Back to webblitz.ai

Privacy Policy

Last updated: August 18, 2026

1. Data Controller

The data controller responsible for webblitz.ai is:

Raw Response Labs UG (haftungsbeschränkt)

Urbanstr. 71, 10967 Berlin, Germany

HRB 284973 B, Amtsgericht Charlottenburg

Email: hello@webblitz.ai

2. How webblitz.ai Works — Outside-In

webblitz.ai measures your brand's visibility in AI answers from the outside: we analyze publicly available AI responses and publicly available web pages. No feature requires access to your internal systems — we do not connect to your CRM, your shop backend, or your web analytics. Optional connections (currently Slack and Google Search Console) are granted by you, individually, per workspace, read-only, and can be disconnected at any time. Connecting Search Console lets us read your own performance data for your own pages; nothing about it is required to use webblitz.ai.

3. What Data We Process

  • Account data: Email address, display name, and optional profile picture, provided during registration via Firebase Authentication. If you invite collaborators, we process the email addresses you invite.
  • Public web content: Publicly available content from URLs you submit for analysis (page text, meta data, headings). We do not access private or authenticated pages.
  • AI answer data: Responses from AI platforms to tracking prompts we run about your brand, including full answer texts, citations, sentiment, and competitor mentions. Public AI answers and web pages can contain names of people who are publicly mentioned there (e.g. founders or authors); we use this data solely for visibility measurement and do not enrich it. If you are one of these individuals, see our dedicated notice for individuals in analyzed content.
  • Content you provide: Chat messages to the agent (web, email replies, connected Slack), uploaded documents and images and the text extracted from them, brand assets, customer cases, and author profiles.
  • Generated content: Article drafts, briefs, and recommendations created for your workspace.
  • Usage and technical data: Feature usage counts for plan limits, email delivery logs, and IP addresses used solely as rate-limiting keys (deleted after 48 hours).
  • Billing references: Customer and subscription identifiers from our payment provider. We never receive or store card or bank details.

4. Legal Basis (GDPR Art. 6)

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the webblitz.ai service.
  • Legitimate interest (Art. 6(1)(f)): Security measures, abuse prevention, and error tracking.
  • Consent (Art. 6(1)(a)): Product analytics (PostHog — loads only after you accept the cookie banner) and optional email reports. You can withdraw consent at any time.

5. Recipients of Data

We use the following processors and recipients (last reviewed 2026-08-20). Where providers process data outside the EU, transfers are safeguarded by EU Standard Contractual Clauses and, where certified, the EU-US Data Privacy Framework.

Subprocessors

Google Cloud Platform (Cloud Run, Cloud SQL, Cloud Storage) · Google Ireland Ltd.

Hosting, database, file storage. Data: All application data. Region: EU — europe-west1 (Belgium). Transfer: Cloud Data Processing Addendum; SCCs + EU-US Data Privacy Framework. DPA

Firebase Authentication · Google

Login and identity (email/password, Google sign-in). Data: Email address, name, authentication identity. Region: USA (per Google: run only from US data centers). Transfer: Firebase Data Processing and Security Terms; SCCs + DPF. DPA

Google Gemini API (paid tier) · Google

AI analysis and generation (answer analysis, drafts, embeddings, chat). Data: Prompts, AI answers, scraped public website content, user inputs and uploads. Region: Global endpoints — no region commitment. Transfer: Google processor terms for paid Gemini API; SCCs + DPF. DPA

OpenAI API · OpenAI, L.L.C.

Visibility measurement on ChatGPT. Data: Tracking prompt text only (may contain publicly known names). Region: USA. Transfer: SCCs (modules 2+3). DPA

Anthropic API · Anthropic, PBC

Visibility measurement on Claude. Data: Tracking prompt text only. Region: USA. Transfer: SCCs; DPA incorporated into Commercial Terms. DPA

Perplexity API · Perplexity AI, Inc.

Visibility measurement on Perplexity. Data: Tracking prompt text only. Region: USA. Transfer: SCCs (modules 2+3). DPA

DataForSEO · DataForSEO OÜ (Estonia)

Google AI Overview measurement, keyword data. Data: Prompt texts as search keywords, keyword lists. Region: EU seat (Estonia); infrastructure EU/USA. Transfer: SCCs / adequacy; DPA incorporated into their ToS. DPA

Resend · Plus Five Five, Inc.

Email delivery and inbound email processing. Data: Recipient addresses, email content; account metadata stored in the US regardless of sending region. Region: USA (EU sending region optional). Transfer: SCCs + EU-US Data Privacy Framework (certified). DPA

Sentry · Functional Software, Inc.

Error tracking (errors only — no session replays, no performance tracing). Data: Exceptions, request context. Region: US region today; migration to the EU org (de.sentry.io) planned. Transfer: SCCs + EU-US DPF. DPA

PostHog · PostHog, Inc.

Product analytics — loads only after cookie consent. Data: Usage events, email, name (after consent). Region: EU Cloud (eu.posthog.com, AWS Frankfurt). Transfer: SCCs where applicable. DPA

Opt-in channels (connected by you)

Google Search Console (customer-connected)

Read-only: which pages Google serves, and whether a finished draft went live. Data: Page URLs, impressions, clicks, average position of the customer's own site.

Slack

Notifications and two-way chat into YOUR Slack workspace — only if you connect it. Data: Metrics, suggestions, message texts of the connected workspace; bot token stored AES-256-GCM-encrypted, workspace-bound.

Independent controllers

Polar (checkout & billing) · Polar Software Inc.

Merchant of record for the checkout — independent controller for payment data; card data stays with Polar/Stripe, never with us

Recipients without personal data

Google Knowledge Graph API

Brand entity check. Data: Brand name only.

Unsplash

Image search for article drafts. Data: Search terms only.

6. Cookies & Analytics

  • We use strictly necessary cookies for login sessions and language preference.
  • We use one optional product-analytics tool, PostHog, hosted in the EU. It loads only after you accept the cookie banner; declining keeps the site fully functional. After acceptance, PostHog receives usage events and, for logged-in users, email and name.
  • We do not use advertising or ad-tracking scripts.
  • We do not sell, rent, or share your data with advertisers.
  • We do not use your data to train AI models.

7. Data Storage & Security

Application and database run in the Google Cloud region europe-west1 (Belgium): PostgreSQL on Cloud SQL with encryption at rest and TLS in transit, plus a non-public file store served only through access-checked application routes. Database backups are retained for 7 days — deleted data leaves backups after at most 7 days.

Credentials for channels you connect (e.g. Slack) are additionally encrypted at the application layer with AES-256-GCM and cryptographically bound to your workspace. Error tracking runs without session replays. Note: AI processing via the Gemini API uses Google's global API endpoints without a region commitment — see section 5 for the applicable processor terms.

8. Data Retention

  • AI answer full texts and source snippets: 12 months, then deleted automatically.
  • Chats and agent memories: 24 months or until account deletion, whichever comes first.
  • Search Console performance history (only if you connect it): 12 months, the same window as the AI answers it is read against.
  • IP addresses (rate limiting): 48 hours.
  • Application logs and email delivery log: 90 days.
  • Uploads: Deleted with your workspace.
  • Guest sessions: Deleted after 48 hours (7 days if you saved your email to keep your report), including all analysis data.

Deleting a website from your dashboard permanently removes all associated data, including uploaded files. Deleting your account removes all your workspaces, your files, and your login identity. One narrow exception, kept under legitimate interest (Art. 6(1)(f), abuse prevention): a record that a domain has already used its free trial — the domain is stored as a hash, not in plaintext.

9. Your Rights (GDPR)

Under the GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Lodge a complaint with a supervisory authority

You can exercise erasure and portability yourself: Settings → Profile lets you export your data as JSON and delete your account, including all workspaces, files, and your login identity. For everything else, contact hello@webblitz.ai.

10. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date. For significant changes, we will notify you via email.

© 2026 Raw Response Labs UG (haftungsbeschränkt). All rights reserved.
Privacy Policy — webblitz.ai | webblitz.ai