This Privacy Policy explains how Gen3 Marketing LLC ("Gen3", "we", "us") collects, uses, and shares personal data in connection with the AI Visibility application — our hosted service for measuring brand presence across AI platforms (the "Service").
This policy covers the Service only. Gen3's marketing website (gen3marketing.com) has its own privacy policy.
Two roles apply. For account, billing, security, and product-usage data we act as the data controller, and this policy governs. For personal data contained in workspace content our business customer is the controller and we act as its processor under our Data Processing Addendum — if your data reached the Service through a customer's workspace, that customer's own privacy notices govern and we may refer requests to them (see Section 8).
| Category | What | Source |
|---|---|---|
| Account data | Name, email address, sign-in provider (Microsoft, Google, or email one-time-code), workspace membership and role | You, via sign-up/sign-in (Microsoft Entra External ID) |
| Workspace content | Organization name; brand, product, competitor, location, and owned-domain details; scan configurations and curated prompts | You |
| Scan artifacts | Questions sent to AI providers, the providers' responses, extracted signals, scores, reports, and recommendations | Generated by the Service |
| Billing data | Plan, subscription status, billing email, Stripe customer and subscription identifiers. Full payment-card details go directly to Stripe; we never receive or store them. | You / Stripe |
| Usage and telemetry | Application logs and diagnostic events (which may include your email address as the acting user), scan progress events, feature usage, IP address and user-agent from standard web logs | Automatic |
| Free Pulse Report requests | Email address, website domain, brand name; IP address and user-agent are collected for abuse prevention and are not displayed publicly | You (public form) |
| Sample report access requests | Email address, website domain, brand name, and optional industry, entered to receive a link to our sample report; IP address and user-agent are collected for abuse prevention and are not displayed publicly | You (public form) |
| Contact / "Ask an Expert" | Name, email, and your message | You |
| Marketing attribution and consent (public pages) | Campaign parameters from links you click (utm tags, advertising click identifiers), the referring site, and your cookie-consent choices | Automatic, on our public marketing pages only |
We do not ask for, and you must not submit, sensitive or special-category personal data (e.g. health, biometric, or government-ID data). The Service analyzes brands, not people.
For EEA and UK users: Providing your account data (name and email address) is a contractual requirement necessary to create an account and access the Service. Without this information, we cannot provide you with access to the Service. Providing billing data is necessary if you subscribe to a paid plan. All other data categories listed above are either generated automatically by the Service or provided voluntarily by you to enhance your experience.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the Service — run scans, build reports, operate your workspace | Account data, workspace content, scan artifacts | Contract |
| Send scan prompts to the AI providers you select | Workspace content (prompts) | Contract |
| Billing and subscription management | Account + billing data | Contract |
| Transactional email (report-ready, schedule failures, invitations, Pulse delivery) | Account data, Pulse requests | Contract / legitimate interest |
| Security, abuse prevention, and rate limiting | Telemetry, IP addresses | Legitimate interest |
| Service operations, monitoring, and improvement | Usage and telemetry | Legitimate interest |
| Responding to your inquiries | Contact data | Legitimate interest / contract |
| Legal compliance | As required | Legal obligation |
| Marketing measurement and advertising (public pages only) | Attribution data; analytics/advertising cookie data | Consent |
No Sale of Personal Data. We do not sell personal data. On our public marketing pages only (not inside the signed-in product), and only with your consent, we use Google advertising tags that may constitute "sharing" for cross-context behavioral advertising as defined by the CCPA/CPRA. You can opt out at any time via the "Do Not Sell or Share My Personal Information" link in the page footer, or by using a browser that sends the Global Privacy Control signal, which we honor automatically (see Section 9). We do not sell or share personal information of individuals under 16 years of age. We do not use your data to train AI models — see Sections 3 and 4.
De-Identified Data. We may de-identify (also referred to as "anonymize") and aggregate data for our business purposes, including improving the products and features of the Service, maintaining the security and integrity of our systems, for analytics, and other legitimate business purposes. "De-identified Data" means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual. De-identified Data is no longer "personal data" under applicable data protection laws. Where we process De-identified Data, we commit to maintain and use the information in de-identified form and will not attempt to re-identify the information, except where permitted by law. We may disclose De-identified Data to third parties who commit to maintaining the data in de-identified form and not to re-identify it. To the extent any non-personal information is combined with personal information we collect directly from you, we will treat the combined data as personal information as described in this Privacy Policy.
To produce your reports, the Service sends scan questions (and, where you configure them, brand/competitor context and location preambles) to the third-party AI providers you select. These providers process the prompts to return responses and are engaged as our sub-processors under their business/API terms — which provide that API inputs and outputs are not used to train their models. The current provider list is on our sub-processor page.
We do not use your account data, workspace content, scan prompts, or scan results to train artificial-intelligence models, and we contract with our AI providers on API terms that exclude training use, as described above.
We share personal data only with:
California law requires us to tell you about the personal information we collect about you in a certain way — specifically, we need to tie it back to "legal categories" of personal information that are listed in the law. To do this, we bundled up the information we gave you above in this Notice and matched the different types of personal information we collect about you with the legal category. To make things easier to understand, we've put this information in a chart that shows you five things:
We've included these things in the Personal Information Privacy Chart at the end of this Notice. At the end of the Personal Information Privacy Chart, we also included a list of personal information we disclose for a business purpose.
The Service is hosted in the United States. Where we receive personal data protected by GDPR/UK GDPR, we rely on Standard Contractual Clauses (and the UK Addendum) as described in our Data Processing Addendum.
| Data | Retention |
|---|---|
| Account data, workspace content, scan artifacts | For the life of your workspace, plus a wind-down period of up to 90 days after termination (earlier on verified deletion request — see Section 8) |
| Transient operational records (scan progress, pending checkout sessions) | Up to 7 days (automatic expiry) |
| Billing event records | For the life of your account and for up to seven (7) years thereafter, to meet tax, accounting, audit, and dispute-resolution requirements |
| Public Pulse Report records | Up to 12 months (automatic expiry) |
| Sample report access records | Up to 12 months (automatic expiry) |
| Logs and telemetry | Up to 13 months |
| Backups | Encrypted point-in-time backups retained up to 30 days |
Retention periods above are maximums for routine operation; we may retain specific records longer where required by law (e.g. tax and accounting records) or to resolve disputes. To request deletion of your account or workspace, contact us as described in Section 8; we honor verified requests within the timeframes required by applicable law.
Some privacy laws require that we disclose to you the privacy rights that you have regarding personal information. We have defined the various privacy rights below. These rights may be subject to certain limitations or exceptions depending on your location and the purpose for which we process personal information about you.
Know: You may have the right to know what personal information is being collected, used, shared, and sold about you, including the categories, sources, and business purposes for collecting your personal information.
Access: You may have the right to request access to your personal information.
Erase, Delete: You may have the right to request that we delete or erase your personal information if we do not have a legal or business reason to keep it.
Correct: You may have the right to correct inaccurate personal information we have about you.
Data Portability: You may have the right to obtain personal information in a portable and readily usable format.
Object: You may have the right to object to processing of your personal information where we are relying on a legitimate interest (or that of a third party) and you feel it impacts your fundamental rights and freedoms. You also have the right to object where we are processing your personal information for direct marketing purposes.
Request Restriction: You may have the right to request restriction of processing of your personal information if: (a) you want us to establish the data's accuracy; (b) our use of the data is unlawful but you do not want us to erase it; (c) you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Complain to a Regulator: If you are in the EEA/UK, you may have the right to complain to a government regulator if you are not satisfied with our response.
Limit Processing of Sensitive Personal Information: You may have the right to ask us to limit our use of your sensitive personal information to only what is required to accomplish the purposes disclosed in this Privacy Policy. Our practice is to not process your sensitive personal information except when it is necessary to accomplish the purposes disclosed in this policy.
Non-Retaliation: You have the right not to receive discriminatory or retaliatory treatment for the exercise of any of the privacy rights conferred by applicable law.
Right to Appeal: If we decline to take action regarding your request to exercise any privacy right, you may have the right to appeal the decision.
How to Make a Request: If you would like to make a request, you may submit a request to exercise a privacy right in any of the following ways:
Verifying Your Identity: In order for us to look into your request, we may first need to verify your identity, meaning that we need to make sure that you are the consumer we may have collected personal information about or a person who has been duly authorized to make the request on behalf of the consumer. For example, if you make a request, we will ask you to confirm your name and email address. For certain requests, we will use a combination of your email address, name, and/or zip code to verify your identity.
Responding to Requests: Your request will be evaluated to determine whether the requested change meets legal regulatory requirements and does not risk making our other data less secure. If we are not able to honor any part of your request, we will tell you that in our response, as well as the reason(s) we cannot do so. We respond within the timeframe required by applicable law (one month under GDPR; 45 days under CCPA).
Appealing a Denied Request: If we deny all or part of your privacy request, you may have a right to appeal that decision. If you would like to make an appeal, please contact us using the methods above, and include your name, email address, physical address, the type of request you made, and the reason for requesting an appeal.
Requests by Authorized Agents: You may have the right to designate someone else to make privacy requests for you under the data protection laws. Authorized agents must: (1) provide us with valid written authorization that the third party agent has the authority to act on behalf of the individual whom they are making the request, which must include the agent's name, email address, and phone number; (2) you must follow the instructions above to verify your own identity; and (3) the authorized agent must follow the instructions provided in this section to make a request. As permitted by California privacy law, any request you submit to us is subject to an identification and verification process, and confirmation of the agent's authority, which may include attestation under penalty of perjury. Absent a power of attorney, we will also require the consumer to verify their own identity.
If your data was submitted to the Service by one of our business customers (for example, you were invited to their workspace), we may redirect your request to that customer, as they control that workspace's data.
Signed-in application: essential cookies only — no advertising or third-party analytics cookies.
| Cookie | Purpose | Type |
|---|---|---|
Authentication session cookies (Azure App Service EasyAuth, names beginning AppServiceAuth) |
Keep you signed in | Essential |
| Cloudflare Turnstile | Distinguish humans from bots on public forms | Essential (anti-abuse) |
| Stripe cookies (on Stripe-hosted checkout pages) | Payment processing and fraud prevention | Set by Stripe on its own domain |
Public marketing pages (landing, pricing, sign-in, and public Pulse Report pages): with your consent, we additionally use:
| Technology | Purpose | Type |
|---|---|---|
Google Analytics 4 (_ga and related cookies) |
Understand how our public pages are used | Analytics — consent required |
Google Ads (_gcl_au and related cookies) |
Measure our advertising campaigns | Advertising — consent required |
aiv-consent (browser storage) |
Remember your consent choices | Essential |
aiv-attribution (browser storage) |
First-party record of the campaign link that brought you here | Essential; shared with advertising platforms only if you consent to advertising |
aiv_sample (cookie, 90 days) |
Remembers that you requested access to our sample report so it opens without re-entering the form | Essential |
No analytics or advertising technology runs until you make a choice in the consent banner, and declining leaves the pages fully functional. You can change or withdraw your choice at any time via the "Cookie preferences" link in the footer.
Opt-out preference signals. We honor Global Privacy Control (GPC): if your browser sends GPC, advertising consent is automatically declined and stays declined while the signal is present. You may also opt out via the "Do Not Sell or Share My Personal Information" link in the footer. We do not respond to legacy Do-Not-Track signals.
We use industry-standard safeguards: encryption in transit (TLS) and at rest, secrets management in a hardened vault, role-based access control, per-organization data isolation, continuous backups, and monitoring and alerting. No card data touches our systems (Stripe handles payment capture). No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
The Service is a business tool, is not directed to children, and may not be used by anyone under 18. We do not knowingly collect children's data.
We will post changes here and update the version and effective date above. For material changes we will notify workspace owners by email and in the Service before the change takes effect.
Gen3 Marketing LLC.
Email: info@gen3marketing.com
For privacy-rights requests, use the contact methods in Section 8.
PERSONAL INFORMATION PRIVACY CHART
We collect customers' personal information as described above for the following purposes, when permissible under applicable law.
| Category | Sources | Purpose for Collection and Use | Sharing with Third Parties for a Business Purpose |
|---|---|---|---|
| A. Identifiers. A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers. | You (sign-up/sign-in, workspace setup, billing email, free Pulse Report form, sample report access form, contact and demo-request forms); automatically (IP address, browser/user-agent); Stripe (customer and subscription identifiers). | Create and authenticate your account; operate your workspace; billing and subscription management; transactional email; respond to inquiries; security, abuse prevention and rate limiting; legal compliance. | Service providers under written contract only: cloud hosting/database (Microsoft Azure), identity provider (Microsoft Entra External ID), transactional email (Azure Communication Services), payment processing (Stripe), monitoring/logging (Azure Application Insights), bot protection (Cloudflare Turnstile). Not sold; not shared for cross-context behavioral advertising. |
| B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, marital status, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. | You. Limited to name and email address (and organization name). We do not collect Social Security numbers, driver's license or passport numbers, financial account or payment card numbers, insurance, medical or health information. | Same purposes as Category A. | Same as Category A. Payment card data is collected directly by Stripe on Stripe-hosted pages and is never received or stored by us. |
| C. Characteristics of protected classifications under California or federal law. Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | None collected. | Not applicable. | Not applicable. |
| D. Commercial information. Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | You / Stripe / automatically. Subscription plan and status, purchase and invoice history, and product usage records (e.g., Visibility Tokens consumed, scans run). | Billing and subscription management; quota and plan enforcement; usage reporting to you; support; recordkeeping. | Payment processing (Stripe); cloud hosting/database; monitoring. Not sold or shared for advertising. |
| E. Biometric information. Imagery of the iris, retina, fingerprint, face, hand, palm, vein patterns, and voice recordings, from which an identifier template, such as a faceprint, a minutiae template, or a voiceprint, can be extracted, and keystroke patterns or rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain identifying information. | None collected. | Not applicable. | Not applicable. |
| F. Internet or other similar network activity. Browsing history, search history, information on your interaction with a website, application, or advertisement. | Automatically. Application logs and diagnostic events; first-party page-view, in-product link-click and client-error events (query strings stripped, IP stored only as a hashed value); IP address and user-agent submitted with a free Pulse Report or sample report access request (retained for abuse prevention). On public marketing pages only and with consent: Google Analytics and Google Ads cookies (Section 9). | Security, abuse prevention and rate limiting; service operations, monitoring, troubleshooting and improvement. | Cloud hosting/database; monitoring and logging (Azure Application Insights); bot protection (Cloudflare Turnstile). Not sold. With consent, on public marketing pages only, shared with Google for advertising measurement; opt out via the footer link or GPC. |
| G. Geolocation data. Data that can identify a consumer's physical location or movements. | None collected about you. We do not perform IP-based geolocation or use device location services. (Customers may type geographic markets — e.g., a city, region or country — that they want their brand scanned for; that is business information about the customer's brand, not location data about an individual.) | Not applicable to personal geolocation. Customer-entered market information is used to scope scans. | Geocoding of customer-entered place names is performed via Mapbox or OpenStreetMap; no personal information is sent. |
| H. Sensory data. Audio, electronic, visual, olfactory, or similar information. | None collected. | Not applicable. | Not applicable. |
| I. Professional or employment-related information. Current or past job history or performance evaluations. | You. Limited to business contact information you volunteer — organization or company name, business email address, and any details you include in a demo request or support message. We do not collect job history or performance evaluations. | Respond to inquiries and demo requests; account and workspace administration. | Transactional email provider; cloud hosting. Not sold or shared for advertising. |
| J. Education information that is not publicly available. Information that is not publicly available maintained by an education agency or institution related directly to a student. | None collected. | Not applicable. | Not applicable. |
| K. Inferences drawn from other personal information. Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | None collected. | Not applicable. | Not applicable. |
| L. Sensitive personal information. Personal information that reveals a consumer's: Social Security number, driver's license number, state identification card number, or passport number; a consumer's account log-in, financial account, debit card, or credit card number in combination with any security or access code, password, or credentials allowing access to an account; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, or union membership; the contents of a consumer's mail, email, and text messages (not business related); genetic data; biometric data used to uniquely identify a consumer; health data; or data related to sex life or sexual orientation. | None collected. | Not applicable. | Not applicable. |
We may also collect information to comply with applicable law or regulatory requirements or legal requests.
In the preceding twelve (12) months, we have disclosed the following categories of Personal Information for a business purpose:
Category A: Identifiers
Category B: California Customer Records Categories
Category C: Protected Classifications
Category D: Commercial Information
Category F: Internet and Network Activity
Category G: Geolocation Data
Category L: Sensitive Personal Information