Clairen Haus AEO Checker
Free scan

Clairen Haus AEO Checker

Privacy policy

Launch draft. Marked details need approval before public launch. This page has not been legally reviewed.

Who runs this service

Clairen Haus operates the AEO Checker. Contact: [CONTACT EMAIL REQUIRED]. Business mailing address: [BUSINESS MAILING ADDRESS REQUIRED]. These pages are launch drafts, have not been legally reviewed, and must be completed before public launch.

Website scans and raw HTML

When you enter a website, we request its public pages and supporting crawler information, then process raw HTML to calculate diagnostic scores and evidence. We do not execute the website’s JavaScript. Do not submit private pages, credentials, sensitive personal information, or content you are not allowed to scan. Scan results can include public page URLs, titles, text excerpts and structured data. Raw HTML is processed by the scanner; reports store the resulting scores, findings and evidence rather than a full copy of each page’s HTML.

Reports and private links

Reports are stored in Supabase in a hosted deployment. Signed-in reports are linked to your account. Anonymous reports have private links; anyone who receives a working private link may be able to open the free report. Keep those links private. Paid reports and PDFs require the appropriate account entitlement. Local development may use a file store; that fallback is disabled in production.

Accounts, email capture and sign-in

Supabase stores your account email and profile. We use magic-link sign-in, so the application does not ask you to create a password. Supabase processes authentication messages and records session IP addresses. If you unlock a report by email, we store the email address, report reference and delivery status. Postmark sends report email when configured; custom authentication email may also use a configured email provider. Email capture is for report access and delivery; this notice does not establish consent to unrelated marketing.

Payments

Stripe processes checkout and payment details. The AEO Checker stores payment references, product, amount, currency, status and report entitlements linked to your account. The application does not collect or store your card number or security code. Stripe maintains its own payment records under its policies.

AI providers and visibility history

If you run AI visibility checks, your buyer questions and the request parameters required by the selected engine are sent to the configured provider: OpenAI or an OpenAI-compatible provider, Google Gemini, Perplexity, or DataForSEO. DataForSEO can provide Google AI Overviews and other engines. Availability depends on configuration. We store answers, cited sources, detection results, competitors, question history and run comparisons. Website HTML is not used as instructions to these providers. Each provider processes requests under its own terms and privacy rules; provider retention and training settings need confirmation before launch: [PROVIDER DATA-PROCESSING SETTINGS REQUIRED].

Usage, failures and IP handling

Provider usage logs record calls, estimated or reported cost, failures and account references for cost reporting. Failed-scan monitoring records only website host, error type and time, not full URL paths, query strings, error text, visitor identity or visitor IP. If the submitted website itself is an IP address, its host value can be an IP address. Application quotas and rate limits use keyed hashes derived from IP addresses rather than storing raw visitor IPs. Supabase Auth, hosting and other providers can process IP addresses in their own infrastructure and logs: [HOSTING AND PROVIDER LOG RETENTION REQUIRED].

Retention

Reports are kept by default so private links continue to work. Email captures are kept until deletion is requested. Accounts remain until deletion. Payment and entitlement records are kept for accounting. Visibility questions, answers, competitors and runs are kept for history; provider usage records are kept for cost reporting. Stripe event identifiers are kept to prevent repeated processing. The retention tool is designed to clear anonymous-quota hashes after 30 days, delete failed-scan logs after 90 days and delete rate-limit counters after two days. These cleanups depend on a scheduled job or operator running the tool; deployment scheduling is not yet verified. Anonymous, never-unlocked free reports are deleted only if a separate retention rule is deliberately enabled. No such report-deletion period is promised here. Final accounting, usage and backup periods require approval: [RETENTION PERIODS AND SCHEDULE REQUIRED].

Deletion and your rights

Contact us to request access, correction, deletion or a copy of your information, or to raise a privacy concern. Rights vary with the law that applies to you. We may need to verify your request and retain records required by law. Account deletion removes the account profile and related visibility data and entitlements; scan and payment rows can remain with the account reference cleared. Email captures need separate deletion by email. Website information that identifies you may remain in retained reports, so tell us which report or site your request concerns. Deleted data may remain in backups until those backups expire. [BACKUP RETENTION AND REQUEST PROCESS REQUIRED].

Service providers and changes

Supabase, Railway, Stripe, email services and configured AI providers process information needed to operate the service. The app uses public Supabase browser configuration, authentication sessions and private report or claim links; never share sign-in links. [COOKIE, INTERNATIONAL TRANSFER AND APPLICABLE RIGHTS REVIEW REQUIRED]. We will update this notice when practices change and show the effective date after approval: [EFFECTIVE DATE REQUIRED].