Legal

Privacy Policy

Last updated: 2 July 2026

Faro (“we”, “us”, “our”) operates byfaro.ai. This Privacy Policy explains what data we collect when you use our website and tools, how we use it, and the choices you have. We keep this as plain as possible. No legal theatre.

1. What we collect

We collect two categories of data:

Data you give us directly. When you enter a URL into the AI Readiness Scan, we process that URL to perform the audit. When you submit an email address to start a paid subscription, set up weekly monitoring, or contact us, we store that email. When you fill in the llms.txt Generator or AI Schema Creator form, we process the details you enter to generate your file. We do not store this after the session ends.

Data collected automatically. We use Google Analytics 4 (GA4) via Google Tag Manager to understand how people use the site. GA4 collects anonymized data including pages visited, session duration, approximate geographic region, and device type. This data is aggregated and does not identify you personally. We also store a basic server-side count of total scans run. This contains no personal information.

2. How we use your data

We use your data to:

  • Run the AI readiness audit on the URL you submit
  • Generate your llms.txt file
  • Send you transactional notifications related to your monitoring subscription or account (you can unsubscribe at any time)
  • Send transactional emails related to your account or subscription, if you become a paid customer
  • Understand how the product is used so we can improve it
  • Comply with legal obligations

We do not sell your data. We do not use your data for advertising. We do not share it with third parties except the processors listed below.

3. Third-party processors

We work with the following services, each of which may process some of your data as described:

  • Clerk: authentication and session management. Clerk handles account creation, sign-in, session tokens, and email verification. Clerk stores your email address, encrypted credentials, and session data on your behalf. See Clerk's Privacy Policy.
  • Supabase: database and backend storage. Supabase stores your scan history, account metadata, and monitoring configuration. Data is held in Supabase's managed Postgres infrastructure. See Supabase's Privacy Policy.
  • Vercel: hosts the Faro application. Your requests pass through Vercel's infrastructure. Vercel may log IP addresses and request metadata for security and reliability purposes.
  • Google Analytics 4: anonymized usage analytics. Data is processed by Google LLC in accordance with their privacy policy.
  • Resend: transactional email delivery. If you submit an email address, Resend processes it to send confirmation emails.
  • Stripe: payment processing for paid subscriptions. Stripe handles all card data directly; Faro never sees or stores payment card details.
  • AI providers (Anthropic, OpenAI, Perplexity): certain Faro tools, including the Faro Assistant and AI-powered generators, send content you input to third-party AI APIs to generate responses. We do not send personally identifying information to these APIs unless you include it in your input. AI provider data handling is governed by their respective usage policies. We use these APIs to generate outputs; we do not use your inputs to train AI models.

Each processor is contractually bound to protect your data and use it only for the purpose of providing their service to us.

4. Cookies

We use a small number of cookies. Google Analytics 4 places analytics cookies to distinguish sessions and measure engagement. You can opt out of analytics cookies by clicking “Decline non-essential” in the cookie banner, or by using the Cookie Policy page. We do not use advertising or tracking cookies.

5. Data retention

Monitoring subscription and account email addresses are retained until you unsubscribe or request deletion. Scan results are ephemeral. We do not store the detailed output of your scan beyond the active browser session. Usage analytics data in GA4 is retained for 14 months, after which it is automatically deleted by Google. If you become a paid customer, we retain account and billing data for the duration of your subscription plus 7 years, as required for tax and accounting purposes.

6. Your rights

Depending on your location, you may have rights under GDPR (EEA/UK), CCPA (California), or other applicable laws. These rights typically include:

  • Access: request a copy of the personal data we hold about you
  • Rectification: ask us to correct inaccurate data
  • Erasure: ask us to delete your data
  • Portability: receive your data in a machine-readable format
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: for any processing based on consent, withdraw it at any time without affecting prior processing

To exercise any of these rights, email us at hello@byfaro.ai. We will respond within 30 days.

7. Security

All data in transit is encrypted via HTTPS. We apply principle-of-least-privilege access controls to any systems holding personal data. We do not store payment card information. All payments are handled by Stripe's PCI-DSS certified infrastructure. Despite these measures, no system is completely secure. If you believe your data has been compromised, contact us immediately at hello@byfaro.ai.

8. Children

Faro is a B2B tool intended for use by businesses and professionals. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has submitted data to us, contact us and we will delete it promptly.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be notified by email if you are a registered user, or by a prominent notice on this page. The “Last updated” date at the top reflects the most recent revision. Continued use of Faro after a change constitutes acceptance of the updated policy.

10. Contact

Questions about this policy or your data: hello@byfaro.ai

Faro · byfaro.ai