[ Legal ]

Privacy Policy

What we collect, why, who processes it for us, how long we keep it, and your choices.

Last updated 1 October 2026

This policy explains how GetLocalised ("we", "us") handles personal data in GetLocalised. We collect as little as the Service needs, don't sell data, and don't use your content to train AI models.

What we collect

  • Account data: your name, email address and profile picture from Google or GitHub when you sign in. We don't receive your password.
  • Workspace content: listings, screenshots, images, brand profiles, strategies, keywords and the other material you create or import, plus who in your workspace changed what (the audit trail).
  • Store data: listing text, images and related details we read from store accounts you connect.
  • Credentials: store service-account keys and any AI provider keys you add. These are encrypted in an isolated vault; our application never holds them in readable form and never shows them back.
  • Billing data: your plan, credit balance and usage. Card and payment details are collected and held by our merchant of record (Dodo Payments or Creem), not by us.
  • Technical data: session cookies needed to keep you signed in, server logs (such as IP address, request times and errors) kept to operate and secure the Service, and cookieless page-view statistics (pages visited, load times, referrer, browser and country) from Cloudflare Web Analytics.

How we use it

To provide and secure the Service; to run the AI features you ask for; to publish what you approve; to bill you and apply plan limits; to support you; and to tell you about changes to the Service or these policies. We don't use advertising trackers. Links to our other products carry campaign tags so we can count clicks; they don't identify you.

AI processing

When you use an AI feature, the relevant content (for example a listing and your brand notes) is sent to an AI model provider to produce the result. We use OpenAI, Anthropic and Google, and send only what the task needs. Under their API terms, these providers don't use API data to train their models. If you add your own key, requests go to the provider you chose under your own agreement with them. We don't use your content to train models.

Who processes data for us

  • Vercel (application hosting)
  • Neon (database)
  • Cloudflare (credential vault, file storage and cookieless web analytics)
  • Inngest (background jobs)
  • OpenAI, Anthropic and Google (AI features)
  • Dodo Payments and Creem (payments, as merchant of record; Creem also screens image-generation prompts)
  • MailPiston (email for messages you send us, workspace invitations and account notifications)
  • Google and GitHub (sign-in)
  • Google Play (only for store accounts you connect)

Each processes data only to provide its service to us. Some are located outside your country; where required, transfers are covered by appropriate safeguards.

How long we keep it

We keep your active projects and workspace content while your account is active. Recent Studio command history is kept for 90 days, completed background-job prompts and results for 30 days, support messages for one year, and operational audit/security records for 400 days. We don't retain full AI-provider response payloads after processing. Billing records are kept for the period required by law. Deleting a project, connection, file or workspace deletes that content from the Service; deleting a connection also destroys its stored credential, and deleting a workspace destroys its stored files and credentials. Backups may keep deleted data for up to 30 days.

Your choices and rights

You can access, correct, export or delete your data. Most of this you can do in the app; for anything else, email [email protected]. Depending on where you live you may also have rights to object to or restrict processing, to data portability, and to complain to a data protection authority.

Security

Credentials are sealed with per-secret keys in an isolated vault, data is encrypted in transit, access is limited to each workspace's members, and changes are recorded in an audit trail. No system is perfectly secure; if a breach affects you, we'll tell you as the law requires.

Children

The Service isn't for children under 16, and we don't knowingly collect their data.

Changes and contact

We'll post changes here and tell you in the app or by email if they're material. Questions or requests: [email protected].