
Privacy policy
Last updated: 1 October 2026
This policy explains what the operator of Mariy ("we", "us") collects when you use Mariy, the AI-readiness checker: why we collect it, who processes it for us, how long we keep it, and the choices you have. It describes the service as it runs during the beta.
1. What we collect
Your account
- Email address: We receive it from Clerk, our sign-in provider, the first time you open the app. We store it only if Clerk has verified it.
- Account ID: A unique ID that Clerk creates for your account. We use it to link your data to you.
Your sites and scans
- Website addresses: The addresses you scan, and the sites you verify, with the verification method and date.
- Scan reports: The score, the result of each check, the recommendations and the AI fixes for scans you run while signed in, plus your site audits and the pages they read. They are saved to your account. If you make a report public, anyone with its link can read it.
- Credits: How many scans, AI fix runs and site audits are left for each of your sites, and a record of each scan you run.
- Beta codes: Your personal beta code and, if you redeem a code, the site you redeemed it for and the date.
Scans without an account
- Visitor scan: We do not save a report. We keep the latest score and the result of each check for each website address, in one entry per site that the next scan of the same site replaces, and reuse it for 24 hours. This is information about a website, not about you. Your browser also keeps the last result for the session (session storage).
- Free AI visibility check: We store the website address, brand name and industry you enter, the question we asked the AI engine, and the sources and the sentence from its answer. We use them to answer the same check again for 7 days and to cap our daily spending. We do not store your IP address, and the check is not linked to any account.
Payments
- Payments are not open during the beta. When they are, Stripe processes them, and we never see or store your card number. We keep your Stripe customer ID and a record of each payment: amount, currency, date, site, Stripe IDs and refund status.
Technical information
- IP address: Used as the key of our rate-limit counters, together with your account ID for some limits, to prevent abuse. The counters are held by Upstash.
- Browser and device: Your IP address, browser type and the pages you request appear in our hosting provider's server logs.
2. How we use it
- To run scans, save your reports, and write recommendations and fixes.
- To manage your account, your verified sites, your credits and your beta code.
- To apply rate limits and protect the service from abuse.
- To send you messages about your account, such as a verification code, once email is switched on.
- To fix problems and improve the service.
- To answer your requests and meet our legal obligations.
3. Who processes your data
We use the service providers below to run Mariy. Each receives only what its task needs and handles it under its own privacy policy, linked next to its name.
Used today
- Clerk: Accounts and sign-in, including sign-in for AI assistants that connect through MCP. Receives your email address, your account ID and session cookies, and sees your IP address and browser when you sign in. clerk.com/legal/privacy
- Vercel: Hosts the website and the app. Receives every request, including your IP address, your browser and the page requested, and keeps server logs for a short time. vercel.com/legal/privacy-policy
- Neon: Our PostgreSQL database. It stores the data described in section 1. neon.com/privacy-policy
- Upstash: Rate limiting. Receives your IP address and, for some limits, your account ID, as counter keys. upstash.com/trust/privacy.pdf
- Anthropic: Writes the AI recommendations and fixes for scans you run while signed in. Receives content from the scanned site: its address, page titles, extracted text and check results. It receives no account data. www.anthropic.com/legal/privacy
- OpenAI: Runs the free AI visibility check. Receives only a fixed question about your industry. The brand name and website address you enter are not sent to it; we keep them in our database. openai.com/policies/privacy-policy
- Wikidata (Wikimedia Foundation): Checks whether a brand has a Wikidata entry, on scans you run while signed in. Receives the domain name of the scanned site. foundation.wikimedia.org/wiki/Policy:Privacy_policy
- Google Fonts: Loads the fonts of the printable report on the paid-report page. Your browser sends it your IP address when you open that view. policies.google.com/privacy
Used only by features that are not switched on yet
These features are off during the beta. Before we switch one on, we will move its provider to the list above and change the date at the top of this page.
- Stripe: Payments for the one-time unlock and for monitoring. Receives your email address, your account ID and the site's address. You enter your card details on Stripe's own page. stripe.com/privacy
- Resend: Email: verification codes and monitoring alerts. Receives your email address, or the admin@ address at your site's domain for a verification code. resend.com/legal/privacy-policy
- Brave Search: Finds mentions of your brand on the web, and receives your brand name and your site's domain (used to leave your own site out of the results). It also grounds one of the citation-test AI engines, and then receives the test question. search.brave.com/help/privacy-policy
- Serper: Finds mentions of your brand. Receives your brand name and your site's domain. serper.dev/privacy
- Exa: Finds mentions of your brand. Receives your brand name and your site's domain. exa.ai/privacy-policy
- YouTube Data API (Google): Finds mentions of your brand on YouTube. Receives your brand name. policies.google.com/privacy
- OpenAI: The citation test and the prompt explorer. Receives questions built from your site's content, and any question you type yourself.
- Anthropic (Claude Haiku): Suggests sites to compare against in the competitor comparison, and writes the citation-test questions. Receives the scanned site's address, its page title and description, the content types detected on it and its language. It receives no account data.
- Perplexity, Google Gemini and Anthropic (Claude Agent SDK): Extra AI engines for the citation test, used only if we turn them on. They receive the same questions.
We do not sell your personal information, and we do not share it for advertising.
4. Cookies and browser storage
- Sign-in cookies: Set by Clerk to keep you signed in. The app needs them to work.
- Theme: A cookie named theme, also saved in local storage, remembers light or dark mode for one year.
- Language: A cookie named NEXT_LOCALE remembers the language you chose.
- Beta banner: A cookie named lp_beta_dismissed remembers for 30 days that you closed the beta banner on the home page.
- Local storage: Your progress in the GEO checklist tool, the notifications you have read, and the announcements you have closed.
- Session storage: The last visitor-scan result, so it survives a page reload. It is cleared when you close the tab.
- Payments: When payments are open, Stripe sets its own cookies on its checkout page.
We use no analytics, tracking or advertising cookies.
5. How long we keep it
- Account data: Kept while your account exists.
- Reports, scan history and site audits: Kept until you delete your account. They do not expire on their own.
- Visitor-scan results: One entry per website address, replaced by the next scan of the same site. We reuse it for 24 hours and then stop showing it, but the entry itself has no expiry date.
- Free AI visibility checks: Reused for 7 days. The stored checks, including the entries we use to track our daily spending, are kept with no expiry date.
- Rate-limit counters: Expire on their own, within about two days.
- Server logs: Kept by our hosting provider for a short time, for operations and security.
- Payment records: Kept after you delete your account, because accounting and tax law requires us to keep them.
- Beta-code redemptions: Kept after you delete your account (the site and the date only), so the same website cannot get a second beta unlock.
- Verification-bundle records: Kept after you delete your account, with the site's address and dates but not your email address, so the same website cannot get the free verification bundle twice.
6. Deleting your account
You can delete your account from Account settings in the account menu, if that option is shown to you, or by emailing us from the address on your account. When an account is deleted, we erase its data automatically, as follows.
What we erase
- Your reports and scan history.
- Your site audits and citation tests.
- Your verified sites, except the site records listed below.
- Your beta code, if you have not used it.
- Your email address.
What we keep
- Payment records (amount, currency, date, site, Stripe IDs and refund status) and the site each payment belongs to, as accounting law requires.
- The record of a redeemed beta code (site and date), to prevent reuse.
- The record of a site that received the free verification bundle (its address and dates), so the same website cannot get it twice.
- An empty account entry that holds only the account ID and links these records together.
Stripe keeps its own payment records under its own policy. Visitor-scan results and free AI visibility checks are not linked to your account, so deleting it does not remove them.
7. Your rights
You can ask us to:
- Access: give you a copy of the personal data we hold about you.
- Correct: fix any data that is inaccurate.
- Delete: delete your account and the data linked to it, as the previous section describes.
- Export: give you your data in a machine-readable format.
- Object: stop or limit certain kinds of processing of your data.
To use any of these rights, email us at the address in the Contact section below. We will reply within 30 days, and we may ask you to confirm that the request comes from you.
8. Data security
We encrypt connections with HTTPS and store data with established service providers. No way of sending data over the internet is completely secure, however, so we cannot guarantee absolute security.
9. Children
The service is not meant for anyone under 16, and we do not knowingly collect their data. If you learn that a child has given us data, contact us and we will delete it.
10. International transfers
Our service providers process your data in countries other than yours, including the United States. We choose providers that apply internationally recognized data-protection standards.
11. Changes to this policy
We may update this policy from time to time, and we will change the date at the top of this page when we do. We will tell you about material changes in the app or by email.
12. Contact
For any question about this policy or about your data:
Email: hadri@alienszone.com