Skip to main content

Privacy policy

Last updated: 26 September 2026

These pages were drafted for the operator named below and are the terms that apply to the service today. They are not legal advice, and they are awaiting review by a lawyer qualified in Portugal; when that review is finished we will publish the reviewed text and change the date above.

The controller of the personal data described here is the Tasadr team, based in Porto, Portugal, reachable at support@tasadr.ai. Because the controller is established in the European Union, the General Data Protection Regulation applies to this processing for every customer, wherever in the world they are. There is no data protection officer: write to the address above and you reach the person who decides.

  1. 1What we collect

    We collect what the service needs in order to work, and nothing we have no use for:

    • Account data: your email address, your password held only as a hash by Supabase, our authentication provider, and the times your account was created and last signed in.
    • What you enter: the sites you track and their domains, the country, language and dialect you chose for each, an optional description, the competitors you watch, and the questions you add or accept from our suggestions.
    • What measurement produces: for each question and each engine, whether your site was mentioned or cited, the passage of the answer around the mention, the domains and links the engine cited instead, their rank, and the scores and history computed from all of it.
    • What a comparison produces: the competitor page and the page of yours that were compared, their titles, the signals compared, and the summary and suggested actions a language model wrote from them.
    • Google Search Console data, only if you connect it: the email address of the Google account you connect, the list of properties you have verified, your site's top search queries with their impressions and clicks over the last ninety days, the countries those impressions came from, and the OAuth access and refresh tokens that let us read them.
    • Operational and billing records: server and function logs, rate-limit counters, error reports with email addresses stripped out, cookieless page statistics, and the Stripe customer and subscription identifiers, the plan, the billing interval and the date the paid period ends. Your card details are collected and held by Stripe and never reach our servers.
  2. 2Why we process it, and on what legal basis

    We process your account data, your sites, your questions and your results to give you the service you subscribed to and to invoice it: that is performance of the contract between us, Article 6(1)(b) of the GDPR. We process logs, rate-limit counters and error reports to keep the service secure, to detect and prevent abuse, and to find and fix faults, and we use what failures teach us to improve the product: that is our legitimate interest, Article 6(1)(f), balanced against your interests, which is why error reports have email addresses removed before they leave the server. We read your Google Search Console data only on your consent, Article 6(1)(a), given when you connect the account and withdrawable at any time. We build no profiles about you, we take no automated decision producing legal or similarly significant effects on anyone, and we neither sell your data nor use it for advertising.

  3. 3Google Search Console, and the Limited Use disclosure

    Connecting Search Console is optional and the service measures without it. We ask for read-only access on the webmasters.readonly scope, and for your Google account's email address so we can show you which account is linked. We use what we read for three things and nothing else: to list the properties you have verified, to read your top search queries so we can suggest questions worth measuring and show you the query each suggestion was written around, and to read which country your impressions come from so that a site is measured in the market it actually serves. We never write anything to your Google account. Tasadr's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. That data is never sold, never transferred for advertising, never used to build advertising profiles, and never read by a human being except with your consent in order to support you, for a security investigation, or where the law requires it. You can withdraw the connection at any time, inside the product or from your Google account's permissions page, and we then delete the tokens: suggestions from search data stop, and measurement continues on the questions you have saved.

  4. 4Who processes your data for us, and where

    We share data only as far as running the service requires, with providers who process it on our instructions. Vercel hosts the site and runs the serverless functions, in United States regions. Supabase provides the database and the authentication, and sends the account emails that confirm an address or reset a password. OpenRouter relays each question to the model that answers it, which may be OpenAI, Anthropic, Google or Perplexity, and SerpApi fetches Google and Bing result pages; both receive the question text and the market it is asked in, and neither receives your name, your email address or any account identifier. Moz is asked for a domain's authority, which is a domain name and nothing more. Google receives the Search Console requests described above. Stripe takes the payments and holds the billing data. Resend delivers the operational alerts we send ourselves when a run fails; those name a site, never a customer. Sentry receives error reports with email addresses stripped out, and Vercel Analytics and Google Analytics 4 count page views; both run here without cookies (Google Analytics is loaded in Consent Mode with every storage type denied, so it sets no cookie and receives cookieless pings only) and neither identifies the visitor. Several of these providers are established in the United States, so data is transferred outside the European Economic Area: where a provider is certified under the EU-US Data Privacy Framework we rely on that adequacy decision, and where it is not we rely on the European Commission's Standard Contractual Clauses. We also disclose data where the law obliges us to.

  5. 5How long we keep it

    Account data, sites and questions are kept for as long as the account exists. The evidence behind a measurement, meaning the answers and the citations, is deleted automatically one hundred and eighty days after it was measured. Competitor analyses are deleted after ninety days. Records of finished measurement jobs are deleted after thirty days, and rate-limit counters after an hour. Scores and their history are kept for as long as the site is tracked, because they are the history you compare against. Deleting a site deletes its questions, its scores, its citations, its answers and its competitor analyses outright, in one transaction, with no way back. A record that a measurement you started this month ran (the site, the time and its cost, without the questions) is kept until finished job records are deleted at thirty days, so that removing a site does not hand back the month's allowance. There is no self-service account deletion yet, and the settings page says so and says whom to write to: ask at support@tasadr.ai and we delete the account and everything attached to it. Backups may hold copies for a limited period afterwards and are then overwritten in their ordinary cycle.

  6. 6Cookies

    We set only cookies that are strictly necessary for the service to work, so there is no consent banner and nothing to opt out of. They are: the Supabase session cookies, whose names begin with sb- and end with -auth-token, which keep you signed in; locale, which remembers whether you chose Arabic or English; and gsc_oauth_state and gsc_oauth_return, two cookies that live for ten minutes while you connect Google, one protecting the exchange against forgery and one returning you to the page you started from. We set no advertising cookies and place no third-party advertising trackers, and our page statistics (Vercel Analytics, and Google Analytics 4 in Consent Mode with analytics storage denied) are collected without a cookie and without identifying the visitor.

  7. 7Security

    Traffic is encrypted in transit with TLS. Every read and write is scoped on the server to the account that made the request, and ownership is checked on each one rather than trusted from the client. Administrative access is limited to those who need it in order to run the service. Google OAuth tokens are stored with restricted access and are encrypted at rest with AES-256-GCM once the encryption key is configured in the environment; the mechanism is in place and the key is being enabled. No system can promise absolute security. If a breach affects your personal data we will notify the CNPD within seventy-two hours where the GDPR requires it, and tell you directly where the risk to you is high.

  8. 8Your rights

    Under the GDPR you have the right to know whether we process data about you and to receive a copy of it (Article 15), to have it corrected (Article 16), to have it erased (Article 17), to have processing restricted (Article 18), to receive the data you gave us in a machine-readable form and have it sent on (Article 20), to object to processing that rests on our legitimate interest (Article 21), and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Article 22), which is a decision we do not take. Where processing rests on consent you may withdraw it at any time, without affecting what was lawful before. Write to support@tasadr.ai from the address on the account and we answer within one month. If you believe we have handled your data wrongly you may complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), or to the authority where you live or work.

  9. 9Children, and changes to this policy

    Tasadr is sold to businesses and is not for anybody under eighteen. We do not knowingly collect data about a child; if you believe a child has created an account, write to us and we will delete it. We may change this policy as the service changes. The date at the top is the date of the version you are reading, we keep it accurate, and we tell account holders by email before a material change takes effect. These pages are published in Arabic and in English; where the two differ, the English text prevails. For anything in this policy, write to support@tasadr.ai.