What we collect
We collect only what we need to score your visibility and run your account. Four kinds of data:
- Public website contentThe pages we crawl from your site to understand your category, products, and positioning.
- Question setsThe buyer questions we generate and run, plus any you supply or refine.
- Engine responsesThe answers we sample from AI engines so we can measure presence, citation, and share of voice.
- Account and billing basicsYour name, work email, organization, plan, and billing details needed to run your account.
How it is stored
Your data lives in a Postgres database managed by Supabase. Every tenant-scoped table is protected by row-level security, so queries can only return rows that belong to your account. Authentication and session management run through Clerk. Data in transit is encrypted over HTTPS, and our providers encrypt data at rest.
Tenant isolation
Primacy Score is multi-tenant, and isolation is enforced in the database rather than only in application code. Each account is a tenant, and row-level security policies tie every read and write to the authenticated account. One customer cannot see, list, or query another customer’s crawled content, question sets, engine responses, or scores.
Payment security
Billing is handled by Stripe. Card details are entered directly with Stripe and we never see or store full card numbers on our own systems. We keep only the billing basics needed to manage your account and purchases, such as plan, status, and the reference Stripe gives us.
Sub-processors
We rely on a small set of established providers to run the product. We share with each only the data needed for its job:
- SupabaseManaged Postgres database and storage.
- ClerkAuthentication and account management.
- StripePayment processing and billing.
- Anthropic, OpenAI, Google, Perplexity, Microsoft, xAIAI engines we sample to measure visibility.
- FirecrawlCrawling public website content.
- ResendTransactional and account email.
- VercelApplication hosting and delivery.
- PostHogProduct analytics for this website.
Retention & deletion
We keep your data for as long as your account is active so that trend lines and historical scores stay intact. You can request deletion of your account data at any time, and we will remove it from our systems and ask our sub-processors to do the same, subject to records we are legally required to retain such as billing history.
Compliance posture
We are not claiming certifications we do not hold. Our practices are designed toward the principles behind SOC 2, ISO 27001, and GDPR, and formal certification is on our roadmap. If your procurement process needs specific documentation, get in touch and we will tell you honestly where we stand today.
Contact
Security questions, disclosures, or data requests go to security@primacyscore.com. For anything else, reach us at hello@primacyscore.com.