Legal

Privacy Policy

How we collect, use, and protect your personal data.

Last updated: February 15, 2026

1. Data Controller

The data controller responsible for the processing of your personal data through this website and the lookd platform is:

lookd
Email: support@lookd.io

If you have any questions about how we handle your personal data, please contact us at the email address above.

2. What Data We Collect

We collect and process the following categories of personal data:

Account Information

  • Email address (required for registration and login)
  • Full name (provided during onboarding)
  • Company name and role (provided during onboarding)
  • Password (stored securely hashed by our authentication provider)

Brand and Business Data

  • Brand names and descriptions you configure
  • Website URLs associated with your brands
  • Competitor brand information you provide
  • Search prompts and queries you create
  • Language preferences for your brands

AI Response Data

  • Responses generated by third-party AI models (ChatGPT, Claude, Perplexity) in response to your configured search prompts
  • Analysis results derived from these responses, including brand mention detection, sentiment scores, visibility metrics, and citation data

Payment Information

  • Payment details are processed exclusively by Stripe. We do not store your credit card number, CVC, or full billing details on our servers. We receive only a Stripe customer ID, subscription status, and plan information.

Technical Data

  • Authentication session data (cookies necessary for login functionality)
  • Server logs including IP addresses, timestamps, and request metadata

3. How We Use Your Data

We process your personal data for the following purposes:

  • Providing the Service: Running AI brand monitoring queries, analyzing responses, generating recommendations, and displaying your dashboard data.
  • Account Management: Authenticating your identity, managing your subscription, and processing payments.
  • Service Improvement: Understanding usage patterns to improve our platform, fix bugs, and develop new features.
  • Communication: Sending essential service notifications such as password resets, payment confirmations, and critical account updates.
  • Legal Compliance: Meeting legal obligations, responding to lawful requests, and protecting our rights.

4. Legal Basis for Processing (GDPR Art. 6)

We process your data based on the following legal grounds:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to provide the lookd service you signed up for, including account creation, AI monitoring, and subscription management.
  • Legitimate Interest (Art. 6(1)(f)): Processing for service improvement, security, and fraud prevention, where our interests do not override your rights.
  • Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, such as tax and accounting obligations.
  • Consent (Art. 6(1)(a)): Where applicable, for optional communications or features. You can withdraw consent at any time.

5. Data Sharing and Sub-Processors

We share your data only with trusted third-party service providers necessary to operate lookd. We have data processing agreements in place with each provider.

ProviderPurposeLocation
SupabaseDatabase, authentication, and storageUnited States
VercelWebsite hosting and serverless functionsUnited States
StripePayment processing and subscription managementUnited States
AnthropicAI model provider (Claude)United States
OpenAIAI model provider (ChatGPT)United States
PerplexityAI model provider (Perplexity Sonar)United States
UpstashJob queue processing and rate limitingUnited States

We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.

6. International Data Transfers

Our sub-processors are located in the United States. When your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • EU-U.S. Data Privacy Framework certifications where available
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with each provider

7. Data Retention

We retain your data for as long as necessary to provide our services:

  • Account data: Retained for the duration of your account. Deleted upon account deletion request.
  • AI response data: Retained for the duration of your account to provide historical analytics and trend tracking.
  • Payment records: Retained as required by German tax law (typically 10 years for accounting records).
  • Server logs: Automatically deleted after 30 days.

8. Your Rights (GDPR Art. 15-22)

As a data subject under the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to Erasure (Art. 17): Request deletion of your personal data. You can delete your account and all associated data directly from your account settings.
  • Right to Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
  • Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at support@lookd.io. We will respond within 30 days as required by the GDPR.

You also have the right to lodge a complaint with a supervisory authority. In Germany, the relevant authority is the data protection authority (Datenschutzbehörde) of the federal state in which we are established.

9. Account Deletion

You can delete your account at any time from your account settings page. When you delete your account:

  • All your personal data is permanently removed from our database
  • All brand data, prompts, responses, and analytics are deleted
  • Any active subscription is cancelled
  • This action is irreversible

10. Cookies

We use only strictly necessary cookies required for authentication and security. We do not use tracking, analytics, or advertising cookies. For detailed information, please see our Cookie Policy.

11. Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS)
  • Encryption of data at rest in our database
  • Row-level security policies ensuring data isolation between users
  • Secure password hashing
  • Regular security reviews of our codebase and infrastructure

12. Children

lookd is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify registered users of significant changes via email. The "Last updated" date at the top of this page indicates when it was last revised.

14. Contact

If you have questions about this privacy policy or your personal data, please contact us:

Email: support@lookd.io

Have questions about your data?

We're happy to help you understand how your data is handled.