Privacy Policy
Last updated 26 July 2026
This policy is a starting point drafted for a small SaaS business. It is not legal advice, and it describes how the software actually behaves rather than an aspiration. Have a lawyer confirm it satisfies the regimes you operate under before you take paying customers.
1. Who we are
SaidFirst provides AI visibility monitoring to marketing agencies. For the account data of agency users we act as the data controller. For the client and brand data an agency enters into its workspaces we act as a processor on that agency’s instructions.
2. What we collect
- Account data. Your name, email address, agency name, and a bcrypt hash of your password. We never store your password itself. If you sign in with Google we receive your name, email and profile image from Google.
- Workspace data. The client names, brand names, domains, category descriptions, competitor names and prompts you configure.
- Sweep results. The answers AI assistants return for your prompts, the mentions and rankings extracted from them, citations, and the scores computed from all of it.
- Branding assets. Company name, logo URL, colours and report footer for white-label reports.
- Billing data. Plan, subscription status and billing interval, plus customer and subscription identifiers from our payment processor. Card numbers go directly to the processor and never reach our servers.
- Usage metering. Counts of engine calls and AI token usage per organisation, used for cost accounting and plan enforcement.
- Operational logs. Server logs from our hosting provider, which include IP addresses and request metadata.
We do not run advertising trackers and we do not sell personal data.
3. Why we process it
To provide the service you signed up for (performance of a contract); to charge you (also contract); to secure the service, prevent abuse and enforce plan limits (legitimate interests); to send service and alert emails you have configured (contract and legitimate interests); and to meet accounting and legal obligations (legal obligation).
4. Third parties that process data for us
- AI providers.Your prompts — and the brand and competitor names inside them — are sent to the AI assistants you enable so we can record how they answer. That is the core function of the product. Each provider handles the data under its own terms.
- Hosting and database. Application hosting and a managed Postgres database.
- Payments. Stripe processes subscriptions and holds card details.
- Email. Resend delivers transactional email such as password resets and score alerts.
Do not enter special-category personal data or anything you are not permitted to share with these processors into a workspace.
5. Where data is held
Data is stored on infrastructure that may be located outside your country, including in the United States. Where a transfer requires a safeguard, we rely on the mechanisms our processors offer, such as the EU standard contractual clauses.
6. How long we keep it
Workspace and sweep data is kept for as long as your account is active, because trend charts depend on history. When you delete a client workspace its sweeps, results and scores are deleted with it. When you close your account we delete your workspace data within 30 days, except records we must retain for accounting purposes. Password reset tokens expire after 60 minutes and are single-use.
7. Security
Passwords are hashed with bcrypt. Sessions use signed JWTs in HTTP-only cookies. Every query for organisation data goes through a central authorisation layer that scopes it to your organisation. Public client portal links are gated by an unguessable token and by your plan, and can be regenerated. Traffic is served over TLS. No system is perfectly secure; we will notify you and any relevant regulator of a breach affecting your data as required by law.
8. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Email privacy@saidfirst.aiand we will respond within 30 days. If your data sits inside an agency’s workspace, contact that agency — we will refer your request to them and support them in answering it.
9. Cookies
We set a session cookie so you stay logged in, and a CSRF cookie to protect form submissions. Both are strictly necessary for the product to work, so we do not show a consent banner for them. We do not use advertising or analytics cookies.
10. Children
SaidFirst is a business tool and is not intended for anyone under 16.
11. Changes
We will post updates here and change the date above. Material changes will be announced by email or in the product.
12. Contact
Privacy questions: privacy@saidfirst.ai.