How GEO Lens Diagnosis collects, uses, stores, shares, and protects account, diagnosis, report, wallet, and technical data
2026/07/04
This Privacy Policy explains how GEO Lens Diagnosis collects, uses, stores, shares, and protects personal data and business data when you access the website, register an account, create brand profiles, run diagnosis tasks, view reports, share reports, purchase or use credits, request support, or interact with administrators.
At the current stage, the service is operated by an individual service provider. That individual service provider acts as the personal information processor for information processed in connection with the service and decides the purposes and methods of processing. Requests to contact us, access, correct, delete, withdraw consent, close an account, or complain may be submitted through Contact. For identity verification, orders, refunds, infringement complaints, or legal requests, we may first need to verify your account email, order ID, payment proof, or other necessary evidence.
The service is intended for users who are at least 18 years old and have full legal capacity, or for authorized representatives of organizations. We do not intentionally provide paid diagnosis, wallet, report sharing, or external export services to minors, and we do not knowingly collect personal information from minors.
If a guardian believes a minor has used the service without consent, submitted personal information, purchased credits, or shared a report, contact us through Contact. After verification, we will reasonably assist with deleting or restricting the relevant information, unless legal, accounting, audit, or dispute-handling requirements require retention.
Depending on how you use the service, we may collect and process:
We use information to:
To provide diagnosis and operations, we may use third-party providers for AI answer collection, LLM processing, payment, email delivery, hosting, storage, monitoring, analytics, and security. We transmit only the information reasonably necessary for the corresponding service.
Third-party AI platform answers and cited sources may come from public web content, model-generated output, search results, or platform-specific retrieval systems. Accuracy, freshness, and availability depend on those platforms.
For report data source and interpretation boundaries, see Report Disclaimer and Data Sources.
Report shares may be protected by password, access token, expiry, and status controls. Anyone with a valid share link and password or access token may be able to view the corresponding report. You should manage share links, passwords, exports, and recipients carefully.
We may record access counts, access time, request metadata, and security events to operate report sharing, detect abuse, and support audit or dispute handling.
The current production deployment stores business data in server-side databases and report storage controlled by the service operator. The single-server version uses SQLite and performs regular backups for disaster recovery, pre-deployment protection, restore rehearsal, and operational continuity.
We use reasonable technical and organizational measures, including access controls, secret management, file permissions, service isolation, audit logs, and backup controls. However, no internet service can be guaranteed to be absolutely secure.
We retain information for as long as needed to provide the service, maintain reports and history, process orders and credits, support disputes, comply with accounting or legal obligations, and protect the service.
You may request deletion of account, brand, diagnosis, report, or share data. Certain order, recharge, refund, reversal, invoice, audit, and ledger records may be retained where necessary for accounting, tax, compliance, security, or dispute handling. See Data Deletion Policy for details.
To the extent permitted by applicable law, you may request access, copies, correction, supplementation, deletion, restriction of processing, withdrawal of consent, account closure, or an explanation of personal information processing rules. To protect account and report security, we may first need to verify your identity, account control, or request scope.
We will try to respond to or complete a verifiable request within 15 business days after receipt. Requests involving large volumes, backup restoration, order audit, report assets, third-party processors, or complex identity verification may take longer; in that case, we will explain the reason and expected handling method. If laws, regulations, or regulator requirements provide otherwise, those requirements apply.
If a request cannot be fulfilled because it affects others' rights, conflicts with legal retention duties, interferes with security audits, cannot be verified, or is clearly repetitive or excessive, we will explain the reason.
If you access the service from outside the server location or submit information about businesses in different markets, your information may be processed in locations where we or our service providers operate, subject to appropriate operational and security controls.
We may update this Privacy Policy as the product, payment channels, collection providers, storage architecture, or legal requirements change. Material updates may be announced through the website, in-app notice, email, or other reasonable methods.
For privacy questions, data processing requests, or deletion requests, contact us through Contact.