Privacy Policy
Last updated August 19, 2026
Limelit (“we”, “us”, “our”) helps brands track how AI search engines including ChatGPT, Perplexity, Claude, Gemini, Google AI Overviews, and Google AI Mode mention them. This policy explains what data we collect, how we use it, and the choices you have.
1. Data we collect
Account data. When you sign up we receive your name, email address, and a profile image from your OAuth provider (Google).
Brand and prompt data. Domain names, competitor lists, buyer-question prompts, and brand-voice configuration you create inside Limelit.
AI engine responses. The text and citation URLs returned by AI search engines when we run your prompts on your behalf.
Source pages we fetch. When you generate a blog draft we fetch the source URL you provided so the AI writer has context. We do not store these pages beyond the lifetime of the generation job.
Telemetry. Standard logs (IP address, user-agent, request paths) and product analytics events that help us debug and improve the service.
Server log data you send us. If you connect a log source for Crawler analytics, we receive request records from your own website: the time of the request, the HTTP method, the requested URL, the response status, the User-Agent header, and the visiting client’s IP address. These records describe visitors to your site, not users of Limelit. For this data you are the controller and we act as your processor, handling it only to produce the analytics you asked for. You are responsible for having a lawful basis to send it to us and for describing it in your own privacy notice.
2. How we use your data
- To run AI search prompts and aggregate the results into your dashboard.
- To generate, refresh, and publish blog drafts on your behalf.
- To send transactional email (sign-in alerts, billing receipts).
- To diagnose service issues and improve product quality.
- To report which AI crawlers reached your site, and to check whether a request claiming to come from a given crawler genuinely did.
Crawler verification. A User-Agent header is chosen by whoever sends the request, so it can be forged. We use the visiting client’s IP address for one purpose: confirming a crawler’s claimed identity against the method its vendor publishes, such as forward-confirmed reverse DNS or a published list of address ranges. We rely on our legitimate interest in reporting accurate analytics and in detecting requests that misrepresent their origin. We do not use these IP addresses to profile, track, or identify individual visitors.
We do not sell your data. We do not use your prompts or generated content to train third-party models.
3. Sharing
We share your prompts with the AI engine providers strictly to run them and return answers: OpenAI, Anthropic, Google, and Perplexity. Each provider’s privacy policy applies to their handling of those requests.
To collect Google’s AI Overviews and AI Mode answers, and to power keyword research, we use search-data providers that query Google on our behalf with your prompts and brand domain. We do not send your name, email, account identifier, or IP address to these providers.
We also use hosting, backend, billing, and email providers to operate Limelit. All of these vendors process data on our behalf under their respective data-processing agreements.
A current list of our sub-processors, including what each one does and the data it receives, is on our Sub-processors page.
4. Cookies, analytics, and session recording
We set a small number of cookies, store a few values in your browser, and we record browsing sessions. This section lists all of it, and it applies to limelit.co only. The blogs we publish for customers on their own domains carry no Limelit analytics: no Google Analytics, no product analytics, no session recording, and no visitor identification. If you are reading a customer’s blog, whatever that site does is described in their privacy notice, not this one.
Strictly necessary. A session cookie keeps you signed in. It cannot be turned off without breaking sign-in, and it is never used for advertising or measurement.
Analytics and session recording. We use PostHog to count pageviews and understand how the product is used, and it records browsing sessions on our marketing pages and inside the app. A recording captures the pages you visit, your clicks, scrolling, and mouse movement. Text you type into form fields is masked, so recordings do not capture what you enter. Recording starts after the page finishes loading, and stops as soon as you decline.
Advertising measurement. We use Google Analytics 4 (_ga and _ga_* cookies), which also feeds Google Ads bidding and remarketing audiences. Separately, if you arrive from an ad or a tagged campaign link, an ll_attrib cookie records the click identifier and campaign tags from that URL for 90 days, so we can tell which campaigns lead to signups. It is only set when the URL you arrive on actually carries those tags. If you arrive through a referral link, an ll_ref cookie records the referral code for 90 days. Both are HTTP-only, meaning scripts in your browser cannot read them.
Visitor identification. We use Apollo.io on limelit.co to work out which company a visit came from, by matching your IP address against its business database. For visitors in the United States it can also identify an individual person. We use this to see which businesses are evaluating Limelit so that we can follow up with them, which is sales outreach rather than measurement. It sets no cookies. It stores three values in your browser’s local storage instead: an anonymous visitor identifier (apolloAnonId), a flag recording whether tracking is allowed, and a queue of events waiting to be sent. It never runs on a customer’s blog.
Turning it off. We honour your browser’s Global Privacy Control and Do Not Track signals. If either is set, we run no Google Analytics, no product analytics, no session recording and no visitor identification on your visit. Google Analytics is switched off before its tag loads rather than after, and the Apollo.io script is never requested at all, so Apollo receives nothing from your visit, not even your IP address. Most browsers offer this in their privacy settings, and several privacy extensions send it. The signal is read on every page load, so it applies to visits you have already made from that browser as well. If you would rather write to us, email hello@limelit.co and we will erase the records associated with your visits, including the ll_attrib and ll_ref cookies, which are HTTP-only and so cannot be cleared from the page itself.
We do not sell your personal information for money. We do use Google Analytics in a way that supports advertising, and Apollo.io to identify visiting companies and people for sales outreach. Some United States privacy laws classify one or both of these as a “sale” or as “sharing” for cross-context behavioral advertising. Declining, as described above, stops both.
5. Your choices
- You can switch off analytics, advertising measurement, session recording, and visitor identification by turning on Global Privacy Control or Do Not Track in your browser.
- You can export or delete your data at any time from /settings.
- You can revoke API keys and pause auto-refresh schedules.
- You can email us at hello@limelit.co with any privacy request.
6. How long we keep things
Visiting client IP addresses. We keep the raw IP address only until crawler verification for that record has run, and only for a few days at most in any case. Once the check runs, or that short window passes, we erase the IP and keep only the result. Records whose IP we never received carry no address to begin with.
Crawler analytics records. Ingested log records are deleted 90 days after we receive them. That window is enforced automatically, every day, for every organization.
Account and brand data. Kept while your account is active, and removed on request or after you close it.
7. Security
Data is encrypted in transit (TLS) and at rest. Sessions are scoped to short-lived cookies. Sensitive credentials live in Google Secret Manager.
8. Changes
We’ll update this page when our practices change and bump the “Last updated” date above. For material changes affecting existing users, we’ll also send notice via email.
9. Contact
Questions? hello@limelit.co.