Privacy Policy
Version v3 · effective 2026-09-10
Ignite Agent — Privacy Policy
Version: v3 · Effective: 2026-09-10 · English text governs.
This Privacy Policy explains what Ignite Agent ("Ignite", "we") processes when you use the platform, why, and who it is shared with. For the controller/processor terms that a Customer's counsel can file, see our Data Processing Addendum (DPA).
1. What we process
- Account data: dashboard user names, email addresses, roles, language preference, and authentication metadata. Two-factor secrets and recovery codes are stored encrypted. We also record the IP address and browser user-agent at signup and when you accept these documents, as evidence of that acceptance.
- Site configuration: connected site domains, settings, and category prompts. Prompts may be configured by you or proposed by the platform for your review; you can edit or remove any of them at any time.
- Answer corpus: the answer text and cited sources returned by AI engines for your prompts, together with derived metrics (branded vs non-branded mention rates, grounded vs parametric tags). To check what a cited source says about you, we also retrieve publicly available pages elsewhere on the web that those answers cite.
- Connected account data: where you connect a search or analytics account, the data we read from it on your authorisation — search terms, page-level search performance, and traffic figures — together with the access credentials that permit those reads until you disconnect. See section 6.
- Traffic and crawl data (hosted sites): CDN and crawl-log records including IP address and user-agent, used to distinguish AI-agent traffic from human traffic. See section 6.
- Site performance data: where you install our software on your site, page-performance measurements taken in your visitors' browsers. Recorded against the page, never against the person: no name, email, cookie or other identifier that would let us recognise a visitor. See section 6.
- Conversion events: where you send us conversion events for attribution, each event with the reference you supply and the details you attach to it. See section 6.
- Communications: messages you send us by email, through the platform, or over WhatsApp, and our replies.
- Credentials you supply: where you provide your own AI provider keys, we store them encrypted and never display them again after entry.
- Billing data: plan, entitlement, and payment status. Card data is handled by Stripe; we store no card number, card type or expiry — only the references that identify your customer and subscription record.
2. Why we process it
To deliver the service you purchased: running sweeps, producing analytics and reports, enforcing entitlement caps, billing, support, and securing the platform. We do not sell personal data.
3. Subprocessors
We share data with the following subprocessors, each only as needed to run the service:
- Google Cloud Platform — application, database and AI-processing services (region
europe-west4, EU, Netherlands). - Stripe — payments and billing.
- Sentry — error monitoring. Our error pipeline scrubs prompt text, answer text, cited sources, IP and user-agent fields before events are stored.
- AWS CloudFront — content delivery and traffic logs for hosted sites.
- Cloudflare — bot protection on our public scan form. A visitor's IP address is sent to Cloudflare to verify that the request is not automated.
- AI engine providers — OpenAI, Anthropic, Google, Perplexity, and xAI. Your prompts and the engines' answers are sent to these providers as the function of the service (that is how a sweep runs), not as telemetry.
4. Retention
Operational data is held in our primary database while your account is active. Sweep records older than 90 days are moved to archival storage. Acceptance and billing records are retained as legal and financial evidence. On termination, data is deleted or exported per the DPA.
5. Your rights
Subject to applicable data-protection law (including GDPR- and PDPL-style rights), you may access, correct, export or delete the personal data we process about you, and you may object to certain processing.
You can exercise the main ones yourself, from Settings in the dashboard, at any time:
- Access and portability: download a copy of every record we hold about you as one machine-readable file. It is assembled when you ask for it, from the live database.
- Correction: change your name and your language there; write to us to change your sign-in email.
- Erasure: delete your account. Your name, email, password, second factor and linked sign-ins are erased at once and you are removed from every workspace. If you were the only member of a workspace, that workspace is closed at the same time and its data is erased 30 days later; if you are its only owner and other people still use it, you are asked to hand ownership on first, and if it still has a paid subscription you are asked to cancel it first, so no one is charged for a workspace nobody can reach.
Acceptance and billing records are kept as legal and financial evidence after an erasure (section 4), with no name or email attached to them. For anything you cannot do from Settings, or to object to a processing, contact privacy@igniteagent.ai; we answer within one month.
6. Who is responsible for what
For your account, your billing, and your use of the platform, we are the data controller.
For data that originates from your website's visitors and from your connected accounts — the traffic and crawl records, site performance measurements, conversion events, and search and analytics data described in section 1 — you are the controller and we act as your processor. We process it only on your instructions and only to provide the service, we do not use it for any purpose of our own, and it is governed by our DPA. If you instruct us to delete it, we delete it.
You are responsible for having a lawful basis for the data you connect or send us, and for any notice or consent your own visitors require.
7. Cookies
The dashboard uses first-party session cookies only, for authentication. It does not set advertising or cross-site tracking cookies.
8. Changes
We may publish a new version of this Policy; prior versions remain retrievable and the effective date is shown on each version.
9. Contact
privacy@igniteagent.ai.