Last updated: July 24, 2026.
GenSig (gensig.app) — [email protected].
| Data | Why |
|---|---|
| Email address | Account sign-in (passwordless magic links) and essential service emails. |
| Brand configurations | The domains, questions, competitors and annotations you set up — the core of the Service. |
| Analysis results | AI engine answers and derived metrics, archived so you can see trends. |
| Usage records | A log of analyses run, used for plan limits and billing history. Retained even if brands are deleted. |
| Workspace activity | An audit log of configuration changes and team actions, visible to your workspace. |
We do not collect passwords (sign-in is passwordless), payment card data (handled entirely by Paddle, our Merchant of Record) or advertising identifiers.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and realtime infrastructure. |
| OpenAI | Running the category questions on ChatGPT with web search to produce analyses. Questions are brand-neutral by design; your site's public content may be included in prompts. |
| Google (Gemini) | Running the same category questions on Gemini with Google Search grounding. Same brand-neutral questions; no personal data is sent. |
| Paddle | Checkout, subscription billing, taxes and invoices. |
| Resend | Delivery of sign-in and service emails. |
| Railway | Application hosting. |
Deleting a brand permanently removes its configuration, archived reports and monitors. Usage records (count and timestamps of analyses) are retained for billing integrity. You can delete your entire account and all associated data yourself from Settings → Delete account — it takes effect immediately and also cancels any active subscription. To prevent abuse of the free allowance, we retain only an irreversible cryptographic hash of the deleted account's email with its free-usage count — no readable personal data. If you prefer, email [email protected] and we'll do it for you within 30 days.
Depending on your jurisdiction (e.g. GDPR, CCPA), you may have rights to access, correct, export or delete your personal data, and to object to or restrict processing. Contact us and we will respond within 30 days.
Data is encrypted in transit, access to production systems is restricted and authenticated, and sign-in uses single-use email links instead of stored passwords. No system is perfectly secure; we will notify affected users of any breach as required by law.
Material changes to this policy will be announced by email or in-app before they take effect.