Oftheard measures what AI answer engines say about a brand and checks whether a website can be read by them. To do that it needs an account, a site to check, and the questions a buyer would ask. This page says what happens to each of those. Where it says “we”, it means Oftheard, Chennai, Tamil Nadu, India, the operator of oftheard.in, reachable at hello@oftheard.in.
What we collect
| Kind | What it is | Where it comes from |
|---|---|---|
| Account | Your email address and a password, or the name, email and profile picture your Google account shares when you sign in with Google. Passwords are held by Firebase Authentication as a salted hash. We never see the password itself. | You, at sign-up |
| Profile | Your name, company, website, sector, the competitors you name, and any place you pick to ask a prompt from, a state or a district, whose centre comes from OpenStreetMap. This is what a check and a session are aimed at. | You, at setup and in settings |
| Google data you connect | If you connect your own Google Analytics or Search Console from Settings: the email of the Google account that connected, the property or site you picked, a read-only token for that one service, and the figures read from it. Described in full under Your Google data. | Google, with your consent, only if you connect it |
| What the product makes | Site check reports, sessions (the prompts asked and the answers the engines gave), collections of prompts, action plans, and the usage counts for your plan. | Produced when you run a check or a session |
| Messages | Your name, email, website and message when you use the contact form or write to us. | You, when you write in |
| Technical | Your IP address and browser identifier, in server logs, used for rate limiting and to stop abuse. No advertising pixels, no fingerprinting; the one analytics tag is described under Cookies. | Your browser, on each request |
Cookies and browser storage
We set two kinds of cookie. The first is the session: it holds the tokens that keep you signed in, is marked HttpOnly and SameSite, and is sent only over HTTPS on the live site. It is not used to track you across other sites, and it is not shared with anyone.
The second comes from Google Analytics, which we use to see which pages are read and where visitors arrive from. It sets cookies named _ga and _ga_… that tell a returning visit from a new one for up to two years. Google Analytics 4 does not record or store IP addresses, and we have advertising features switched off. They are set only if you allow them when the site asks, and you can change your choice at any time; the site works the same either way. A browser that sends the Global Privacy Control signal is treated as a no without being asked.
Two things are kept in your browser's own storage and never sent to us: the theme you chose, and which fixes you have ticked off on a plan. Clearing your browser data clears them.
If you sign in with Google, Google sets its own cookies on its own domain under its own policy.
How we use it
- To do what you asked: run the check or the session, show you the report and the history, and build the plan.
- To run your plan: count checks and sessions against the month's allowance, and record which plan the account is on.
- To answer you: reply to messages sent through the form or by email.
- To keep the service up: rate limiting, abuse prevention, and fixing faults.
- To show you your own Google figures: which visits an AI answer sent, and which questions people typed into Google, read from the Analytics or Search Console property you connected and shown only to you.
- To see how the site is used: which pages are read and where visitors come from, in aggregate, through Google Analytics. Nothing in it names you.
We do not sell personal data, we do not run advertising, and we do not use your data to train any model.
Who else handles it
Oftheard is built on other companies' services. Each one sees only what it needs for its part.
| Service | What it does for us | What reaches it |
|---|---|---|
| Google Firebase | Sign-in and the database your account lives in | Your account, profile and everything the product makes |
| Google Cloud Run | Runs the server, in Mumbai (asia-south1) | Every request, and the stored reports |
| Cloudflare | The front door for oftheard.in: DNS, TLS and routing | Every request, including your IP address |
| Google Sign-In | The “Sign in with Google” button and prompt | Your Google account, when you choose it |
| Google Analytics | Counts page views and where visitors come from | The pages you open, your browser and rough location; never your email or account |
| Google Analytics Data API, Search Console API | Read the property you connected, read-only | The token you consented to and the property or site name; only if you connect one |
| Gemini, OpenAI, Perplexity | The answer engines a session asks | The prompts in your collection and the brand and competitor names. Never your email or account details. |
| DataForSEO | Fetches Google's live results page, as a buyer in India, for AI Overviews and AI Mode | The prompts in your collection |
| Google Places | Checks a business listing against the website, only for sites that declare a physical address | The business name and address on the site being checked |
| Chrome UX Report, PageSpeed Insights | Speed and field data for the site being checked | The site's address |
| Optional lookups | India Post PIN data, OpenStreetMap, Wikidata, Common Crawl and Bing Webmaster Tools, each switched on separately | The address or domain of the site being checked |
None of these is given your data for its own purposes. The engines answer the prompts; they are not told whose account asked.
What checking a site involves
A check reads the public pages of the site you name, the way a search crawler does: about seventy requests for a homepage check, more for a whole-site pass. It changes nothing on the site. The report keeps the findings and the short excerpts needed to show them, such as a title, a heading or a few lines of text. It does not keep copies of the pages.
On the free plan you can check only the site named on your account. Paid plans can check competitors' public sites in the same way, up to the plan's cap.
A report can be given a share link. Anyone holding that link can open the report without signing in, so treat the link as public. Shared report files expire thirty days after they are made.
AI crawler reads
If you install the crawler sensor, a short snippet in your Cloudflare worker or a small WordPress plugin, your site sends us one line each time a known AI crawler fetches a page: the time, the path, the crawler's name and the response status. Nothing is sent about human visitors, no address of anyone is kept, and the records are used only to show you which crawlers read which pages. Removing the snippet or the plugin stops the sending at once; revoking the key from Settings does the same.
Your Google Analytics and Search Console data
From Settings you can connect your own Google Analytics property and your own Search Console property, so that your own numbers show which visits arrived from an AI answer and which questions people typed into Google that showed your site. Both connections are optional, and the rest of the product works without them.
What we ask for. Two read-only permissions and no others: to view your Google Analytics data (analytics.readonly) and to view Search Console data for your verified sites (webmasters.readonly). Nothing in either service can be changed by us. Consent is asked for on Google's own page, and only the account you choose there is connected.
What we read. From Analytics: the list of properties the account can see, so you can pick one, and then a report of sessions over the last ninety days by landing page and referring site, from which the visits sent by ChatGPT, Perplexity, Gemini, Copilot and Claude are counted. From Search Console: the list of sites the account can see, and then the queries, pages, impressions and clicks for the last ninety days in India. Nothing else is read, and nothing about individual visitors reaches us, since neither service provides it.
What we keep. On your account record: the email address of the Google account that connected, the property or site you picked, and a token that lets the server read that one service again without asking you each time. The Analytics summary is re-read when you open the page, and no more than once every six hours. Queries imported from Search Console are saved into a collection on your account, where they are yours to edit or delete like any prompt you typed. If you instead share the property with our service account, only the property id is stored.
What we do with it. Show it to you on your own pages, and offer the Search Console queries as prompts for sessions you choose to run. It is not sold, not used for advertising, not used to train any model, and not read by a person except to fix a fault you have reported. Who does and does not receive it is named in full under who we share it with. Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting. Press Disconnect on the row in Settings. That deletes the token and the stored figures from your account at once, and asks Google to revoke the token as soon as neither row uses it. You can also remove the access from your Google account at myaccount.google.com/permissions, after which the server can read nothing further. Deleting the account deletes all of it.
Who we share your Google data with
This section is about the data described just above: what is read from the Google Analytics property and the Search Console property you connect, the token that reads them, the email of the Google account that connected, and the figures derived from any of it. Google asks every application to say plainly who receives that data. Here is the whole of it.
We do not sell it, rent it or trade it. We do not transfer it to anyone for advertising or any other marketing purpose. We do not use it, and we do not allow anyone else to use it, to develop, improve or train any model, ours or another company's, including any artificial intelligence or machine learning model. No person reads it — nobody here and nobody elsewhere — except with your explicit consent while we look into a fault you have reported, or where security requires it to investigate abuse or a breach, or where the law requires it.
Three parties handle it, each only as far as its part needs, each acting on our instruction and never for purposes of its own:
| Who | Why they have it | What reaches them |
|---|---|---|
| You, the account holder | It is yours, and showing it to you is the whole point of the connection | All of it, on your own signed-in pages: Settings, the visits from AI answers, and the page ledger |
| Google LLC, as Google Cloud Run, Mumbai (asia-south1) | Runs our server, which is what calls the Google APIs. The data passes through it as the request is served | Everything read from your property, for the length of the request that serves it. What stays on the server afterwards is one line of our own running log — that a read happened, for which account, and how many sessions it counted — and nothing of the figures themselves |
| Google LLC, as Cloud Firestore and Firebase Authentication, United States (nam5) | The database your account lives in, and the sign-in that proves the account is yours | The refresh token, the connected Google account's email, the property or site you picked, and the summary of figures. Held under your account and readable only with your own signed-in credentials |
Nobody else, with one exception that is yours to make or not, and it is worth being exact about it.
Your Analytics figures never leave. They are not sent to Gemini, OpenAI, Perplexity, DataForSEO or any other engine, at any time, for any reason. Nothing read from your Analytics property goes anywhere but your own pages.
Search Console is different in one respect, and only if you press Import. Doing so turns the questions people typed into Google to find you into prompts in a collection on your account, yours to edit, add to or delete. If you then run a session on that collection, the text of those questions is sent to the answer engines, because asking them is what a session is. Editing a question first does not change where it came from. What is never sent with it is everything else: not the impressions, the clicks, the positions or the pages, not the property, not your email, and nothing that identifies you or any visitor to your site. Nothing is sent until you run a session, or until one you booked yourself comes due, and a collection you never run sends nothing anywhere.
Beyond that, nobody. Not our own website analytics. Not any advertising network, data broker, enrichment service or marketing tool. Not another customer of ours. A report can be given a public share link, as said above; a report contains none of this data, so a share link cannot carry it.
Two things could move it further, and both are named here rather than left to be assumed. The law: if a binding legal demand, a court order or a regulator's direction requires disclosure, we will disclose only what is required, and we will tell you unless we are forbidden to. A change of ownership: if the service were sold or merged, we would ask for your consent before your Google data moved to the new operator, and refusing would disconnect it and delete it rather than transfer it.
All of it stops when you press Disconnect, which deletes the token and the figures and asks Google to revoke our access, or when you remove the access yourself at myaccount.google.com/permissions.
How long we keep it
- Account, profile, reports, sessions and plans: for as long as the account exists.
- Shared report files: thirty days.
- Crawler read records: ninety days.
- Connected Google data: the token and the summary until you press Disconnect or the account is deleted; imported queries until you delete them from the collection.
- Messages: until answered, and then for up to a year as a record of the correspondence.
- Server logs: for a short period, under the log retention of the hosting provider.
To have the account and everything under it deleted, write to hello@oftheard.in from the address on the account. Deletion is done within thirty days, and confirmed by reply. A copy of your data can be requested the same way.
Your rights
Under the Digital Personal Data Protection Act, 2023 and any other law that applies to you, you can ask what personal data we hold about you, have it corrected, have it erased, and withdraw consent for anything that rested on it. Write to hello@oftheard.in. Mail is read by a person and acknowledged within one working day, and requests are resolved within the time the law sets. If you are not satisfied with the answer, you may raise it with the Data Protection Board of India.
Security
Everything travels over HTTPS with strict transport security. The session cookie cannot be read by script. Passwords are never held by us. Access to the stored data is limited to the people who run the service. No system is beyond fault; if a breach affects your data we will tell you and the authority as the law requires.
Children
The service is for businesses and the people who work in them. It is not meant for anyone under eighteen, and we do not knowingly hold data about them.
Changes to this page
The date at the top changes when the policy does. A change that matters to you, such as a new processor or a new use of data, is announced on this page and by email to account holders before it takes effect.
Contact
Questions, requests and complaints about personal data go to hello@oftheard.in, or through the contact page.