Product policy
Privacy
Your session
No account or database is required. API keys, current analysis and user notes stay in active browser memory and are cleared on refresh or close. Live Google prospect data is not persisted or sold. The app does not include analytics.
Optional saved contacts and client work
Agency details and independently entered client contact records are saved in this browser’s local storage when you choose Save. Client Tools automatically saves your intake answers, edited menus, manual reviews and roadmap progress with each client. Agency logos and theme/walkthrough preferences also use local storage. These records survive refresh, are not encrypted by the app, and do not sync between browsers, devices or app addresses. They are separate from API keys and live analysis. You can edit or delete client records and clear the agency profile in Settings. Clearing browser site data also removes saved contacts and client work. Client backups contain user-entered records and can be restored as a separate client in Settings. These records are used for report headers and copied summaries, not sent to AI automatically.
Requests you initiate
Keys pass transiently through the application server to the matching provider. Google receives search queries and requested place identifiers; PageSpeed receives the website URL; OpenAI receives structured website findings, derived scores and your notes only when you generate Sales Intelligence. Keys are not included in URLs, logs or AI prompts. Website servers receive a normal public-page request with an identifying User-Agent.
Optional external menu editing
Copying a menu prompt makes no external request. If you paste it into an AI service, that service receives the menu facts under its own policies. Preview and verify returned suggestions before applying them.
Provider policies
Google Maps Platform services are subject to Google's Privacy Policy. Optional AI requests are subject to OpenAI's Privacy Policy and API data controls. The app requests that Responses API output not be stored; provider abuse-monitoring rules can still apply.
Hosting and exports
Hosting providers may process normal connection metadata. Deployment operators must disable request-body and credential logging. Google-derived business data is displayed live and excluded from client snapshots. You control any copies or PDFs you create using the browser.