Sign up = 10 credits to see your brand's visibility in ChatGPT and Gemini

    Privacy Policy

    Last updated: June 2026

    At Growth SpA, operator of the SearchBrand platform, we are committed to protecting the privacy and security of your personal data. This Privacy Policy describes how we collect, use, store, and protect your personal information in accordance with Chilean Law 19.628 on Protection of Private Life and the General Data Protection Regulation (GDPR) of the European Union, where applicable.

    1. Data Controller

    Growth SpA

    Tax ID (RUT): 77.824.037-8

    Address: La Capitanía 80, office 108, Las Condes, Metropolitan Region, Santiago, Chile

    Email: hi@searchbrand.ai

    DPO (Data Protection Officer): Orlando Flores

    DPO Email: hi@searchbrand.ai

    2. Data We Collect

    We collect the following types of personal data:

    • Identification data: name, surname, email, phone
    • Company data: company name, website, position
    • Usage data: platform interactions, preferences, query history
    • Technical data: IP address, browser type, device, cookies

    3. Purposes of Processing

    We use your personal data for the following purposes:

    3.1 Service Provision

    • Create and manage your user account
    • Provide access to platform functionalities
    • Process queries and generate AEO/SEO analyses
    • Manage subscriptions and billing
    • Provide technical support and customer service

    3.2 Service Improvement

    • Analyze usage patterns to improve the platform
    • Develop new functionalities
    • Perform aggregated statistical analyses
    • Optimize user experience
    • Perform performance benchmarking
    • Adjust and optimize credit consumption models

    3.3 Communications

    • Send notifications about your account and services
    • Communicate platform updates
    • Send commercial information (with your prior consent)

    4. Legal Basis for Processing

    The processing of your data is based on the following legal grounds:

    • Contract execution: for the provision of contracted services
    • Consent: for commercial communications and marketing
    • Legitimate interest: for service improvement and security
    • Legal obligation: for regulatory and tax compliance
    • Specific consent: for non-essential cookies
    • Legitimate interest: for fraud prevention
    • Consent: for international transfers when required
    • Legitimate interest: for internal analytics and service optimization

    5. Use of Data for Service Improvement and Communications

    5.1 Improvement Purposes

    Growth SpA may use depersonalized and aggregated data to:

    • Improve Platform functionalities.
    • Adjust and optimize credit consumption models.
    • Perform internal performance and usage analyses.
    • Optimize user experience.

    5.2 Data Ownership

    The use of data for improvement purposes does not alter the ownership of your personal data. You remain the owner of all personal information provided to the Platform.

    5.3 Communications About Changes

    Communications about relevant changes to the Platform or these policies may be made through:

    • Email to the address registered in your account.
    • Notifications within the Platform.
    • Publication on our website.

    6. Legal and Regulatory Compliance

    GROWTH SPA maintains strict compliance with the following data protection regulations and standards:

    • GDPR (General Data Protection Regulation): Compliance guaranteed through DPA (Data Processing Agreement) signed with Fly.io
    • Chilean Law 19.628: On Protection of Private Life and Personal Data Protection
    • SOC 2 Type 2: Compliance through Fly.io certifications
    • HIPAA: Security standards implemented through Fly.io

    Data Encryption and Security

    • Data in transit: TLS 1.3 encryption
    • Data at rest: AES-256 encryption
    • Backups: AWS redundancy with full encryption

    7. Data Subject Rights

    As a data subject, you have the following rights that you may exercise by contacting hi@searchbrand.ai:

    Right of Access (15 days)

    Request information about what personal data we process and how we use it.

    Right of Rectification (10 days)

    Request correction of inaccurate or incomplete personal data.

    Right of Erasure (20 days)

    Request deletion of your personal data when processing is no longer necessary.

    Right to Object

    Object to the processing of your personal data on legitimate grounds.

    Right to Data Portability (30 days)

    Receive your personal data in a structured, commonly used format.

    8. Security Breach Notification

    In the event of a security breach that may affect your personal data:

    • We will notify competent authorities within 72 hours of becoming aware of the breach
    • We will inform you directly if there is a high risk to your rights and freedoms
    • We will implement immediate corrective measures to mitigate risks
    • We will document the incident according to established procedures

    9. Third-Party Services

    We use the following third-party services for the operation of our platform:

    • Google Analytics / GA4 / GTM (web analytics)
    • Google Search Console
    • OpenAI
    • Google Gemini
    • Grok
    • Meta AI
    • Anthropic - Claude
    • Mercado Pago or similar payment processing platforms
    • Fly.io (cloud infrastructure with SOC 2 and HIPAA certifications)
    • Zapier / Make / Airtable / Notion (automation and internal management)
    • CRM / email marketing platforms (communication and customer management)

    Each of these providers operates under their own privacy policies and terms of service.

    Important: We do not sell, rent or transfer personal data — including Google user data obtained via Google Sign-In — to these third parties for purposes other than providing the contracted service.

    10. Google User Data and Limited Use

    SearchBrand offers "Sign in with Google" as an authentication method. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    10.1 What Google user data we collect

    When you sign in with Google we request only the non-sensitive scopes openid, userinfo.email and userinfo.profile. This gives us access to:

    • Email address
    • First and last name from your profile
    • Profile picture (URL)
    • Unique Google account identifier (Google account ID)

    We do not access Gmail, Drive, Calendar, Contacts, YouTube or any other sensitive or restricted scope.

    10.2 How we use Google user data

    • Authenticate your sign-in and create/identify your SearchBrand account.
    • Display your name and picture in the platform interface.
    • Send operational communications related to your account and the service.

    10.3 With whom we share, transfer or disclose Google user data

    We do not sell, rent or disclose Google user data to third parties for purposes other than providing or improving user-facing features. The only transfer occurs to subprocessors strictly necessary to operate the service (authentication provider, cloud infrastructure and transactional email), all under a Data Processing Agreement (DPA).

    10.4 How we protect Google user data

    • TLS 1.3 encryption in transit and AES-256 at rest.
    • Role-based access and multi-factor authentication for authorized personnel.
    • 24/7 security monitoring and audit logs.
    • Human access only for user support, debugging, security or legal compliance, always with explicit authorization or under legal requirement.

    10.5 Retention and deletion of Google user data

    We retain Google user data while your account is active. You may disconnect Google Sign-In or request account deletion at any time by emailing hi@searchbrand.ai. After your request, we delete your Google user data within a maximum of 30 days, except where legal retention obligations apply.

    10.6 Limited Use — Prohibited uses

    We explicitly do NOT use Google user data for:

    • Targeted, personalized, retargeted or interest-based advertising.
    • Sale to third parties, data brokers or information resellers.
    • Determining credit-worthiness or for lending purposes.
    • Training artificial intelligence models, our own or third-party.
    • Creating databases for resale or licensing.

    11. Data Retention

    We retain your personal data according to the following criteria:

    • Account data: while you maintain an active account
    • Billing data: 6 years for tax obligations
    • Security logs: 12 months
    • Google user data (OAuth profile): deleted upon disconnecting Google Sign-In or canceling the account, within a maximum of 30 days

    After cancellation of your account, your data will be deleted within 30 days, unless legal obligations require its retention.

    12. Data Security

    We implement appropriate technical and organizational measures to protect your data:

    • TLS 1.3 encryption for data in transit
    • AES-256 encryption for data at rest
    • Two-factor authentication available
    • Role-based access
    • 24/7 security monitoring
    • Encryption and access controls applied specifically to Google user data

    Our infrastructure provider (Fly.io) complies with SOC 2 Type 2 and HIPAA.

    13. International Transfers

    Your data may be transferred and processed on servers located outside Chile:

    • United States (Fly.io, AI providers)
    • European Union (where applicable)

    All transfers are made with appropriate safeguards in accordance with GDPR and applicable Chilean legislation.

    14. Cookies and Similar Technologies

    We use essential cookies for site operation and analytics cookies to improve our services. You can manage your cookie preferences in your browser settings.

    15. Minors

    Our services are directed at businesses and professionals. We do not intentionally collect data from minors under 18 years of age. If we detect that we have collected data from a minor, we will proceed with immediate deletion.

    16. Changes to This Policy

    We may occasionally update this Privacy Policy. Changes will be notified through:

    • Publication on our website with the update date
    • Email notification for significant changes

    Continued use of our services after publication of changes constitutes acceptance of the updated policy.

    17. Governing Law and Jurisdiction

    This Privacy Policy is governed by the laws of the Republic of Chile. For users in the European Union, GDPR provisions will apply where applicable. Any dispute will be submitted to the ordinary courts of Santiago, Chile.

    18. Contact

    To exercise your rights or for questions about this policy, you may contact us at:

    Email: hi@searchbrand.ai

    DPO: Orlando Flores

    Address: La Capitanía 80, office 108, Las Condes, Santiago, Chile