Privacy Policy

Last updated: 3 June 2026

Who we are

Unsourced is an AI search intelligence platform operated by Unsourced, registered in England and Wales. We are the data controller for personal data processed through the unsourced.app platform.

Contact: rene@unsourced.app

ICO Registration: We are registered with the Information Commissioner's Office (ICO) as a data controller. ICO registration number: ZC150902.

This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and your rights under UK GDPR.

Personal data we collect

Account data

When you register: name, email address, company/organisation name. We use this to create and maintain your account and communicate with you about the service.

Site and monitoring data

When you add a site: the URL and display name you provide. If you upload nginx access logs or use the JS beacon, WordPress plugin, or Cloudflare Worker, we receive data generated by your site visitors including IP addresses, user-agent strings, request paths, and timestamps. This data is used to identify AI crawler activity on your site.

Citation and crawl event data

We store the results of AI citation checks: which AI systems were asked about your content, the prompts used, the AI responses, whether your site was cited, and which competitor domains were mentioned.

Payment and billing data

When you subscribe, Stripe processes your payment. We receive from Stripe: your Stripe customer ID, subscription status, and invoice records. We do not receive or store your card number, bank account details, or CVV — these are held exclusively by Stripe.

Plugin API key

A unique API key is generated for your account for use with the WordPress plugin. This key is stored and used to authenticate plugin requests.

Partner programme data

If you apply to the Partner Programme: your name, email, agency name, website, and any notes you provide. On approval, a Stripe Connect Express account is created using your email.

Technical and usage data

Server logs and error tracking data including IP addresses, browser type, pages visited, and error reports. Used to maintain and improve the service.

Lawful basis for processing

We process your personal data on the following legal bases under UK GDPR:

  • Contract performance (Article 6(1)(b)): processing necessary to provide the service you have subscribed to — account management, citation monitoring, report generation, billing
  • Legitimate interests (Article 6(1)(f)): security monitoring, fraud prevention, service improvement, and sending you relevant product updates. We have assessed that our legitimate interests are not overridden by your rights.
  • Legal obligation (Article 6(1)(c)): where required by law, e.g. retaining financial records for HMRC purposes
  • Consent: where we ask for your consent (e.g. optional marketing communications), you may withdraw it at any time

Data sub-processors

We share personal data with the following sub-processors who process data on our behalf. All are bound by Data Processing Agreements (DPAs) and process data only as instructed:

  • Stripe Payments Europe Ltd (payments, partner payouts) — EU/UK — stripe.com/privacy
  • Anthropic, PBC (AI citation checking — Claude) — US — anthropic.com/privacy
  • OpenAI, LLC (AI citation checking — ChatGPT) — US — openai.com/policies/privacy-policy
  • Google LLC (AI citation checking — Gemini) — US — policies.google.com/privacy
  • xAI Corp (AI citation checking — Grok) — US — x.ai/legal/privacy-policy
  • Groq, Inc (AI citation checking — Llama models) — US — groq.com/privacy-policy
  • Perplexity AI, Inc (AI citation checking — Sonar) — US — perplexity.ai/hub/legal/privacy-policy
  • Resend Inc (transactional email delivery) — US — resend.com/privacy
  • Hetzner Online GmbH (cloud hosting infrastructure) — DE/EU — hetzner.com/legal/privacy-policy
  • Cloudflare, Inc (CDN, DDoS protection, DNS) — US — cloudflare.com/privacypolicy
  • Sentry.io / Functional Software Inc (error monitoring and diagnostics) — US — sentry.io/privacy

All US-based processors operate under Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms approved under UK GDPR for international data transfers.

Origin Signal — proprietary data processing

Unsourced uses a proprietary mechanism called "Origin Signal" to detect whether AI systems reproduce content from your monitored pages. This involves embedding a hidden marker in pages you register with the service.

For the purposes of UK GDPR transparency, we disclose that this mechanism constitutes automated data processing of your site content. The specific technical implementation is a trade secret and commercially sensitive, but the fact of processing and its purpose (AI content reproduction detection) is disclosed here in accordance with our transparency obligations.

Origin Signal data is stored only in association with your account and is not shared with third parties for any purpose other than to provide the service.

Your customers — monitoring tools (JS beacon, WordPress plugin, Cloudflare Worker)

When you install any Unsourced monitoring tool on your website — the JS beacon, WordPress plugin, or Cloudflare Worker — Unsourced acts as your data processor. Your site visitors' data (including IP addresses, user-agent strings, and request metadata) is collected and transmitted to our servers on your behalf.

In this context, YOU are the data controller for your site visitors' data. You are responsible for:

  • Disclosing the use of Unsourced monitoring tools in your own Privacy Policy
  • Obtaining any consent required under UK GDPR, EU GDPR, or other applicable law from your site visitors
  • Entering into a data processing agreement with Unsourced if required under Article 28 UK GDPR (contact rene@unsourced.app)

Unsourced processes visitor data received via these tools solely to provide AI crawler detection services to you.

Data retention

We retain personal data for the following periods:

  • Trial account data: automatically deleted 30 days after collection
  • Standard and Pro account data: retained for 6 months (180 days) from the date of collection
  • Account data (email, name): retained for the duration of your account, then deleted within 30 days of account closure or deletion request
  • Financial records (Stripe billing data): retained for 7 years in accordance with HMRC requirements
  • Partner programme data: retained for the duration of programme participation, then deleted within 30 days of programme exit on written request
  • Error and diagnostic logs: retained for 90 days

Your rights under UK GDPR

You have the following rights under UK GDPR:

  • Right of access: request a copy of the personal data we hold about you
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): request deletion of your personal data (subject to legal retention obligations)
  • Right to data portability: receive your data in a machine-readable format
  • Right to restriction: request that we limit how we process your data
  • Right to object: object to processing based on legitimate interests
  • Rights related to automated decision-making: we do not use solely automated decision-making that produces significant effects on individuals

To exercise any of these rights, email rene@unsourced.app. We will respond within 30 days. Account deletion is also available self-service via Settings.

International data transfers

Some of our sub-processors (Anthropic, OpenAI, Google, xAI, Groq, Perplexity, Resend, Cloudflare, Sentry) are based in the United States. Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the UK Information Commissioner.

All server infrastructure (primary data storage) is hosted in EU data centres operated by Hetzner Online GmbH in Germany.

Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • All data in transit encrypted via TLS 1.2+
  • Passwords hashed using bcrypt (12 rounds)
  • Authentication tokens expire after 24 hours
  • API keys are unique per account
  • Access logs monitored for anomalies
  • Automated backups to encrypted object storage

No security measure is completely foolproof. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by UK GDPR.

How to complain

If you have concerns about how we handle your personal data, please contact us first at rene@unsourced.app — we will do our best to resolve any issue promptly.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time:

ICO helpline: 0303 123 1113 ICO website: ico.org.uk/make-a-complaint

Changes to this policy

We will notify you by email of any material changes to this policy at least 14 days before they take effect. The current version is always available at unsourced.app/privacy.

Contact

Data controller: Unsourced Email: rene@unsourced.app Website: unsourced.app ICO registration: ZC150902