1. Scope
This Privacy Policy applies to your access to maxfound.ai and its subdomains, and to all products provided through Maxfound AI (including but not limited to AI visibility monitoring, AEO rewriting, AutoMedia content distribution, AI support, Webhook integrations, and the API).
This policy is designed to be compatible with both the EU GDPR and applicable data-protection law. Where you are located in a jurisdiction with specific privacy regulations (e.g. GDPR or CCPA), those regulations apply to your personal data as described below.
2. What Data We Collect
- Account information: email, phone number, display name, avatar URL, and third-party OAuth profile (e.g. GitHub, Google, Feishu, and others).
- Brand data: brand name, category, website, competitor list, monitored keywords, and Schema markup.
- Scan data: your brand's visibility in AI answers, mention positions, sentiment, and citation sources.
- Payment data: if you choose to pay online, we process only the corresponding payment reference (transaction ID). We do not store card numbers · PCI-isolated.
- Usage data: login times, IP address, user agent, and activity logs (audit_log).
- Cookies: a session cookie (httpOnly, 30 days) plus theme/language preference (localStorage).
3. How We Use Data
- Delivering core features such as AI visibility monitoring and report generation.
- Payments, billing, invoicing, and renewal reminders.
- System security: abuse prevention, rate limiting, and anomalous-login alerts.
- Customer success: product improvement, NPS surveys, and weekly digests (you can unsubscribe).
- Compliance auditing: records retained for 1 year (5 years on Enterprise).
- Aggregate analysis: we may use de-identified, aggregated data for industry reports (never exposing any individual customer).
4. Third-Party Sharing · Full Subprocessor Disclosure
All third-party processors have signed a Data Processing Agreement (DPA); all transferred data is de-identified with sensitive personal information removed.
| Provider | Purpose | Data scope | Location |
|---|---|---|---|
| Neon Postgres | Primary DB | All structured data | us-east-1 |
| Vercel | Hosting + edge | HTTP traffic + logs | iad1 · global |
| Cloudflare | CDN + DDoS | HTTP traffic | Global |
| Payment processor | Online payment processing if you choose it (optional) | Payment reference (no card numbers) | Per processor |
| Resend | Email delivery | Recipient email + content | us-east |
| Feishu | Feishu integration (optional) | Feishu ID after your authorization | China |
| Sentry | Error monitoring | Stack traces · no PII | us-east |
| LLM providers | AI queries | Prompt + brand name (no PII) | Global |
All subprocessors have signed a DPA. To request the full DPA, email legal@maxfound.ai.
5. Cross-Border Data Transfers
This platform handles cross-border data transfers in accordance with applicable data-protection law, including the following safeguards:
- Storage at rest: structured business data is stored on Neon servers (us-east-1); all data is de-identified with sensitive personal information removed.
- LLM transfers: when a cross-border scenario triggers a third-party AI model, we transmit only de-identified prompts and publicly available brand information, never your phone number, email, or account information.
- Legal basis: transfers are limited to what is necessary to perform our service contract with you, and do not involve important data or large-scale personal-information export.
- Your control: Maxfound AI selects AI models based on your brand's business type. To adjust or restrict which models are called, change your brand's business-type setting or contact legal@maxfound.ai for assistance.
- Recipient obligations: all recipients have signed a Data Processing Agreement (DPA) committing not to use the data for model training and not to redistribute it.
6. LLM Data-Use Policy
- The prompts we send to LLM providers contain no PII — your name, email, and phone never appear in a prompt.
- All LLM providers have signed a DPA committing not to train models on your data, not to cache it, and not to retain your queries (pure API-call mode, unlike consumer AI products).
- You can enable "opt out of training" under Data & Privacy in /dashboard/settings (on by default).
- AI-generated content on the platform is for reference only and does not constitute business advice or any guarantee of results.
7. Your Rights (GDPR + CCPA)
- Access: GET
/api/me+/api/audit-log - Rectification: edit directly in /dashboard/settings
- Portability: POST
/api/me/data-export· full ZIP delivered by email within 24h - Erasure: DELETE
/api/me/data-purge· reversible within a 30-day grace period - Withdraw consent: decline cookies at any time — core functionality is unaffected
- Complaints: if you disagree with how your data is handled, email legal@maxfound.ai · response within 72 business hours
8. Data Retention
- Primary account data: for the life of the account + a 30-day grace period after deletion.
- Scan history: Free 30 days / Starter 90 days / Growth 365 days / Enterprise unlimited.
- Audit logs: 1 year (5 years on Enterprise).
- Payment records: retained as required by applicable accounting and tax law.
- Closed accounts: backups purged within 30 days of hard deletion.
9. Security Measures
10. Protection of Minors
12. Changes to This Policy
13. Governing Law and Contact
Disputes arising from your use of this service shall first be resolved through good-faith negotiation. The governing law and dispute-resolution venue are set out in our Terms of Service.
- Privacy / data rights:legal@maxfound.ai
- Security vulnerabilities:security@maxfound.ai
- Customer support:hi@maxfound.ai