Privacy Policy

Last updated: 14 July 2026

Who we are

GEOrca (“we”, “us”) operates georca.com, a tool for tracking and improving brand visibility in AI search engines. This policy explains what we collect and why. Questions: [email protected].

What we collect

  • Account data — your email and a hashed password. Passwords are never stored in plaintext.
  • Project data — the brands, domains, prompts, and pages you choose to track.
  • Billing data — handled by Stripe; we store only your plan and Stripe customer/subscription identifiers, never card numbers.
  • Usage & analytics — we use Google Analytics and our own cookieless page analytics to understand product usage. IP addresses are not stored raw; visitor identifiers are daily-salted hashes.
  • Diagnostics — error reports (via Sentry when enabled) to keep the service reliable.

How we use it

To provide and operate the service, process payments, communicate with you (e.g. password resets, team invites, service notices), prevent abuse, and improve the product. We do not sell your personal data.

Third parties

We share data only with providers that help us run the service: Stripe (payments), Resend (transactional email), Google Analytics (usage), and the AI/search vendors we query on your behalf. Each processes data under its own terms.

Retention & security

We keep account and project data for as long as your account is active. Analytics events are retention-bounded. Data is encrypted in transit; secrets are stored server-side only.

Your rights

You can access, correct, export, or delete your personal data by emailing [email protected]. If you are in the EEA/UK, you have rights under the GDPR, including the right to lodge a complaint with your supervisory authority.

Changes

We may update this policy; material changes will be reflected here with a new date.