to the underlying database is restricted to the founder and is used only for support, debugging, and incident response.
- Our sub-processors (Supabase, Vercel, Stripe, Anthropic) are all SOC 2 Type II certified.
No system is perfectly secure. If we discover a data breach affecting your account, we will notify you by email within 72 hours of confirming it.
9. Children
Semantic Spy is a business tool. It is not intended for anyone under 16, and we do not knowingly collect data from anyone under 16. If you believe a minor has created an account, email us and we'll delete it.
10. Changes to this policy
We'll update this page when the practices change. If a change materially reduces your privacy (for example, adding a new sub-processor with different data-handling practices), we'll email account holders at least 30 days before it takes effect. Continued use after the effective date means you accept the updated policy.
All prior versions are available on request.
11. How to reach us
Privacy questions, requests, or complaints:
Doug Saltzman
Founder, And Zeros LLC
hello@andzeros.com
Santa Fe, NM · United States
We'll respond to any privacy request within 30 days.