Privacy Policy
Effective 2026-07-06
Plain-language summary
Collimer is a tool that audits a website’s visibility in AI search assistants (ChatGPT, Claude, Gemini, Perplexity, Grok) and produces a scorecard with recommendations. To do this, we send queries to those AI providers, fetch publicly accessible web pages, and store the results so you can see them. This page describes what we collect, how long we keep it, how to delete it, and the limits of what we promise.
Who we are
Collimer is operated by Orrin Consulting, LLC, doing business as (“DBA”) Sandcastle Labs, based in Denver, Colorado, United States. We are the “data controller” for the personal data described in this policy. This policy covers collimer.com and the Collimer product at app.collimer.com. For anything in this policy, email hello@sandcastlelabs.ai.
Data we collect
From you
| Data | Why we collect it | When |
|---|---|---|
| Email address | To send scan-completion notification + your scorecard link | When you submit a Free Scan |
| URL you submit | To identify the site we’re auditing | When you submit a scan |
| Optional: ICP description, competitor list, conversion goal | To improve recommendation quality | If you fill them in (paid tiers) |
| IP address + timestamp | Abuse prevention + rate limiting | At submission |
We do not collect: your name (unless you sign up), payment data we don’t need (handled by Stripe), or third-party tracker data beyond what’s noted under “analytics.”
From the audit process
| Data | Why we store it |
|---|---|
| Raw responses from each LLM probe | Auditability + methodology transparency + future hallucination detection |
| HTML snapshots of the URL audited (and competitors, if provided) | Evidence trail for every recommendation |
| Scorecard JSON | Public sharable artifact + your dashboard history |
| Per-call cost + model version | Cost transparency + methodology validation |
Analytics
We use PostHog (US-hosted) for product analytics, plus Vercel Web Analytics, to measure aggregate funnel events: scan started, scan completed, scorecard viewed, scorecard shared, signup. We do not log personally identifiable behavioral profiles, sell your data, or run ad networks. On collimer.com, if you visit from the EU, EEA, or UK we ask for your consent before any non-essential analytics cookies load; everywhere else they load on page view. In the app at app.collimer.com, analytics run when you use it. Either way, you can opt out (see “Your rights” below).
How long we keep your data (retention)
| Data | Retention |
|---|---|
| Raw LLM probe responses | 90 days, then deleted |
| HTML page snapshots | 90 days, then deleted |
| Scorecard JSON (anonymized after 1 year if no account) | Indefinite if account active; anonymized otherwise |
| Email address | Until you unsubscribe / delete |
| IP address + submission timestamps | Only as long as needed for abuse prevention and security, then deleted or aggregated |
| Account-level usage data | Duration of account + 1 year |
You can request earlier deletion at any time (see “Your rights” below).
How we share data
We do not sell your data.
We share with the following processors only to deliver the service:
| Processor | What they see | Where |
|---|---|---|
| OpenAI / Anthropic / Google AI / Perplexity / xAI (Grok) | The prompt sent for the scan; never your personal data | US |
| Stripe | Billing data (card, billing address, invoice history) | US |
| Resend | Email address + email contents we send to you | US/EU |
| Cloudflare (R2 + CDN) | Encrypted page snapshots + scorecard JSON | Global edge cache |
| Neon (Postgres) | All structured app data | US-East |
| Fly.io (compute) | Application code execution | US (default region) |
| Sentry (error reporting) | Error stack traces with PII redacted | US |
| PostHog (product analytics) | Aggregate funnel events; no scan content | US |
The table above is our current sub-processor list. We update this page when it changes; material changes are announced as described under “Changes to this policy.”
Each provider processes data on our behalf under its own terms. We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, or property of Collimer, Sandcastle Labs, or others.
Your rights
Legal basis (EEA/UK). We rely on contract to run the scans and accounts you ask for, legitimate interests for analytics, abuse prevention, and inbound email, and your consent where we ask for it (e.g. non-essential analytics cookies in the EU/EEA/UK).
- Access: request a copy of your data via hello@sandcastlelabs.ai. We respond within 30 days, usually much sooner.
- Deletion: click the unsubscribe link in any Collimer email, or email us. We delete within 30 days, usually much sooner.
- Correction: email us; we update.
- Portability: we provide JSON / CSV exports on request.
- Opt out of analytics: browser cookie controls or tracker blockers (most stop PostHog on our domains), or email us and we’ll suppress what we can reasonably identify as yours.
Depending on where you live, you may have additional rights:
- EEA / UK (GDPR / UK GDPR): the rights above, plus the right to object to or restrict certain processing, withdraw consent, and lodge a complaint with your local data protection authority.
- California (CCPA/CPRA): the rights to know, delete, correct, and to opt out of “sale” or “sharing.” We do not sell or share personal information as those terms are defined, so there is nothing to opt out of. We will not discriminate against you for exercising your rights.
We may need to verify your identity before acting on a request. We are not a covered entity under HIPAA, GLBA, or similar regimes; do not submit health, financial, or other regulated data via the scan.
Data residency and international transfers
Data is stored in the United States (Neon US-East primary; Cloudflare R2 with US default; Fly.io US default region). If you use Collimer from outside the US, your data is processed in the US; where required, we rely on our providers’ Standard Contractual Clauses or equivalent safeguards for those transfers. We do not offer EU-only data residency at v1. Users for whom this is a blocker should not submit data to Collimer until we offer a regional option.
Brand non-affiliation disclaimer
Collimer scans publicly available web content. Brand mentions reproduced in scorecards reflect what we observe in publicly accessible AI assistant responses; they are not endorsements of, partnerships with, or any other relationship with the named brands. Collimer and Sandcastle Labs are not affiliated with OpenAI, Anthropic, Google, xAI, Perplexity, or any third party whose service we query as part of the scan.
Hallucination disclosure
AI assistants sometimes generate inaccurate or fabricated information (“hallucinations”). Collimer scorecards report what AI assistants actually said when probed; some of those statements may themselves be inaccurate. Where Collimer detects probable inaccuracies about a brand, it surfaces them as such. Collimer does not warrant that AI assistant outputs are accurate.
Methodology
Our methodology, including which models we query, how many runs per prompt, our scoring formula, and known limitations, is published at collimer.com/methodology and updated whenever it changes. Confidence intervals are reported on every metric.
Children
Collimer is not intended for users under 16. We do not knowingly collect data from children.
Changes to this policy
Material changes are communicated via email and dashboard notice 14 days before they take effect. Trivial / clarifying changes are posted with an updated “Effective” date.
Contact
Questions, requests, or complaints: hello@sandcastlelabs.ai. Orrin Consulting, LLC (DBA Sandcastle Labs), Denver, Colorado, USA.