LightSpot

Legal

Privacy Policy

Last updated September 4, 2026

This Privacy Policy explains what personal data LightSpot collects when you use the Service, why we collect it, how we share it, how long we keep it, and the rights you have over it. We try to keep this document short and concrete — if anything is unclear, write to privacy@lightspot.ai.

1.Who we are

For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is LightSpot.ai, contactable at privacy@lightspot.ai.

2.What we collect

  • Account data: email address, display name, and the authentication provider you used (magic link or Google).
  • Audit data: the URLs you submit, the public HTML content fetched at those URLs, the criteria results we compute, and the reports we generate. Reports include scores, issues, fixes, and optionally a competitor analysis.
  • Billing data: we do not store credit-card numbers. Stripe stores them on our behalf and shares back a customer ID, subscription status, plan, and invoice history.
  • API key metadata: name you give the key, the SHA-256 hash of the key (we never store the key in cleartext), the first 15 characters of the key for UI recognition, the last-used timestamp, and the revocation timestamp.
  • Logs: request method and path, timestamp, response code, and the IP address making the request — kept for security and debugging for up to 30 days.
  • Usage data: pages viewed, actions performed in the product, browser and device information, and approximate location derived from your IP address — collected through our first-party analytics tool (PostHog, hosted in the EU). When you are signed in, this data is linked to your user ID. You can object at any time — see "Cookies & analytics" below.

3.Why we collect it (legal basis)

  • Performance of contract (GDPR art. 6(1)(b)) — to provide the Service you signed up for: running audits, storing reports, processing payments.
  • Legitimate interest (art. 6(1)(f)) — to keep the Service secure, fight abuse, improve the methodology with anonymized aggregate metrics, and measure how the Service is used through our first-party analytics (see "Cookies & analytics"). You can object to this measurement at any time.
  • Consent (art. 6(1)(a)) — to store the analytics cookie that recognizes your browser across visits. It is only set after you accept in the cookie widget, and you can withdraw your consent at any time by reopening the widget.
  • Legal obligation (art. 6(1)(c)) — to issue invoices and respond to lawful requests from authorities.

4.How long we keep it

  • Account data: until you close your account, then deleted within 30 days.
  • Audit reports and crawled HTML snippets: indefinitely while your account is active, deleted within 30 days of account closure unless you delete them sooner.
  • API keys: indefinitely while not revoked; revoked keys are kept (hash + metadata) for audit-trail purposes.
  • Stripe subscription state: kept as long as the subscription is active and for the legal retention period required for accounting (up to 10 years).
  • Server logs: 30 days.
  • Analytics events: kept in PostHog (EU) for as long as needed for audience measurement; you can request deletion at any time (see "Your rights").

5.Sub-processors

To provide the Service we share data with the following providers, only to the extent necessary for the purpose listed:

ProviderPurposeWhat is shared
Anthropic (Claude)Semantic GEO checks, content keyword extractionPage text + targeted prompts
OpenAICompetitor citation probing (web_search tool)Question-style prompts derived from your topics
PerplexityCompetitor citation probing (Sonar API)Question-style prompts derived from your topics
Google PageSpeed InsightsCore Web Vitals measurement (S18-S21)Page URL
StripePayment processingEmail, name, payment method
ResendTransactional email (magic link, audit reports)Email address, message content
PostHog (EU Cloud)Product analytics, audience measurement, session replayUsage events (pages viewed, product actions), device and browser info, IP-derived location, user ID when signed in, session replays (only after you consent)
Axeptio (France)Cookie consent management (widget and proof-of-consent storage)Your consent choices and a consent token
Amazon Web Services (EU regions)Archive of AI citation probe results; isolated build sandboxes for the code autofixProbe results; repository content you connect for verified fixes
Google (Gemini)Generation of social post visualsThe article or post content you generate a visual for
BetterAuth (open-source library on our infra)AuthenticationSession tokens
Cloud hosting (Vercel-class provider)Application hosting and databaseAll data, encrypted at rest

We update this list as our infrastructure evolves. Material additions are announced by email at least 30 days before they take effect.

6.Cookies & analytics

Strictly-necessary cookies — required for the Service to work:

  • better-auth.session_token — to keep you signed in. Httponly, expires after 7 days.
  • axeptio_cookies and its axeptio_* companions — store the choices you make in our cookie consent widget (provided by Axeptio) so we don't ask again on every page. Expire after 12 months.
  • Stripe cookies on the checkout page, for payment fraud detection. Set on Stripe's domain only.

Advertising attribution cookie — when you arrive from an advertising campaign (for example a ChatGPT/OpenAI ad), we set a first-party cookie (ls_attr, HttpOnly, expires after 30 days) that stores the identifier of that advertising click. It is used only to measure which campaign led to an audit or an account. No third party receives it, and it is never used to track you across other websites.

First-party analytics — we measure audience and product usage with PostHog, hosted in the EU. Until you make a choice in the cookie widget, this measurement runs without any cookie or persistent identifier on your device, so visits cannot be linked to each other. If you accept, PostHog stores a first-party cookie and browser localStorage entries to recognize your browser on returning visits and group page views into sessions. If you decline, analytics collection stops entirely on your browser. You can change your choice at any time by reopening the cookie widget, or by writing to privacy@lightspot.ai. If you accept, we may also record a replay of your session (pages viewed, clicks and scrolls) to diagnose usability problems. Replays never start before you consent, anything you type in sensitive fields is masked, and recordings are stored in the EU.

We do not use third-party advertising or cross-site tracking cookies, and analytics data is never shared with ad networks or data brokers.

7.International transfers

Some of our sub-processors (notably Anthropic, OpenAI, Perplexity, Stripe) are based in the United States. Transfers rely on Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework. We do not transfer data outside the EU/EEA without an adequate legal basis. Analytics data collected by PostHog is hosted in the EU and does not leave it.

8.Your rights

If you are a resident of the EU/EEA or UK, you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion of your data (subject to our legal retention obligations);
  • request a portable copy of your data;
  • object to processing based on legitimate interest;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the CNIL or your local data protection authority.

To exercise any of these rights, write to privacy@lightspot.ai. We respond within 30 days.

9.Data Processing Addendum (DPA)

For Business and Enterprise customers using the Service to audit third-party content, a standalone DPA is available on request. Email privacy@lightspot.ai.

10.Changes to this policy

We will notify you of material changes by email and dashboard banner at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.