Legal
Privacy Policy
Last updated September 4, 2026
This Privacy Policy explains what personal data LightSpot collects when you use the Service, why we collect it, how we share it, how long we keep it, and the rights you have over it. We try to keep this document short and concrete — if anything is unclear, write to privacy@lightspot.ai.
1.Who we are
For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is LightSpot.ai, contactable at privacy@lightspot.ai.
2.What we collect
- Account data: email address, display name, and the authentication provider you used (magic link or Google).
- Audit data: the URLs you submit, the public HTML content fetched at those URLs, the criteria results we compute, and the reports we generate. Reports include scores, issues, fixes, and optionally a competitor analysis.
- Billing data: we do not store credit-card numbers. Stripe stores them on our behalf and shares back a customer ID, subscription status, plan, and invoice history.
- API key metadata: name you give the key, the SHA-256 hash of the key (we never store the key in cleartext), the first 15 characters of the key for UI recognition, the last-used timestamp, and the revocation timestamp.
- Logs: request method and path, timestamp, response code, and the IP address making the request — kept for security and debugging for up to 30 days.
- Usage data: pages viewed, actions performed in the product, browser and device information, and approximate location derived from your IP address — collected through our first-party analytics tool (PostHog, hosted in the EU). When you are signed in, this data is linked to your user ID. You can object at any time — see "Cookies & analytics" below.
3.Why we collect it (legal basis)
- Performance of contract (GDPR art. 6(1)(b)) — to provide the Service you signed up for: running audits, storing reports, processing payments.
- Legitimate interest (art. 6(1)(f)) — to keep the Service secure, fight abuse, improve the methodology with anonymized aggregate metrics, and measure how the Service is used through our first-party analytics (see "Cookies & analytics"). You can object to this measurement at any time.
- Consent (art. 6(1)(a)) — to store the analytics cookie that recognizes your browser across visits. It is only set after you accept in the cookie widget, and you can withdraw your consent at any time by reopening the widget.
- Legal obligation (art. 6(1)(c)) — to issue invoices and respond to lawful requests from authorities.
4.How long we keep it
- Account data: until you close your account, then deleted within 30 days.
- Audit reports and crawled HTML snippets: indefinitely while your account is active, deleted within 30 days of account closure unless you delete them sooner.
- API keys: indefinitely while not revoked; revoked keys are kept (hash + metadata) for audit-trail purposes.
- Stripe subscription state: kept as long as the subscription is active and for the legal retention period required for accounting (up to 10 years).
- Server logs: 30 days.
- Analytics events: kept in PostHog (EU) for as long as needed for audience measurement; you can request deletion at any time (see "Your rights").
5.Sub-processors
To provide the Service we share data with the following providers, only to the extent necessary for the purpose listed:
| Provider | Purpose | What is shared |
|---|---|---|
| Anthropic (Claude) | Semantic GEO checks, content keyword extraction | Page text + targeted prompts |
| OpenAI | Competitor citation probing (web_search tool) | Question-style prompts derived from your topics |
| Perplexity | Competitor citation probing (Sonar API) | Question-style prompts derived from your topics |
| Google PageSpeed Insights | Core Web Vitals measurement (S18-S21) | Page URL |
| Stripe | Payment processing | Email, name, payment method |
| Resend | Transactional email (magic link, audit reports) | Email address, message content |
| PostHog (EU Cloud) | Product analytics, audience measurement, session replay | Usage events (pages viewed, product actions), device and browser info, IP-derived location, user ID when signed in, session replays (only after you consent) |
| Axeptio (France) | Cookie consent management (widget and proof-of-consent storage) | Your consent choices and a consent token |
| Amazon Web Services (EU regions) | Archive of AI citation probe results; isolated build sandboxes for the code autofix | Probe results; repository content you connect for verified fixes |
| Google (Gemini) | Generation of social post visuals | The article or post content you generate a visual for |
| BetterAuth (open-source library on our infra) | Authentication | Session tokens |
| Cloud hosting (Vercel-class provider) | Application hosting and database | All data, encrypted at rest |
We update this list as our infrastructure evolves. Material additions are announced by email at least 30 days before they take effect.
6.Cookies & analytics
Strictly-necessary cookies — required for the Service to work:
better-auth.session_token— to keep you signed in. Httponly, expires after 7 days.axeptio_cookiesand itsaxeptio_*companions — store the choices you make in our cookie consent widget (provided by Axeptio) so we don't ask again on every page. Expire after 12 months.- Stripe cookies on the checkout page, for payment fraud detection. Set on Stripe's domain only.
Advertising attribution cookie — when you arrive from an advertising campaign (for example a ChatGPT/OpenAI ad), we set a first-party cookie (ls_attr, HttpOnly, expires after 30 days) that stores the identifier of that advertising click. It is used only to measure which campaign led to an audit or an account. No third party receives it, and it is never used to track you across other websites.
First-party analytics — we measure audience and product usage with PostHog, hosted in the EU. Until you make a choice in the cookie widget, this measurement runs without any cookie or persistent identifier on your device, so visits cannot be linked to each other. If you accept, PostHog stores a first-party cookie and browser localStorage entries to recognize your browser on returning visits and group page views into sessions. If you decline, analytics collection stops entirely on your browser. You can change your choice at any time by reopening the cookie widget, or by writing to privacy@lightspot.ai. If you accept, we may also record a replay of your session (pages viewed, clicks and scrolls) to diagnose usability problems. Replays never start before you consent, anything you type in sensitive fields is masked, and recordings are stored in the EU.
We do not use third-party advertising or cross-site tracking cookies, and analytics data is never shared with ad networks or data brokers.
7.International transfers
Some of our sub-processors (notably Anthropic, OpenAI, Perplexity, Stripe) are based in the United States. Transfers rely on Standard Contractual Clauses or, where applicable, the EU-US Data Privacy Framework. We do not transfer data outside the EU/EEA without an adequate legal basis. Analytics data collected by PostHog is hosted in the EU and does not leave it.
8.Your rights
If you are a resident of the EU/EEA or UK, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data (subject to our legal retention obligations);
- request a portable copy of your data;
- object to processing based on legitimate interest;
- withdraw consent where processing is based on consent;
- lodge a complaint with the CNIL or your local data protection authority.
To exercise any of these rights, write to privacy@lightspot.ai. We respond within 30 days.
9.Data Processing Addendum (DPA)
For Business and Enterprise customers using the Service to audit third-party content, a standalone DPA is available on request. Email privacy@lightspot.ai.
10.Changes to this policy
We will notify you of material changes by email and dashboard banner at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.