Privacy Policy

What we collect, why we collect it, who we share it with, and how long we keep it.

Last updated

1. Two different relationships

This policy covers two groups of people, and the distinction matters because our obligations differ.

You, our customer. We decide what to do with your account data, so we are the controller of it.

Visitors to sites you publish. We process their data on your instructions — you decide what forms and booking pages to run and what to do with the results. For that data you are the controller and we are your processor.

A third group is covered separately in section 10: businesses we research and contact before any account exists.

2. What we collect about you

  • Account details — your email address, name if you give one, and a hashed password. We never store the password itself.
  • Sign-in sessions — the IP address and browser user-agent for each active session, so you can see and revoke your own sessions in account settings.
  • Your content — the sites you build, including copy, images, uploaded files, and anything you import.
  • Product usage — which features you open and which actions you take in the app, so we can tell what works. This is tied to your account identifier, never to your email address, and we do not record your screen or your keystrokes.
  • Billing details when you subscribe. Card numbers are handled by our payment processor and never reach our servers; we keep the card brand, last four digits and expiry so you can recognise your own payment method.
  • Support correspondence when you email us.

3. Your conversations with the AI

The editor and the blog agent are chat tools, and we keep the conversation so it survives a page reload and so the next message has the context of the last one. That transcript includes what you asked for and the parts of your site the agent read or changed while answering.

It is stored with your site and deleted with it. We do not use your conversations, your content, or your site to train AI models, and neither the transcript nor your content is used to answer anyone else's request.

4. What we collect about visitors to your site

Sites published through UltraSites include analytics so you can see how they perform. For each visit we record the page, the referring source, the browser user-agent, language, timezone, a country derived from the network address, campaign parameters, and a random visitor identifier that distinguishes repeat visits.

Our analytics records do not contain visitors' IP addresses. The address is used at the moment a request arrives — to work out the country and to honour the exclusion list that keeps your own team's visits out of your numbers — and is not written to the analytics record.

There is one exception, and it applies to form submissions. When a visitor submits a form we capture the IP address, the user-agent and any advertising cookies present on that request, and hold them alongside the submission. They exist for a single purpose: if you have connected an advertising account, they are what lets us tell that platform the lead came from its click. They are never shown in your inbox, never used for anything else, and are erased 90 days after the submission — the longest window any ad platform accepts a conversion for. The lead itself stays.

Where you run a contact or lead form, we store what the visitor submits so you can read it. Where you run booking, we store the name, email address, phone number, any note the visitor adds, and the appointment itself, so the appointment can be confirmed, changed or cancelled. That content is yours; we do not use it for anything except delivering it to you and running the booking.

If you run an A/B test, visitors are assigned to a variant and that assignment is remembered for 90 days so they see a consistent site.

5. Cookies on sites you publish

The sites we serve set a small number of first-party cookies. No third party sets a cookie through us unless you add one yourself.

  • A visitor identifier and a session identifier, so repeat visits and sessions can be counted.
  • A first-touch attribution cookie recording how the visitor first arrived, so a lead can be credited to the campaign that produced it.
  • An A/B test assignment, where a test is running, kept for 90 days.
  • An opt-out cookie, described below.
  • A consent record, where consent gating is switched on.

A visitor can opt out of analytics on any site we host by visiting it with ?us_track=off appended, which sets a cookie the tracker honours from then on.

By default these cookies are set when a visitor arrives. Each site also has an opt-in mode in which nothing is stored until the visitor accepts — you will need to run a consent banner to collect that acceptance, because we do not currently ship one. Deciding whether your audience requires a banner, and putting one in place, is your responsibility as the controller of your visitors' data.

6. Published sites are public

A site you publish is served to anyone who asks for it, including search engines and the crawlers that gather material for AI answer engines. Published sites are always indexable and always readable by those crawlers; there is no per-site setting to opt out. If you do not want something read, do not publish it.

We record which AI crawlers read which pages, so you can see whether answer engines are picking your site up. That record is about the crawler, not about a person.

7. AI processing

The editor, the site generator, the blog writer, the SEO fixer and the translator all work by sending your site's content to Anthropic, which returns the changes. That means your copy and page structure leave our infrastructure and are processed by them on our behalf in order to answer your request. The same applies to the automated screening described in the Terms of Service, which reads published content to check it against our acceptable-use rules.

Where we research your market to brief the AI on your business, that research runs as web searches about your business and your competitors. It does not include your customers' data.

Where you dictate instead of typing, the recording is sent to OpenAI to be turned into text and is not retained afterwards. Where you generate an image, the prompt is sent to our image provider.

Where you enable the AI-visibility feature, we send prompts about your business to answer engines to check whether your site is being cited. Those prompts describe your business; they do not include your customers' data.

8. Who else sees it

We do not sell personal data. We share it with the providers that run the service:

  • Amazon Web Services — hosting, file storage, and transactional email.
  • Anthropic — the AI behind the editor, the generator, the blog writer, the SEO fixer, translation, market research and content screening.
  • OpenAI — speech-to-text for dictation, and one of the answer engines used for AI visibility.
  • Our image-generation provider, where you generate an image.
  • Stax — our payment processor. Card details go from your browser to Stax directly.
  • DataForSEO — keyword, ranking and AI-mention data about your site and your market.
  • Google — PageSpeed and, where you connect it, Search Console performance data.
  • Perplexity, for the AI-visibility feature when enabled.
  • PostHog — product usage analytics for the app itself.
  • Desque — where you connect it, leads from your site are forwarded to it as support tickets.

Advertising platforms. Where you connect an advertising account — Google Ads, Meta, Microsoft, TikTok, LinkedIn, Reddit or OpenAI — we send that platform the conversions from your site so it can measure and optimise your campaigns. That upload includes the identity-match material described in section 4. Nothing is sent to any advertising platform until you connect one, and connecting one is your decision as the controller of that data.

We may also disclose data where the law requires it, or where it is necessary to investigate a breach of the Terms of Service.

9. How long we keep it

  • Site analytics: 400 days, then deleted automatically by a daily sweep.
  • AI-citation records: 400 days. AI-crawler hits: 400 days. Page-speed samples: 120 days.
  • The identity-match material attached to a form submission: 90 days, then erased while the submission itself is kept.
  • Search Console query-and-page detail: 90 days. Market research about your business: 90 days, then refreshed.
  • Form submissions and bookings: until you delete them, or until your account closes.
  • Your sites, files and content: for as long as your account is open.
  • Account and billing records: for as long as needed to meet tax and accounting obligations after you close the account.

When you close your account we give you a reasonable window to export before deleting.

10. Businesses we research and contact

Separately from the service, we research small businesses from public sources — a company's own website, its public listings and its published contact details — to check how the site performs and to prepare a report on it. We hold the business's name, its website, its published contact details and the findings of that check, and we may use them to contact the business about what we found.

This is our legitimate interest in offering a relevant service to a business we can demonstrably help. If you would rather we did not hold or use your details, tell us and we will delete them and record the address so we do not approach it again. Every message we send says how to stop.

11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to how we use it, or receive it in a portable form. Email hello@ultrasites.ai and we will respond.

If your request concerns data collected by a site one of our customers publishes, that customer controls it — we will pass your request to them.

12. Security

Passwords are stored hashed. Access to production data is limited to the people who need it to run the service. Files are stored privately and served through short-lived signed links rather than public buckets. Credentials for the accounts you connect are stored encrypted.

No system is perfectly secure. If a breach affects your data we will tell you and the relevant regulator as the law requires.

13. International transfers

Our infrastructure and several of the providers above operate in the United States. If you are outside it, your data will be transferred and processed there.

14. Changes

We will update this policy as the service changes, and will give notice of material changes by email or in the app before they take effect.

15. Contact

Privacy questions: hello@ultrasites.ai.

English