Privacy Policy
Last updated: September 4, 2026 · Version 1.6 · Data Controller: Promodo Inc., Las Vegas, Nevada, United States
What changed in version 1.6: our contact addresses moved to our own domain — support@gelios-monitor.ai for privacy and support requests, legal@gelios-monitor.ai for legal notices and data-subject requests. Version 1.5 (September 4, 2026) moved transactional email to Resend; version 1.4 added Google Analytics 4; version 1.3 added Microsoft Clarity.
SUMMARY: We collect only what we need to provide the GELIOS service. We do not sell your personal data to third parties. We do not use your data for targeted advertising. For questions or to exercise your rights, contact us at support@gelios-monitor.ai or legal@gelios-monitor.ai.
1. Introduction and Scope
GELIOS ("Service"), available at gelios-monitor.ai, is an AI brand visibility monitoring platform owned and operated by Promodo Inc. ("Promodo," "we," "us," or "our"), a corporation incorporated in the State of Nevada, United States.
This Privacy Policy ("Policy") explains how we collect, use, store, share, and protect your personal data when you use the Service. It applies to all users of the Service, including Free Plan and Paid Plan users.
We are committed to protecting your privacy in compliance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, applicable U.S. state privacy laws (including the California Consumer Privacy Act / CPRA), the Law of Ukraine "On Personal Data Protection" (which is relevant because part of the Promodo group operates from Ukraine — see Section 10), and other relevant legislation.
This Policy is incorporated by reference into our Terms of Service. By using the Service, you confirm that you have read and understood this Policy.
2. Data Controller
The data controller responsible for your personal data is:
Promodo Inc.
Registered address: Suite 100, 6920 S. Cimarron Rd., Las Vegas, NV 89113, United States
State of incorporation: Nevada, United States
Privacy inquiries: support@gelios-monitor.ai
Legal notices: legal@gelios-monitor.ai
Website: gelios-monitor.ai
For users in the European Union or United Kingdom, Promodo Inc. acts as the data controller within the meaning of the GDPR and UK GDPR respectively. Where required by applicable law, we will appoint a local representative. For EU/UK data protection inquiries, contact legal@gelios-monitor.ai.
3. Information We Collect
3.1 Information You Provide Directly
- Account information: Your name, email address, and password when you register, or your name and email address if you sign in with Google
- Project configuration: Domains, brand names, competitor names, regions, and custom queries you enter into the Service
- Subscription and billing information: Your billing plan selection. Payment card details are collected and processed directly by Stripe — we never receive or store your full card number or CVV
- Support communications: Messages, inquiries, and attachments you send to our support team
- Contact enquiries: Your name, email address and, optionally, your phone number when you submit the "Contact our team" form
- Feedback and survey responses: Information you voluntarily provide when responding to surveys or submitting product feedback
3.2 Information Collected Automatically
- Usage data: Features accessed, queries submitted, projects created, audit runs initiated, and interaction patterns with the dashboard
- Device and browser data: IP address, browser type and version, operating system, device type, screen resolution, and referring URLs
- Log data: Access times, pages viewed, API calls made, error logs, and session duration
- Cookies and similar technologies: Session and preference cookies (see Section 9 for details)
3.3 Information from Third-Party Sources
- Google Sign-In: If you choose to sign in with Google, we receive your name, email address, and profile image from your Google account. If you register with an email address and password instead, no third party is involved in your authentication — your password is stored by us only as a salted hash
- Payment processor (Stripe): Transaction status, subscription status, billing country, and payment amount. We do not receive your full card number or billing address beyond country
- Ahrefs Brand Radar: Aggregated AI search query volume data and visibility trend metrics associated with domains you monitor. This data relates to domains, not to you personally
- Google (Gemini) and OpenAI (ChatGPT): AI-generated responses to queries about the domains you monitor. These interactions involve your configured queries, not your personal identity
- DataForSEO: Supplementary search volume data and Google AI Overview results for domains under monitoring
3.4 What We Do Not Collect
We do not collect:
- Financial data beyond transaction status — full payment card details are handled exclusively by Stripe
- Sensitive personal data (health, biometric, religious, or political information)
- Personal data about individuals whose brands or domains you monitor — we process domain and brand names, not personal profiles
- Data from children under 18 (see Section 12)
4. How We Use Your Information
We use your personal data only for the following purposes:
- Service delivery: To create and manage your account, process AI visibility audit requests, generate brand monitoring reports, and deliver dashboard results
- Billing and subscriptions: To manage your subscription, process payments through Stripe, send receipts and invoices, and handle billing inquiries
- Product improvement: To analyze usage patterns, identify technical issues, improve Service features, and develop new capabilities — using anonymized and aggregated data where possible
- Communications: To send essential service notifications, security alerts, subscription renewal reminders, and material policy updates
- Sales follow-up: To contact you about the Service where you have submitted an enquiry, or where your account has remained inactive after registration
- Fraud prevention and security: To detect and prevent fraudulent activity, unauthorized access, billing abuse, and violations of our Terms of Service
- Legal compliance: To comply with applicable laws, regulations, tax obligations, and lawful requests from government authorities
- Dispute resolution: To investigate complaints, resolve disputes, and defend against legal claims
We do NOT use your personal data for: targeted advertising · profiling for marketing purposes · selling data to third parties · training AI models on your Content or query configurations.
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we process your personal data on the following legal grounds under GDPR Article 6:
Contract Performance (Article 6(1)(b))
Processing necessary to provide the Service you subscribed to, including account management, running AI visibility audits, generating reports, and processing subscription billing.
Legitimate Interest (Article 6(1)(f))
Processing for Service improvement, sales follow-up, fraud prevention, security monitoring, and abuse detection — where our interests do not override your fundamental rights and freedoms. You may object to processing on this basis (see Section 8).
Legal Obligation (Article 6(1)(c))
Processing required to comply with tax, accounting, anti-money laundering, or other legal requirements applicable to Promodo Inc.
Consent (Article 6(1)(a))
Where required — such as for optional marketing communications or non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Data Sharing and Third-Party Providers
We share your personal data with the following categories of third-party service providers, strictly for the purposes described below. We do not sell your personal data. We do not share your data with any other third parties unless required by law or with your explicit consent.
A current, itemised list of named sub-processors — including their purpose and jurisdiction — is available at gelios-monitor.ai/legal/subprocessors.
6.1 Payment Processing
Stripe, Inc. processes all subscription payments and handles sales tax calculation and invoicing. Stripe receives your email address, name, billing country, and payment card details. All transactions are processed in accordance with Stripe's Privacy Policy (stripe.com/privacy). Stripe is a PCI-DSS Level 1 certified processor.
6.2 Authentication
We manage user accounts and authentication ourselves. Passwords are stored only as salted hashes and are never shared with any third party. If you choose to sign in with Google instead of a password, Google LLC processes that sign-in and provides us with your name, email address, and profile image; Google's privacy practices are governed by Google's Privacy Policy (policies.google.com/privacy).
6.3 AI Platform Providers
To execute brand visibility audits, we submit your configured queries to AI platforms on your behalf:
- Google LLC (Gemini): Receives the query text you configure in your Project. Google's privacy practices are governed by Google's Privacy Policy (policies.google.com/privacy)
- OpenAI, LLC (ChatGPT): Receives the query text you configure in your Project. OpenAI's privacy practices are governed by OpenAI's Privacy Policy (openai.com/privacy)
We submit domain names and query text — not your personal identity — to these providers. Queries are processed through API integrations subject to each provider's API terms.
6.4 Data and Analytics Providers
Ahrefs Pte. Ltd. provides Brand Radar data powering six-month AI search visibility trends. We receive aggregated, domain-level visibility metrics from Ahrefs. See Ahrefs' Privacy Policy at ahrefs.com/privacy.
DataForSEO OÜ provides supplementary search data and Google AI Overview results for monitored domains. See DataForSEO's Privacy Policy at dataforseo.com/privacy-policy.
Microsoft Corporation provides Microsoft Clarity, the product-analytics tool we use to understand how our website and the Service are actually used — which elements people interact with, where they hesitate, and where they abandon a task. Clarity records individual interaction sessions and builds heatmaps from them, and those recordings are transmitted to and stored by Microsoft. Microsoft states that it acts as an independent controller of the data collected through Clarity. See Microsoft's Privacy Statement at privacy.microsoft.com and the Clarity terms at clarity.microsoft.com/terms.
Google LLC provides Google Analytics 4, which we use on our marketing site at gelios-monitor.ai to count visits and understand where they come from and how the site is used — the pages viewed, which buttons and links are clicked and whether a form was sent (never what was typed into it), the referring site or campaign, the browser and device type, and an approximate location derived from the IP address (Google Analytics does not store the IP address itself). It recognises a returning browser by the cookies described in Section 9. The data is transmitted to and processed by Google in the United States under Google's data processing terms. We use it for statistics only: we do not use Google Analytics data for advertising and do not link it to Google Ads. See Google's Privacy Policy at policies.google.com/privacy and the description of how Google uses data from sites that use its services at policies.google.com/technologies/partner-sites.
6.5 Infrastructure Providers
The Service, its database, and the reports it generates run on cloud infrastructure located in the United States, operated on our behalf by a cloud infrastructure provider that holds a current certification under the EU–US Data Privacy Framework. We identify that provider on request — write to legal@gelios-monitor.ai. Transactional email — account notifications, security alerts and billing messages — is sent from our own domain (gelios-monitor.ai) through Resend, an email delivery service operated by Resend, Inc. (United States). Resend processes the recipient address, subject and message content of those emails and keeps delivery logs for a limited period. See Resend's Privacy Policy at resend.com/legal/privacy-policy.
Technical administration of the Service — deployment, monitoring, incident response and database maintenance — is performed by Promodo personnel, part of whom are located in Ukraine. Those personnel access the Service remotely; the data itself is not stored in Ukraine. Access is limited to the individuals who need it and is governed by the safeguards described in Section 10.
6.6 Sales and Support Communications
Enquiries you submit through the "Contact our team" form are transmitted to Promodo's internal lead intake service and stored in Pipedrive OÜ, the customer relationship management system used by the Promodo sales team. Where a guest account has remained inactive after registration, the account email address and the monitored domain are sent to an internal Promodo team channel on Telegram so that a sales representative can follow up. No other personal data is transmitted to Telegram.
6.7 Legal Disclosures
We may disclose your personal data to law enforcement, government authorities, or courts when required by applicable law, valid legal process, or to protect the rights, safety, or property of Promodo Inc., our users, or the public.
6.8 Business Transfers
If Promodo Inc. is involved in a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service before your data is transferred and becomes subject to a different privacy policy.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Policy:
- Account data (name, email, preferences): Retained while your account is active and for up to 30 days after account deletion
- Project data (domain configurations, query lists, audit results, visibility reports): Retained while your account is active. Deleted within 30 days of account deletion or project removal
- Transaction and billing records: Retained for up to 7 years to comply with U.S. tax, accounting, and financial record-keeping obligations
- Usage and access logs: Retained for up to 12 months for security monitoring, debugging, and service improvement
- Support and enquiry communications: Retained for up to 24 months after the last interaction
- Fraud prevention records: Retained for up to 5 years where necessary to prevent repeated abuse
After the applicable retention period, data is permanently deleted or anonymized so that it can no longer be associated with you. We may retain data for longer periods where required by applicable law or for active legal proceedings.
8. Your Rights
8.1 Rights Under GDPR (EU/UK Users)
If you are located in the EEA or United Kingdom, you have the following rights:
- Right of access (Article 15): Request a copy of the personal data we hold about you
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data
- Right to erasure (Article 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
- Right to restriction (Article 18): Request that we limit how we process your data in certain circumstances
- Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format
- Right to object (Article 21): Object to processing based on legitimate interest or for direct marketing purposes
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing
- Right not to be subject to automated decision-making: We do not make solely automated decisions with legal or similarly significant effects on you
To exercise any of these rights, contact us at support@gelios-monitor.ai. We will respond within 30 days. We may ask you to verify your identity before processing your request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority. For EU users: your national Data Protection Authority. For UK users: the Information Commissioner's Office (ico.org.uk).
8.2 Rights Under U.S. State Privacy Laws (California and Other States)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA):
- Right to Know: Request information about the categories and specific pieces of personal data we have collected about you, the sources, purposes, and third parties with whom we share it
- Right to Delete: Request deletion of personal data we have collected from you, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal data
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal data for cross-context behavioral advertising. No opt-out is required, but you may submit a request to confirm
- Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by CPRA
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights
To exercise California privacy rights, contact us at support@gelios-monitor.ai or legal@gelios-monitor.ai. We will respond within 45 days as required by CCPA. Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states with applicable privacy laws may have similar rights; contact us to exercise them.
DO NOT SELL OR SHARE MY PERSONAL INFORMATION: Promodo Inc. does not sell, rent, or share your personal data with third parties for their own marketing or advertising purposes. This applies to all users, including California residents under CCPA/CPRA.
9. Cookies and Tracking Technologies
GELIOS uses a limited and purposeful set of cookies and similar technologies:
Essential Cookies
Required for authentication, session management, security, and core Service functionality. These cannot be disabled without impairing the Service. They are set by Promodo Inc. only.
Preference Cookies
Store your settings and preferences such as language, display options, and dashboard configuration. These can be disabled without affecting core functionality.
Analytics Cookies
Set by Google Analytics 4 on our marketing site at gelios-monitor.ai only — not inside the Service after you sign in. The _ga cookie and one _ga_<id> cookie distinguish a returning browser from a new one so that visits and traffic sources can be counted; they hold a random identifier, not your name or email address, and expire after two years. They help us understand how the site is used so we can improve it. Our legal basis is our legitimate interest (Article 6(1)(f) GDPR); you may object at any time — see Section 8. You can block or delete these cookies in your browser settings or install Google's opt-out add-on at tools.google.com/dlpage/gaoptout; the site works without them.
Product Analytics Without Cookies
We use Microsoft Clarity to understand how our website and the Service are used. Clarity is configured to set no cookies at all — it stores nothing in your browser and cannot recognise you on any other website.
What it does record is the behaviour of an individual visit — pointer movement, clicks, scrolling and the pages viewed — and not only aggregated statistics. A recording may also include what you enter into forms on the site, such as the website address and the email address in our sign-up form. Those recordings are transmitted to and stored by Microsoft.
Our legal basis is our legitimate interest in improving the Service (Article 6(1)(f) GDPR). You may object at any time — see Section 8.
We do not use advertising, tracking, or cross-site behavioral profiling cookies. Third-party cookies may be set by Stripe during checkout and by Google if you choose to sign in with Google, subject to their respective cookie policies. You can manage cookie preferences through your browser settings. Disabling essential cookies will impair your ability to use the Service.
10. International Data Transfers
Promodo Inc. is incorporated in Nevada, United States. The production infrastructure on which the Service runs — application, database, and generated reports — is located in the United States. Personal data you provide to the Service is therefore stored at rest in the United States, in the same jurisdiction as the Data Controller. Until August 2026 that infrastructure was located in Ukraine; the move is reflected throughout this Section.
Processing takes place in the following jurisdictions:
| Where | What is processed there |
|---|---|
| United States | Storage of all Service data (application, database, generated reports); AI checks (Google Gemini, OpenAI), Google Sign-In, transactional email (Resend), visit statistics for the marketing site (Google Analytics), payments (Stripe) |
| Ukraine | Receipt and routing of enquiries submitted through the "Contact our team" form; technical administration of the Service by Promodo personnel, who access the Service remotely |
| Estonia (EEA) | Supplementary search data (DataForSEO), CRM records of sales enquiries (Pipedrive) |
| Singapore | Domain-level visibility metrics (Ahrefs) — no personal data |
| United Arab Emirates | Internal notification to the sales team about inactive guest accounts (Telegram) |
A per-provider breakdown is published at gelios-monitor.ai/legal/subprocessors.
When we transfer personal data from the EEA or the United Kingdom to a country that has not been recognised as providing an adequate level of data protection, we put appropriate safeguards in place, including:
- The EU–US Data Privacy Framework for transfers to United States providers that are certified under it, relying on the European Commission's adequacy decision of 10 July 2023
- Standard Contractual Clauses (SCCs) approved by the European Commission, for transfers from the EEA where no adequacy decision applies — this includes transfers to Ukraine
- UK International Data Transfer Agreements (IDTAs), or the UK Addendum to the SCCs, for transfers from the United Kingdom
- Equivalent contractual protections with our service providers where the above are not applicable
Storage of Service data in the United States relies on the European Commission's adequacy decision of 10 July 2023: our cloud infrastructure provider holds a current certification under the EU–US Data Privacy Framework, and the data is stored with that provider.
Ukraine has not been the subject of an adequacy decision. Personal data held by the Service is no longer stored in Ukraine; what remains there is the handling of enquiries submitted through the contact form and the technical administration of the Service, during which Promodo personnel located in Ukraine access the Service remotely. That processing is carried out under Standard Contractual Clauses and is additionally subject to the Law of Ukraine "On Personal Data Protection." You may request a copy of the transfer safeguards applicable to any specific provider by contacting legal@gelios-monitor.ai.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, destruction, or accidental loss. These measures include:
- Encryption of data in transit using TLS/SSL
- Passwords stored only as salted hashes, never in plaintext and never disclosed to third parties
- Session management and access controls on all authenticated areas of the Service
- Role-based access controls limiting data access to authorized personnel only
- Regular security reviews, vulnerability assessments, and dependency audits of our infrastructure
- Payment card data security delegated entirely to Stripe (PCI-DSS Level 1 certified)
While we take these precautions, no method of electronic transmission or data storage is 100% secure. We cannot guarantee absolute security of your personal data.
Data Breach Notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the applicable supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33) and will notify affected individuals without undue delay in accordance with GDPR Article 34 and applicable U.S. state breach notification laws.
12. Children's Privacy
GELIOS is not intended for users under 18 years of age. We do not knowingly collect, solicit, or process personal data from children. If we become aware that we have inadvertently collected data from a user under 18, we will promptly delete it and terminate the associated account. If you believe we have collected data from a child, contact us at support@gelios-monitor.ai.
13. Third-Party Links and Integrations
The Service may contain links to third-party websites, services, or resources, including the websites of AI platform providers referenced in our reports. This Policy does not apply to third-party sites. We are not responsible for the privacy practices or content of any third-party site. We encourage you to review the privacy policies of any third-party sites you visit.
When you configure domains for monitoring, we query those domains via third-party AI APIs. Any personal data that may appear in AI-generated responses (for example, a domain owner's name appearing in an AI answer) is processed solely for the purpose of delivering your monitoring report and is not used for any other purpose.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or Service features.
Updates that correct or clarify factual information — for example, the country in which the infrastructure running the Service is located — take effect when published. This Policy has to describe how the Service actually works at any given moment, so we do not delay a correction: an accurate description published today is worth more to you than an outdated one kept in force for another two weeks.
When we make material changes to how we handle your data, we will:
- Notify you via email to the address on your account at least 14 days before those changes take effect, and state in that notice the date from which they apply
- Post a prominent notice on the Service and update the "Last updated" date and version number at the top of this Policy
- For changes that materially affect your rights or how we use your data, provide at least 30 days' notice
Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy. If you do not agree to a material change, you must stop using the Service before the date stated in our notice. Prior versions of this Policy are available on request at legal@gelios-monitor.ai.
15. Contact and Data Protection Inquiries
For any questions, concerns, or requests regarding this Privacy Policy or our data practices:
Promodo Inc.
Registered address: Suite 100, 6920 S. Cimarron Rd., Las Vegas, NV 89113, United States
State of incorporation: Nevada, United States
Privacy & support inquiries: support@gelios-monitor.ai
Legal notices & data subject requests: legal@gelios-monitor.ai
Website: gelios-monitor.ai
We aim to respond to all privacy-related inquiries within 30 days. For GDPR-related requests, we will respond within the timeframes required by applicable law. For California privacy rights requests under CCPA/CPRA, we will respond within 45 days.
Your privacy matters to us. We process only what is necessary to provide GELIOS, we do not sell your data, and we do not use it for advertising. If you have any concern about how we handle your data, please reach out — we are committed to resolving privacy inquiries promptly and transparently.