Privacy policy.
This policy explains what data LLMSEOLab collects, why we collect it, where it lives, and what you can do about it. It applies to llmseolab.com and the LLMSEOLab application (the “Service”), operated by INYRA LABS LLP (“we,” “us,” “LLMSEOLab”).
We're a B2B SaaS. We do not sell personal data. We do not run third-party advertising. The Service is the data you give us, the data we generate by querying public AI providers about your brand, and the analytics required to keep both running.
Who we are
INYRA LABS LLP is a Limited Liability Partnership registered in India, operating LLMSEOLab from Mumbai. Our contact address for privacy matters is support@llmseolab.com.
What we collect
We collect data in three layers, each with a different purpose.
We do not collect: payment-card data (handled directly by Stripe when billing is enabled), browsing history outside our app, location beyond country-level (derived from IP), or any data from your end users.
How we use it
- ·Operate the Service — run scheduled brand-visibility queries, parse provider answers, score mentions and citations, generate findings and reports.
- ·Authenticate accounts and enforce per-workspace, per-brand permissions.
- ·Communicate operational events you opted into (content reminders, run completion notifications, invite emails).
- ·Detect and mitigate abuse, security incidents, and platform misuse.
- ·Diagnose bugs and improve product quality, using aggregated and de-identified usage signals.
- ·Comply with our legal obligations (tax, audit, lawful requests).
Who we share data with (sub-processors)
We share the minimum data necessary with the third-party providers below. They are contractually bound to use your data only to deliver their service. We do not sell data and we do not share it with advertisers.
- SupabasePostgres database and authentication (US-incorporated; data physically in AWS ap-south-1 Mumbai)
- RailwayAPI and worker compute (AWS Asia Southeast, Singapore)
- VercelFrontend hosting and edge cache (global edge with primary region near us)
- CloudflareDNS, R2 object storage for raw provider responses, edge security (Cloudflare global edge)
- UpstashRedis queue and cache (AWS ap-south-1 Mumbai)
- ResendTransactional email delivery (EU region)
- OpenAI, Anthropic, Google (Gemini), OpenRouterLLM provider calls — your tracked prompts are sent to these to generate the answers we measure. Provider data-retention defaults apply unless we have a no-retention agreement.
- SerpAPI / DataForSEOGoogle AI Overview measurement
- YouTube Data API (Google)Owned-channel video and comment fetch when you connect your channel
- PageSpeed Insights (Google)LLM Readiness Core Web Vitals signals
- Brave SearchCitation-grounding fallback for some provider answers
- Stripe (when billing is enabled)Card payments and subscription management
Where your data is stored
The primary database and queue live in AWS ap-south-1 (Mumbai). Application compute runs in AWS Asia Southeast (Singapore). Raw provider responses are archived to Cloudflare R2 (Asia-Pacific region by default). Operational metadata and edge cache may transit additional regions via Vercel and Cloudflare's global networks. LLM provider calls leave our infrastructure to reach the relevant provider's API region.
How long we keep it
- ·Account + workspace data: for as long as your account is active. On account deletion, we remove identifiable data within 30 days. Backups may retain it up to a further 30 days before rotation.
- ·Operational data (mentions, citations, runs, reports): retained as long as your account is active, because historical trend analysis is the product. You can request deletion of specific data at any time.
- ·Application logs: 90 days.
- ·Email delivery records: 30 days for diagnostic purposes.
Your rights
Depending on where you live, applicable data-protection law (including India's DPDP Act 2023, the EU GDPR, and the California CCPA) gives you the right to:
- ·Access the personal data we hold about you.
- ·Correct inaccurate personal data.
- ·Delete your personal data, subject to limited legal exceptions.
- ·Export your data in a portable format.
- ·Object to or restrict certain processing.
- ·Withdraw consent where processing is consent-based.
To exercise any of these, email support@llmseolab.com. We'll respond within 30 days. We may need to verify your identity before acting.
Security
All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted at the storage layer (Supabase, R2, Upstash). Access to production systems is limited to engineering staff under role-based access, with audit logs. We use Postgres Row-Level Security to limit cross-tenant exposure even at the database layer. We will notify affected customers without undue delay if we become aware of a confirmed personal-data breach.
Cookies and similar tech
We use strictly-necessary cookies for authentication and session state. We use anonymised, first-party analytics to measure aggregate usage (e.g. which screens are used) without identifying individuals. We do not use third-party advertising cookies or cross-site trackers. You can clear cookies in your browser; doing so will log you out.
International transfers
As noted above, your data may be processed outside India by our sub-processors. Where we transfer EU/UK personal data internationally, we rely on the European Commission's Standard Contractual Clauses or other adequacy mechanisms with the sub-processor.
Children
The Service is a business tool. It is not directed at, and we do not knowingly collect data from, anyone under 18.
Changes to this policy
We may update this policy as the product evolves. The “effective” date above will change when we do. For material changes, we'll notify account owners by email at least 14 days before they take effect.
How to reach us
Privacy questions, data-subject requests, or anything else: support@llmseolab.com.