Privacy Policy
Last updated 6 August 2026
This policy is a starting point drafted for a small SaaS business. It is not legal advice, and it describes how the software actually behaves rather than an aspiration. Have a lawyer confirm it satisfies the regimes you operate under before you take paying customers.
1. Who we are
SaidFirst provides AI visibility monitoring to marketing agencies. For the account data of agency users we act as the data controller. For the client and brand data an agency enters into its workspaces we act as a processor on that agency’s instructions.
2. What we collect
- Account data. Your name, email address, agency name, and a bcrypt hash of your password. We never store your password itself. If you sign in with Google we receive your name, email and profile image from Google.
- Two-factor data, if you turn it on. The shared secret your authenticator app holds, encrypted at rest, plus one-way hashes of your recovery codes and the time-slot of the last code you used. No phone number and no device identifier is involved: the factor is a code your own app computes, so there is nothing about you to collect. Turning two-factor off deletes all of it.
- Workspace data. The client names, brand names, domains, category descriptions, competitor names and prompts you configure.
- Sweep results. The answers AI assistants return for your prompts, the mentions and rankings extracted from them, citations, and the scores computed from all of it.
- Branding assets. Company name, logo URL, colours and report footer for white-label reports.
- Billing data. Plan, subscription status and billing interval, plus customer and subscription identifiers from our payment processor. Card numbers go directly to the processor and never reach our servers.
- Usage metering. Counts of engine calls and AI token usage per organisation, used for cost accounting and plan enforcement.
- Operational logs. Server logs from our hosting provider, which include IP addresses and request metadata.
We do not run advertising trackers and we do not sell personal data.
3. Why we process it
To provide the service you signed up for (performance of a contract); to charge you (also contract); to secure the service, prevent abuse and enforce plan limits (legitimate interests); to send service and alert emails you have configured (contract and legitimate interests); and to meet accounting and legal obligations (legal obligation).
4. Third parties that process data for us
- AI providers(Anthropic, OpenAI, Perplexity, Google, SerpAPI — each only when enabled). Your prompts — and the brand and competitor names inside them — are sent to the AI assistants you enable so we can record how they answer. That is the core function of the product. Each provider handles the data under its own terms.
- Hosting and database. Vercel hosts the application; Neon provides the managed Postgres database; Cloudflare provides DNS.
- Payments. Stripe processes subscriptions and holds card details.
- Email. Resend delivers transactional email such as password resets and score alerts.
- Keyword volumes. DataForSEO, when enabled, receives extracted head terms from prompts for search-volume lookups — sent in a flat batch with no client, workspace or account identifier attached, though a term may itself contain a brand name if your prompt does.
The complete register, with what each processor receives and its keyless fallback, is at /legal/subprocessors. We give 14days’ email notice before adding a sub-processor that would process customer data.
Do not enter special-category personal data or anything you are not permitted to share with these processors into a workspace.
5. Where data is held
Production data is hosted in the United States (single region). We do not currently offer EU data residency; an EU-hosted deployment can be provisioned on request for customers who need it contractually. Where a transfer requires a safeguard, we rely on the mechanisms our processors offer, such as the EU standard contractual clauses.
6. How long we keep it
Workspace and sweep data is kept for as long as your account is active, because trend charts depend on history. When you delete a client workspace (Workspace → Danger zone) its competitors, prompts, sweeps, results, scores, briefs and portal access are deleted immediately and permanently; cost-accounting entries survive without the workspace link. To close your account entirely, email privacy@saidfirst.aifrom your account address — we verify the request against that address, provide a full export first if you want one, and complete deletion within 30 days. Cost-accounting totals are retained without any link to you, which is the only record that outlives the account.
Operational records are deleted automatically on a published schedule: abuse-prevention counters after a day, delivery records for notification emails after a week, and spent password-reset and portal-access tokens after 30 days. Counters are keyed by a one-way hash, so no email address or IP is written to them, and any credential inside a stored email is redacted before the record is saved. The full table is on our trust page. Password reset tokens expire after 60 minutes and are single-use; portal invitations after 72 hours.
7. Security
Passwords are hashed with bcrypt. Sessions use signed JWTs in HTTP-only cookies. Every query for organisation data goes through a central authorisation layer that scopes it to your organisation. Public client portal links are gated by an unguessable token and by your plan, and can be regenerated. Traffic is served over TLS. No system is perfectly secure; we will notify affected customers of a personal-data breach without undue delay and within 72 hours of becoming aware of it, and any relevant regulator as required by law. The full security posture, with code-level evidence, is published at /trust.
8. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Email privacy@saidfirst.aiand we will respond within 30 days. If your data sits inside an agency’s workspace, contact that agency — we will refer your request to them and support them in answering it.
9. Cookies
We set a session cookie so you stay logged in, and a CSRF cookie to protect form submissions. Both are strictly necessary for the product to work, so we do not show a consent banner for them. We do not use advertising or analytics cookies.
10. Children
SaidFirst is a business tool and is not intended for anyone under 16.
11. Changes
We will post updates here and change the date above. Material changes will be announced by email or in the product.
12. Contact
Privacy questions: privacy@saidfirst.ai.