Now tracking answers across six engines, including Google AI Overviews and AI Mode

Privacy Policy

Last updated July 27, 2026

Limelit (“we”, “us”, “our”) helps brands track how AI search engines including ChatGPT, Perplexity, Claude, Gemini, Google AI Overviews, and Google AI Mode mention them. This policy explains what data we collect, how we use it, and the choices you have.

1. Data we collect

Account data. When you sign up we receive your name, email address, and a profile image from your OAuth provider (Google).

Brand and prompt data. Domain names, competitor lists, buyer-question prompts, and brand-voice configuration you create inside Limelit.

AI engine responses. The text and citation URLs returned by AI search engines when we run your prompts on your behalf.

Source pages we fetch. When you generate a blog draft we fetch the source URL you provided so the AI writer has context. We do not store these pages beyond the lifetime of the generation job.

Telemetry. Standard logs (IP address, user-agent, request paths) and product analytics events that help us debug and improve the service.

Server log data you send us. If you connect a log source for Crawler analytics, we receive request records from your own website: the time of the request, the HTTP method, the requested URL, the response status, the User-Agent header, and the visiting client’s IP address. These records describe visitors to your site, not users of Limelit. For this data you are the controller and we act as your processor, handling it only to produce the analytics you asked for. You are responsible for having a lawful basis to send it to us and for describing it in your own privacy notice.

2. How we use your data

  • To run AI search prompts and aggregate the results into your dashboard.
  • To generate, refresh, and publish blog drafts on your behalf.
  • To send transactional email (sign-in alerts, billing receipts).
  • To diagnose service issues and improve product quality.
  • To report which AI crawlers reached your site, and to check whether a request claiming to come from a given crawler genuinely did.

Crawler verification. A User-Agent header is chosen by whoever sends the request, so it can be forged. We use the visiting client’s IP address for one purpose: confirming a crawler’s claimed identity against the method its vendor publishes, such as forward-confirmed reverse DNS or a published list of address ranges. We rely on our legitimate interest in reporting accurate analytics and in detecting requests that misrepresent their origin. We do not use these IP addresses to profile, track, or identify individual visitors.

We do not sell your data. We do not use your prompts or generated content to train third-party models.

3. Sharing

We share your prompts with the AI engine providers strictly to run them and return answers: OpenAI, Anthropic, Google, and Perplexity. Each provider’s privacy policy applies to their handling of those requests.

To collect Google’s AI Overviews and AI Mode answers, and to power keyword research, we use search-data providers that query Google on our behalf with your prompts and brand domain. We do not send your name, email, account identifier, or IP address to these providers.

We also use hosting, backend, billing, and email providers to operate Limelit. All of these vendors process data on our behalf under their respective data-processing agreements.

A current list of our sub-processors, including what each one does and the data it receives, is on our Sub-processors page.

4. Your choices

  • You can export or delete your data at any time from /settings.
  • You can revoke API keys and pause auto-refresh schedules.
  • You can email us at hello@limelit.co with any privacy request.

5. How long we keep things

Visiting client IP addresses. We keep the raw IP address only until crawler verification for that record has run, and only for a few days at most in any case. Once the check runs, or that short window passes, we erase the IP and keep only the result. Records whose IP we never received carry no address to begin with.

Crawler analytics records. Ingested log records are deleted 90 days after we receive them. That window is enforced automatically, every day, for every organization.

Account and brand data. Kept while your account is active, and removed on request or after you close it.

6. Security

Data is encrypted in transit (TLS) and at rest. Sessions are scoped to short-lived cookies. Sensitive credentials live in Google Secret Manager.

7. Changes

We’ll update this page when our practices change and bump the “Last updated” date above. For material changes affecting existing users, we’ll also send notice via email.

8. Contact

Questions? hello@limelit.co.