Privacy Policy

A practical summary of how Sikwati handles account, website, and citation data.

What we collect

Account details: your email address, optional name, and authentication credentials so you can access the product securely.

Website data: the domain you add, discovered URLs from your sitemap or import, GEO scan results (heading structure, schema, content quality scores), tracked prompts, competitor domains, and the citation history we generate by testing those prompts against AI engines.

AI engine response excerpts: when we test your tracked prompts, we store an excerpt (up to ~3,000 characters) of the AI engine's text response so we can detect brand mentions and benchmark against competitors. These excerpts are content generated by the AI engines, not content from your site.

Optional connected services: if you connect Google Analytics 4 (GA4) or Google Search Console (GSC), we store the OAuth refresh token (encrypted at rest) plus the property or site details you select. We use these only to fetch the metrics needed for the overlay or search-visibility views, and you can disconnect them at any time from Site Settings.

Integration data: if you create API tokens, we store only a one-way hash of the token plus a short visible prefix, never the full token in plaintext after creation. If you configure Slack or outgoing webhooks, we store the destination URL and any signing secret needed to deliver those events.

Operational telemetry: we keep limited request logs and error traces to operate the service reliably. These do not include the contents of your scans or citation results.

How we use data

We use your data to run GEO scans on publicly accessible pages, run citation tests against AI engines using the prompts you've configured, generate reports and exec summaries, send transactional emails, and improve reliability and support. Public website monitoring does not require DNS ownership verification. Custom report domains and connected Google accounts have separate authorization requirements.

We do not sell your customer data, and we do not use your scan or citation history to train any models.

Third-party processors

AI providers: new tracking checks use OpenAI and Google Gemini APIs. Historical adapters for Anthropic and Perplexity may exist in legacy deployments, but are not included in the new tracking offer. Tracking sends your chosen question and search-context parameters. If you request an AI-written fix or report summary, relevant page or report information also goes to the generation provider. The applicable provider terms govern those requests.

Google Analytics 4 (GA4) and Google Search Console (GSC) — only if you opt in by connecting them. We use Google's official OAuth flow and do not see your Google credentials.

PayPal — for paid subscriptions. We store the subscription identifier returned by PayPal so we can manage your plan; we never see or store your payment instrument.

Email delivery: Cloudflare Email Sending is configured for the private staging deployment. Legacy or separately configured deployments may use Resend. The selected service receives the recipient address and email payload for transactional delivery. Enabling email does not imply that every scheduled report or alert workflow is available.

Slack — only if you configure a Slack incoming webhook for workspace alerts or test messages.

Your outbound webhook receiver — only if you configure one. In that case, Sikwati sends the event payloads you asked to receive (`webhook.test`, `alerts.created`, `sov.updated`, `scan.completed`) to the URL you provided, optionally signed with your secret.

Sentry — when enabled by the operator of your deployment, used for error tracking. Configured to scrub user-identifying fields from captured events.

Hosting: the current private staging deployment uses Cloudflare Workers and D1. Legacy deployments may use different hosting or database providers. Contact support for the verified infrastructure and processor list for the deployment you use.

Retention and deletion

We retain account and scan data while your account is active so your history and reports remain available. Citation results and GEO scan history accumulate over time — that's the value of using a tracker rather than a one-off prompt.

If you delete a website from your account, we delete its discovered pages, scan results, citation queries, citation results, competitor configurations, and share links. Aggregate alert and audit logs may persist briefly for operational integrity.

Account deletion removes associated active account records and owned website data, subject to legal obligations and the deployment's verified backup retention schedule. Deletion from the active database does not mean immediate deletion from backups. Contact support for the applicable retention and deletion process; we do not state a fixed backup deletion window without infrastructure verification.

Security

Passwords are stored as bcrypt hashes, never plaintext. Sessions are HTTP-only cookies with the standard NextAuth protections.

Access is scoped per user: every database query that touches your data is filtered by your user ID or your workspace membership. There is no admin override path that bypasses this scoping in normal operation.

Sensitive tokens are protected before they hit the database. GA4 and GSC OAuth refresh tokens plus share-link access tokens are encrypted at rest. API tokens are stored as one-way SHA-256 hashes, and share-link lookup also uses a SHA-256 hash so the plaintext token is not present in any index.

Outbound fetches during scans go through an SSRF guard that resolves hostnames first and rejects private and link-local IP ranges, with the resolved IP pinned for the actual fetch to prevent DNS rebinding.

If you have a security question or want to disclose a vulnerability, contact the support channel for your deployment.

Your choices

You can edit or remove tracked prompts, competitors, and websites from inside the app at any time, which removes the associated history.

You can disconnect GA4 or GSC from Site Settings, which removes the stored OAuth credentials for those integrations.

You can revoke API tokens, Slack webhooks, and outgoing webhooks from Settings or Workspace Integrations at any time.

You can revoke any share link you've generated, which immediately makes the report URL inaccessible to anyone holding it.

You can request account deletion through the support channel for your deployment.