Privacy Policy

Last updated: 2026-08-17

This is a plain-English first-pass privacy notice. It describes what Kartafla actually does today. We'll publish a lawyer-reviewed version before we scale; until then, anything below is accurate but not legal advice. Email support@kartafla.com with any question.

Who we are

Kartafla is a Generative Engine Optimization (GEO) platform that shows you how AI search engines (ChatGPT, Claude, Perplexity, Gemini) describe your brand, and helps you fix what they get wrong. The service operates from kartafla.com and is operated by Machariel OÜ.

Machariel OÜ (registry code 17573220), Sepapaja tn 6, Tallinn 15551, Estonia, is the data controller for personal data processed through the Kartafla service. Contact: support@kartafla.com.

What we collect

  • Account details you give us: email, name, password (hashed with Argon2; we never see your plaintext).
  • Project configuration: the brand name, domain, questions, and competitors you choose to track.
  • Scan results: the AI engines' answers about your brand, your GEO scores, your site audit findings, fixes generated.
  • Billing metadata via Paddle: subscription id, tier, status, billing-period end date. We never see or store your card number, billing address, or tax identifiers — those go to Paddle, which is the merchant of record and collects them as an independent controller under its own privacy notice.
  • Free-scan details (no account needed): if you run a free scan from our home page without signing up, we store the domain and question you enter, your IP address, and — only if you choose to unlock the full report — the email address you give us to send it to.
  • IP address: recorded on free scans and used transiently to rate-limit requests and protect the service from abuse.
  • Operational logs: server access logs and error reports (via Sentry) used to keep the service running.

How we use it

  • To deliver the service you signed up for — running scans, generating fixes, surfacing reports.
  • To grant the tier you paid for, and to keep it in step with what Paddle tells us about your subscription.
  • To send transactional email (password resets, weekly digests, fix-ready notifications, and free-scan reports you ask us to send) via SMTP2go.
  • To improve the product — aggregated, never traceable to an individual user.

Who we share it with

  • Paddle — our merchant of record. Paddle sells the subscription to you, takes the payment, handles tax and invoicing, and manages refunds and chargebacks. For payment data Paddle is an independent controller, not our processor, so Paddle’s privacy notice governs that data. We send Paddle your email address and an internal account reference so a payment can be matched to your account. (Subscriptions bought before 20 August 2026 were sold and billed through PayPal instead. We no longer send PayPal new data, but billing records from those purchases are retained for as long as tax and accounting law requires, and PayPal’s own privacy notice governs what it holds.)
  • OpenAI, Anthropic, Perplexity, Google, xAI and Mistral — we send your tracked questions to these AI engines as questions, so we can measure how each one answers. Each question is sent to each engine you are subscribed to. We do not send your account details, and the question text is the one you chose to track. (Until 17 August 2026 these questions were routed through a single intermediary, Apify; we now query the engines directly. Google — which powers our Gemini results — was paused between 17 and 19 August 2026 and receives questions again from 19 August 2026. xAI, which powers Grok, and Mistral are both listed here from 22 August 2026 ahead of those engines becoming available; no questions are sent to either unless and until that engine is part of your plan.)
  • OpenAI — we send relevant audit context to OpenAI when generating content fixes (rewrites, briefs, comparison articles). We also use OpenAI to suggest questions worth tracking: when you ask for suggestions, we fetch the public homepage of the website being analyzed and send a short extract of its visible text to OpenAI. On the homepage free scan this applies to whichever website address you enter, including one you do not own.
  • SMTP2go — to deliver transactional email.
  • Sentry — to capture and triage runtime errors. Sentry's data-scrubbing defaults are enabled.
  • Cloudflare — three separate things. It resolves our DNS. It provides Web Analytics, which counts page views without cookies, without local storage, and without fingerprinting, so no individual is tracked from one visit to the next. And it provides the bot check described below. Your traffic is not routed through Cloudflare otherwise.

We do not sell your data. We do not share it with advertisers. We run no advertising or cross-site tracking scripts, and no analytics that identify you or follow you between visits.

Cookies & local storage

If you don't have an account, we store nothing on your device at all — no cookies, no exceptions. You can browse the site and run a free scan without anything being saved to your browser. We previously set one cookie to help count visitors; we removed it in August 2026 because it wasn't worth what it cost you.

Once you create an account and sign in, five items are kept in your browser's local storage: the token that keeps you signed in, which project you had open, which explanatory tips you've dismissed, how far through setup you are, and your light or dark appearance choice. All five are first-party and exist only to make the app work; clearing them signs you out and resets those preferences. Signing out removes them. If you leave appearance set to "System" we store nothing for it — your device's own setting is read by the page as it renders, and never saved.

We use no marketing or advertising cookies, and nothing we store is used to build a profile of you or follow you across other sites. That is why you see no consent banner: there is nothing here to consent to.

Bot protection

The sign-up and password-reset forms are protected by Cloudflare Turnstile, which checks that a real person is filling them in. It replaced a wave of automated sign-ups that were using our password-reset email to send mail to people who had never heard of us. When you open one of those two pages, your browser loads the check from Cloudflare, which receives your IP address, browser details, and a token we then verify. It sets no cookie. The check runs on those two forms only — nowhere else on the site.

Cloudflare acts in two capacities here, and we think you should know both. It handles these signals on our instructions in order to protect our forms, which makes us responsible for that use. Separately, Cloudflare states that it also uses them to improve its own bot detection, and for that purpose it is responsible in its own right, relying on its legitimate interests. Cloudflare states it does not use these signals for tracking or advertising, and that it cannot identify individuals from them. Its Turnstile privacy addendum covers this in full.

Your rights

If you're in the EU/UK (GDPR) or California (CCPA) you can ask us to:

  • Show you the data we hold about you.
  • Delete your account and the data tied to it.
  • Export your data.
  • Correct anything that's wrong.

Email support@kartafla.com from the address on your account and we'll handle it within 30 days.

Retention

We keep your account data for as long as your account exists. You can delete it yourself at any time from Settings, which removes your account, projects, questions, scan results and email enrolments; if you email us instead we action it within 30 days. Cancelling a paid plan does not delete your account — paid features stop at the end of the billing period and your data stays until you ask us to remove it, so nothing disappears while you decide.

Everything else has a fixed window:

  • Free-scan IP addresses — 30 days, then redacted.
  • Free-scan email addresses — 180 days, then removed. The scan record stays, with nothing in it that identifies you.
  • Server access logs — 30 days.
  • Per-call AI usage records — 90 days. Only monthly totals are kept after that.
  • Billing records — retained as long as tax and accounting law requires, which is longer than the above.
  • Unsubscribe records — kept indefinitely, deliberately. They are how we remember not to email you, so deleting one would undo the request it represents.

Where we run

Kartafla servers run in Hetzner's Germany region. Cloudflare provides DNS resolution and the bot check described above; it does not proxy the rest of your traffic or see request content. OpenAI, Anthropic, Perplexity, Google, xAI, Mistral, Paddle, PayPal, SMTP2go, and Sentry operate from their own jurisdictions; standard contractual clauses apply for cross-border transfers where required. OpenAI, Anthropic, Perplexity, Google and xAI are based in the United States. Mistral is based in France, so questions sent to it do not leave the EU.

Contact

Questions or rights requests: support@kartafla.com.