Privacy Policy
How we collect, use, and protect your personal data.
Last updated: February 15, 2026
1. Data Controller
The data controller responsible for the processing of your personal data through this website and the lookd platform is:
lookd
Email: support@lookd.io
If you have any questions about how we handle your personal data, please contact us at the email address above.
2. What Data We Collect
We collect and process the following categories of personal data:
Account Information
- Email address (required for registration and login)
- Full name (provided during onboarding)
- Company name and role (provided during onboarding)
- Password (stored securely hashed by our authentication provider)
Brand and Business Data
- Brand names and descriptions you configure
- Website URLs associated with your brands
- Competitor brand information you provide
- Search prompts and queries you create
- Language preferences for your brands
AI Response Data
- Responses generated by third-party AI models (ChatGPT, Claude, Perplexity) in response to your configured search prompts
- Analysis results derived from these responses, including brand mention detection, sentiment scores, visibility metrics, and citation data
Payment Information
- Payment details are processed exclusively by Stripe. We do not store your credit card number, CVC, or full billing details on our servers. We receive only a Stripe customer ID, subscription status, and plan information.
Technical Data
- Authentication session data (cookies necessary for login functionality)
- Server logs including IP addresses, timestamps, and request metadata
3. How We Use Your Data
We process your personal data for the following purposes:
- Providing the Service: Running AI brand monitoring queries, analyzing responses, generating recommendations, and displaying your dashboard data.
- Account Management: Authenticating your identity, managing your subscription, and processing payments.
- Service Improvement: Understanding usage patterns to improve our platform, fix bugs, and develop new features.
- Communication: Sending essential service notifications such as password resets, payment confirmations, and critical account updates.
- Legal Compliance: Meeting legal obligations, responding to lawful requests, and protecting our rights.
4. Legal Basis for Processing (GDPR Art. 6)
We process your data based on the following legal grounds:
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide the lookd service you signed up for, including account creation, AI monitoring, and subscription management.
- Legitimate Interest (Art. 6(1)(f)): Processing for service improvement, security, and fraud prevention, where our interests do not override your rights.
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, such as tax and accounting obligations.
- Consent (Art. 6(1)(a)): Where applicable, for optional communications or features. You can withdraw consent at any time.
5. Data Sharing and Sub-Processors
We share your data only with trusted third-party service providers necessary to operate lookd. We have data processing agreements in place with each provider.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and storage | United States |
| Vercel | Website hosting and serverless functions | United States |
| Stripe | Payment processing and subscription management | United States |
| Anthropic | AI model provider (Claude) | United States |
| OpenAI | AI model provider (ChatGPT) | United States |
| Perplexity | AI model provider (Perplexity Sonar) | United States |
| Upstash | Job queue processing and rate limiting | United States |
We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.
6. International Data Transfers
Our sub-processors are located in the United States. When your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
- EU-U.S. Data Privacy Framework certifications where available
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data processing agreements with each provider
7. Data Retention
We retain your data for as long as necessary to provide our services:
- Account data: Retained for the duration of your account. Deleted upon account deletion request.
- AI response data: Retained for the duration of your account to provide historical analytics and trend tracking.
- Payment records: Retained as required by German tax law (typically 10 years for accounting records).
- Server logs: Automatically deleted after 30 days.
8. Your Rights (GDPR Art. 15-22)
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your personal data. You can delete your account and all associated data directly from your account settings.
- Right to Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@lookd.io. We will respond within 30 days as required by the GDPR.
You also have the right to lodge a complaint with a supervisory authority. In Germany, the relevant authority is the data protection authority (Datenschutzbehörde) of the federal state in which we are established.
9. Account Deletion
You can delete your account at any time from your account settings page. When you delete your account:
- All your personal data is permanently removed from our database
- All brand data, prompts, responses, and analytics are deleted
- Any active subscription is cancelled
- This action is irreversible
10. Cookies
We use only strictly necessary cookies required for authentication and security. We do not use tracking, analytics, or advertising cookies. For detailed information, please see our Cookie Policy.
11. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest in our database
- Row-level security policies ensuring data isolation between users
- Secure password hashing
- Regular security reviews of our codebase and infrastructure
12. Children
lookd is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify registered users of significant changes via email. The "Last updated" date at the top of this page indicates when it was last revised.
14. Contact
If you have questions about this privacy policy or your personal data, please contact us:
Email: support@lookd.io
Have questions about your data?
We're happy to help you understand how your data is handled.