Privacy Policy
Last updated: August 27, 2026
This policy covers the AI Visibility Checker at
aivisibility.unomage.com and its Polish-language mirror at
aivisibility.unomage.pl (together, the “tool”) — the free,
no-signup site scanner, its public report pages, the badge feature, and
the report-removal request form. It does not cover any other Unomage product or
website.
Who we are
The tool is operated by Unomage Sp. z o.o., a company registered in Warsaw, Poland (KRS 0001152225, NIP 9512614313, REGON 540770406). For any question about this policy or your data, contact us at contact@unomage.com or via LinkedIn.
What we collect, and why
Domains you scan
When you submit a URL to scan, we fetch and analyze that website (not you) and publish the result as a permanent, public report page at a shareable URL — this is the whole point of the tool, described in full on the methodology page. We do not require an account, an email address, or any payment to run a scan.
Your IP address
We log the requesting IP address briefly to enforce rate limits (a cap on how many fresh scans one visitor can trigger per hour, so the tool stays usable for everyone) — these records are automatically deleted after 24 hours. If you submit a report-removal request, the IP address that submitted it is stored alongside the request indefinitely, so we can review and act on it; you can ask us to delete it by contacting us at the address above.
Cloudflare Turnstile
We use Cloudflare Turnstile to tell real visitors apart from automated abuse on the scan form, the removal-request form, and our own admin sign-in — without a traditional "click every traffic light" CAPTCHA. Turnstile runs in your browser and may process your IP address and other device/browser signals to do this; it is provided by Cloudflare, Inc., a separate company we don't control. Cloudflare's own handling of that data is described in their Turnstile Privacy Notice , which we're required to (and do) reference here as a condition of using it.
Off-site signals about the domain you scan
As part of scoring, we check free public sources — Wikidata, Wikipedia, and Common Crawl — for whether the domain you're scanning is independently known to them. These are lookups about the domain, not about you, and involve no personal data of yours.
Business contact details we collect for sales outreach
Separately from the public scanner, we maintain an internal admin area where we track
scanned businesses as potential customers for a paid, more detailed report. For a given
scanned domain, we may record publicly-listed business contact email addresses found on
that business's own website (e.g. a contact@ or info@ address
on their public "Contact us" page), either added by us manually or found automatically
by a simple scan of that business's own already-audited pages. This is business contact
information about the company being scanned, not personal data collected from you as a
visitor to our tool, and we process it on the basis of our legitimate interest in
reasonable business-to-business marketing. We have not yet sent any outreach using this
data — that capability doesn't exist yet — and this policy will be updated before it
does.
Cookies
The public tool sets no cookies at all — no accounts, no tracking, no analytics cookies. The only cookie this site ever sets is a session cookie for our own internal admin sign-in (HttpOnly, Secure, SameSite=Lax), which only applies to us as the site operator, never to a visitor running a scan.
Other third parties involved
- Cloudflare, Inc. — Turnstile bot protection, as described above.
- Anthropic PBC — used only for an internal, manually-triggered fallback that helps us find a scanned business's public contact email when a simple scan of their site doesn't find one; not used automatically, and not used at all unless we've explicitly enabled it.
How long we keep things
- Scan reports: kept indefinitely as permanent public pages, per the tool's design.
- Rate-limiting IP records: deleted automatically after 24 hours.
- Removal-request records (domain, note, requesting IP): kept indefinitely unless you ask us to delete them.
- Admin sign-in sessions: expire automatically (currently after 7 days) and only apply to our own staff sign-in.
- Business contact emails collected for future outreach: kept until we no longer have a reason to, or until removed on request.
Requesting removal or deletion
If you own a site we've scanned and want its report unlisted from search engines and our sitemap, use the removal request form — submitting it takes effect immediately, no verification required. Unlisting removes the report from search and our sitemap; the page itself stays reachable only by direct link, and the underlying record isn't deleted. If you want data about you or your business fully deleted rather than just unlisted — including any business contact email we may have on file, or removal-request records tied to your IP address — email us at contact@unomage.com and we'll handle it manually.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data, and to receive a copy of it in a portable format. To exercise any of these, contact us at contact@unomage.com. If you're in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority — in Poland, that's the Urząd Ochrony Danych Osobowych (UODO).
International transfers
Cloudflare and Anthropic are both based in the United States. Where we rely on them, personal data may be processed outside the European Economic Area; both companies publish their own data-transfer safeguards, which govern that processing independently of this policy.
Children
This tool isn't directed at children, and we don't knowingly collect personal data from them.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and the "Last updated" date above.