Privacy Policy
A plain-language summary, provided for convenience. The numbered sections below are the policy.
- Most of what DepthFinder handles is business data — domains, pages, search queries and performance figures. The personal information we hold is mostly account, login and billing details.
- We set no cookies. Our website uses cookieless, aggregated analytics that cannot identify you or follow you to other sites; we use no advertising, session-recording or cross-site tracking tools. There is nothing to opt out of.
- We do not sell personal information, we do not share it for advertising, and we do not use your data to train AI models.
- If you ask us for access before you are a customer, we use it only to consider the request and reply — and if we can't offer access right away, we keep it so we can offer it later. It does not put you on a marketing list.
1. Who we are
This Privacy Policy explains how Tangent49 Inc., carrying on business as DepthFinder ("DepthFinder", "we", "us"), collects, uses, discloses, and protects personal information in connection with the DepthFinder application at https://app.depthfinder.ai/ and the website at https://depthfinder.ai (together, the "Service").
DepthFinder is a search-visibility and AI-visibility analytics product for businesses. It connects to a customer's Google Search Console property, combines that data with third-party search data, and produces interpreted findings and recommendations.
Contact: Tangent49 Inc., carrying on business as DepthFinder 23 Alhambra Ave, Toronto, Ontario M6R 2S4, Canada privacy@depthfinder.ai
Privacy Officer: Adam Day, Chief Executive Officer, DepthFinder — privacy@depthfinder.ai. The Privacy Officer is responsible for our compliance with this Policy and with applicable privacy laws, and is the person to contact with any privacy question, request, or complaint.
This Policy applies to our customers, their team members who use the Service, visitors to our website, and anyone who contacts us. It applies alongside our Terms of Service.
2. What this Policy covers, and what it doesn't
Most of the data DepthFinder handles is business data: website domains, page URLs, search queries, and performance metrics such as impressions, clicks, and average position. That data belongs to our customers and is governed by our Terms of Service. This Policy covers personal information — information about an identifiable individual — which in DepthFinder is mostly account, login, and billing information about the people who use the Service, the details someone sends us when they ask for access before becoming a customer, plus the limited cases described in §4 where business data may incidentally include personal information.
3. Personal information we collect
Access requests. When you ask for access through the form on our website, we collect your name, your work email address, the website you would like us to look at, and anything you choose to tell us about what you are hoping to figure out. We use it to assess the request and to reply to you. If we cannot offer you access right away, we keep your request so that we can offer it to you when capacity opens; if you would rather we didn't, tell us and we will delete it sooner. We do not use it for marketing, and asking for access does not put you on any list. The request reaches us by email, delivered through Resend and received in our business email operated by Google Workspace (see §8).
Account information. Name, work email address, password (stored as a salted hash), company name, and role, when you create an account or are invited to a workspace by a customer.
Google account information. When you connect a Google Search Console property, Google provides us with the email address of the Google account used and an authentication token. We store the token so that we can retrieve Search Console data on your behalf until you disconnect. We do not receive your Google password.
Billing information. Billing name, billing address, tax identification number where relevant, and transaction history. Payment card details are collected and stored by our payment processor, Stripe. We never see or store your full card number. We receive a card brand and last four digits for display.
Support and correspondence. Anything you send us by email or through the Service, and our replies.
Technical information. IP address, browser type, and request information collected in server logs operated by us and our hosting providers. We use this for security and debugging. On our website we use Vercel Web Analytics and Speed Insights, a cookieless measurement tool operated by our hosting provider. It records page views and page-performance timings together with the page URL, referrer, approximate location, and device, browser and network type; visitors are counted using a hash derived from the incoming request, which is discarded after 24 hours. It sets no cookies, stores nothing in your browser, and cannot identify you or follow you to other websites. We do not use session-recording or advertising tools, and we do not track how you use the Service.
Information from customers about their team. When a customer invites a team member, we receive that person's name and email address from the customer. The customer is responsible for having the right to share it.
We collect this information directly from you, from the customer that invited you, from Google when you connect a property, and from Stripe in connection with payments. We do not buy personal information from data brokers.
4. Google Search Console data
This section describes how DepthFinder uses data obtained through Google APIs. DepthFinder's use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
What we access. With your permission, DepthFinder requests read-only access to your Google Search Console data (the webmasters.readonly scope). Through this access we retrieve: the list of Search Console properties you can access, and, for each property you connect, search performance data — search queries, pages, dates, impressions, clicks, click-through rate, and average position. We do not retrieve any other Search Console data, we do not request access to any other Google service, and we cannot change your Search Console settings or your website.
Why we access it. We use Search Console data solely to provide the Service to you: to analyze your site's search performance, identify trends and opportunities, benchmark against market data, and generate findings and recommendations that we show to you and your team in your workspace. We do not use it for advertising, and we do not sell it.
Who sees it.
- You and your team. Search Console data is shown within the workspace it was connected to, to the customer and its authorized team members.
- Our infrastructure providers. It is stored and processed on servers operated by our hosting providers (see §8).
- AI model providers. To generate findings and recommendations, we send relevant portions of your Search Console data — such as queries, pages, and performance figures — to AI model providers (currently Anthropic and OpenAI) through their commercial APIs. These providers process the data to return a response and do not use it to train their models. See §8.
- Third-party search-data provider. To obtain market and competitive data, we send selected search-query text to our search-data provider (currently DataForSEO). We do not send your identity, your domain, your page URLs, or any of your Search Console performance figures to this provider. The queries we send are chosen because they appeared in your Search Console data, so a query list is derived from your data even though each individual query is a generic search term. Separately, to measure how your brand appears in search and AI results, we send your brand name to this provider.
- No one else. We do not disclose Search Console data to any other third party except as required by law (§9).
How long we keep it.
- Raw API responses from Google are deleted no later than 90 days after retrieval.
- Processed search performance history is kept for as long as your workspace is active, because the trend history is part of the product.
- All Search Console data for a workspace is permanently deleted 60 days after the subscription ends, or within 30 days of a verified deletion request, whichever is earlier.
- If you disconnect a property, we stop retrieving new data immediately and delete the stored authentication token. Previously retrieved data remains in the workspace until deleted under the rules above or at your request.
Revoking access. You can disconnect a property in the Service at any time. You can also revoke DepthFinder's access from your Google Account permissions page.
Personal information in search queries. Search Console data consists of the search terms people typed into Google before reaching your site. Google removes most queries that could identify a person, but a query may occasionally contain something like a person's name or an address. DepthFinder does not seek this information, cannot filter it at the source, and does not use it to identify or profile anyone. We treat any such content as part of your business data, handle it under this section, and delete it on the same schedule. If you notice a query in your workspace that you believe contains someone's personal information and want it removed, contact the Privacy Officer.
No model training. We do not use Search Console data, or any other customer data, to train or fine-tune artificial-intelligence or machine-learning models, and the commercial terms under which we use our AI providers prohibit them from doing so.
5. How we use personal information
We use personal information to:
- assess a request for access to the Service and reply to the person who made it;
- create and administer your account and workspace, authenticate you, and let you and your team use the Service;
- retrieve, store, and analyze data from the Google Search Console properties you connect, and generate findings and recommendations;
- process payments, calculate and collect taxes, issue invoices and receipts, and manage subscriptions;
- send you service messages — account confirmations, password resets, billing notices, security alerts, and notices about changes to the Service or these documents;
- send you product news or marketing email, only where you have consented or where the law otherwise permits, and always with an unsubscribe link (see §10);
- respond to your questions and provide support;
- monitor, secure, debug, and improve the Service, and prevent fraud, abuse, and unauthorized access;
- comply with our legal obligations, enforce our Terms, and protect our rights; and
- create aggregated, de-identified data as described in §7.
We collect and use personal information with your consent, which you give by requesting access, creating an account, connecting a property, or otherwise providing information for a stated purpose. Where consent is not the applicable legal basis, we rely on the need to perform our contract with you, our legitimate business interests as described above, or legal obligation. We do not use personal information for any purpose that is not described in this Policy without telling you and, where required, getting your consent.
6. Automated decision-making
DepthFinder's findings and recommendations are generated automatically, including by AI systems. They are about websites and search performance, not about individual people, and they do not produce legal or similarly significant effects on any individual. We do not use personal information to make automated decisions about you.
7. Aggregated and de-identified data
We may create data that is derived from customer data and Service usage but that has been aggregated across customers and de-identified so that it does not identify any customer, team member, website, or individual. We use this data to operate, benchmark, and improve the Service and to publish general insights about search and AI visibility. We do not attempt to re-identify it, and we do not sell aggregated data that could be linked back to a customer or individual.
8. Service providers and where your data goes
We use a small number of service providers to run DepthFinder. Each is bound by contract to use the data we share only to provide its service to us, to protect it, and not to use it for its own purposes. Our service providers process data in the United States and, in the case of our search-data provider, the European Union.
| Provider | What they do for us | What they receive | Location |
|---|---|---|---|
| Railway | Application hosting and database | All Service data, including account information and Search Console data, at rest | United States |
| Vercel | Web application hosting and website analytics | Data in transit through the application; IP addresses and request logs; cookieless, aggregated page-view and performance data from our website | United States |
| Google (Google Cloud / Search Console API) | Authentication and source of Search Console data | Google account email and OAuth token | United States |
| Anthropic | AI model provider (analysis and classification) | Search-query text and the related performance figures needed to generate a finding; no account or billing information | United States |
| OpenAI | AI model provider (text embeddings) | Search-query and topic text only; no performance figures, account, or billing information | United States |
| DataForSEO | Search and market data | Selected search-query text and brand names; no identity, domain, URLs, or performance data | European Union |
| Stripe | Payments, invoicing, and tax calculation | Billing name, billing address, email, tax ID, payment card details (Stripe only) | United States |
| Resend | Transactional email delivery | Email address and message content for password resets, account emails, and access requests made through our website | United States |
| Google (Workspace) | Business email | Support correspondence and access requests sent to our @depthfinder.ai addresses | United States |
We keep this list current at depthfinder.ai/subprocessors and will notify customers by email at least 30 days before adding a new provider that will process customer data.
AI providers. We use Anthropic's and OpenAI's commercial APIs. Their commercial terms provide that neither provider uses data we send to train their models, and that API inputs and outputs are deleted from their systems within 30 days by default; content flagged for trust-and-safety review may be retained longer under their policies. We send only the data needed to generate a given finding.
Cross-border transfers. Because our providers are outside Canada, personal information and customer data leave Canada. Account, billing, and Search Console data are stored and processed in the United States; selected search-query text and brand names are processed in the European Union. While outside Canada, data is subject to the laws of the jurisdiction where it is processed and may be accessible to authorities there under those laws. We use contractual protections, encryption in transit and at rest, and access controls to protect data wherever it is processed, and we have assessed the privacy impact of these transfers as required by applicable Canadian law.
9. Other disclosures
Apart from service providers, we disclose personal information only:
- to your team: your name and email are visible to other members of your workspace;
- when required by law: in response to a valid court order, subpoena, or other legal process, or where we believe disclosure is necessary to comply with the law, protect the safety of any person, or investigate fraud or security issues. We will notify you where the law permits;
- in a business transaction: if DepthFinder or Tangent49 Inc. is involved in a merger, acquisition, financing, or sale of all or part of its business, personal information may be disclosed to the parties involved and transferred to the successor, who will be bound by this Policy or one that offers equivalent protection. We will notify affected customers; or
- with your consent.
We do not sell personal information and we do not share it for advertising.
10. Email and marketing
We send service emails that you cannot opt out of while you have an account, such as password resets, billing receipts, and security or legal notices. These are sent through Resend.
If you ask us for access, our reply is a response to your enquiry, not marketing email. We do not add you to a marketing list because you asked for access, and we will send you marketing email only if you expressly opt in — even where anti-spam law would allow us to email you without it. If you later become a customer, the next paragraph applies to you like any other customer.
We send marketing emails — product updates, tips, and offers — only if you have consented, or where Canada's anti-spam legislation otherwise permits (for example, to an existing customer about related products). Every marketing email identifies Tangent49 Inc. o/a DepthFinder, includes our contact information, and includes an unsubscribe link that works within 10 business days. We keep a record of your consent and any unsubscribe request.
11. Cookies and tracking
The Service sets no cookies. To keep you logged in, an authentication token is stored in your browser's local storage. It is sent only to our Service, is not readable by other websites, and is not a tracking technology. It is removed when you log out.
We use no analytics cookies, advertising cookies, tracking pixels, session recording, or cross-site tracking technology. The website analytics described in §3 is cookieless: it stores nothing in your browser, and it produces aggregate counts rather than a profile of you. If that changes, we will update this Policy and, where required, ask for your consent before setting non-essential cookies.
Because we store nothing in your browser and build no profile of you, we do not respond differently to "Do Not Track" browser signals; there is nothing to turn off.
12. Your rights and choices
Depending on where you live, you may have some or all of the following rights. We offer all of them to everyone whose personal information we hold, regardless of location.
- Access. Ask us what personal information we hold about you, how we use it, and who we have disclosed it to.
- Correction. Ask us to correct personal information that is inaccurate or incomplete. You can update most account information yourself in your settings.
- Deletion. Ask us to delete your personal information and close your account. We will do so within 30 days of verifying your request, except for information we must keep by law (for example, billing records) or that we keep in de-identified form.
- Portability. Ask us for a copy of the personal information you provided to us, and of the data you provided and the processed data in your workspace, in a structured, commonly used, machine-readable format. We will provide it within 30 days. Exports do not include raw third-party API responses or internal model artifacts.
- Withdraw consent. Withdraw your consent to our collection, use, or disclosure of your personal information, subject to legal or contractual restrictions. Disconnecting a Google property withdraws consent to further collection from it. Withdrawing consent needed to run your account may mean we can no longer provide the Service.
- Marketing opt-out. Unsubscribe from marketing email at any time using the link in any such email or by contacting us.
To exercise any right, email the Privacy Officer at privacy@depthfinder.ai. We will confirm your identity before acting, respond within 30 days, and tell you if we need more time and why. There is no charge for a first request. If we refuse a request in whole or part, we will tell you why and how to challenge our decision.
Team members. If you use DepthFinder as a member of a customer's workspace, the customer controls your workspace account. We may direct requests about your account information to that customer, and will assist as needed.
13. Complaints
If you have a concern about how we handle your personal information, please contact the Privacy Officer first at privacy@depthfinder.ai. We take every complaint seriously, will acknowledge it within 5 business days, investigate, and respond in writing within 30 days.
If you are not satisfied with our response, you may complain to the privacy regulator with jurisdiction over you:
- Office of the Privacy Commissioner of Canada — priv.gc.ca — 1-800-282-1376
- Commission d'accès à l'information du Québec (if you are located in Quebec) — cai.gouv.qc.ca
- Your provincial privacy commissioner, or your state attorney general or national data protection authority, as applicable.
14. How long we keep personal information
| Information | Retention |
|---|---|
| Account and profile information | Life of the account, then deleted within 60 days of account closure (30 days on verified request) |
| Google authentication tokens | Until you disconnect the property or close your account, then deleted immediately |
| Search Console data | See §4 |
| Billing records and invoices | 7 years after the transaction, as required by Canadian tax law |
| Access requests that do not become accounts | 12 months from the request, then deleted |
| Support correspondence | 2 years after the ticket is closed |
| Server logs | 30 days |
| Marketing consent and unsubscribe records | 3 years after the last interaction, as required by anti-spam law |
| Breach records | 2 years after the incident, as required by PIPEDA |
| Records of deletion (workspace identifier, workspace name, deletion date, counts of records destroyed) | Retained indefinitely as proof of destruction; contain no Search Console data or personal information |
When retention ends we delete or irreversibly anonymize the information. Backups are overwritten on our hosting provider's four-week rotation cycle, so deleted data may persist in backups for up to four weeks after deletion. Background-job records may briefly reference a workspace identifier and related job parameters after deletion; they are limited in number, purged on a best-effort basis at deletion time, and are never accessible to any user.
15. Security
We protect personal information with measures appropriate to its sensitivity, including: encryption in transit (TLS) and at rest; hashed and salted passwords; OAuth-based access to Google with read-only scope and no password storage; role-based access controls so that team members see only their workspace; least-privilege access for our staff and contractors, who are bound by confidentiality obligations; logging and monitoring of access to production systems; and vendor review before we engage a new service provider.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at privacy@depthfinder.ai.
Breach notification. If we discover a breach of security safeguards involving your personal information that creates a real risk of significant harm to you, we will notify you and the applicable privacy regulator as soon as feasible, describe what happened and what we are doing, and keep a record of the incident as required by law. Where the affected data belongs to a customer's workspace, we will notify the customer so that it can meet its own obligations.
16. Privacy by default
New accounts and workspaces are configured with the most privacy-protective settings by default: no marketing email unless you opt in, no analytics or tracking cookies, read-only Google access, and workspace data visible only to invited team members. You do not need to change any setting to receive these protections.
17. Children
The Service is for businesses and is not directed to individuals under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have, contact the Privacy Officer and we will delete it.
18. Changes to this Policy
We may update this Policy from time to time. If we make a material change — in particular, any change to how we use Google Search Console data, any new category of disclosure, or any new purpose for using personal information — we will notify account holders by email and post a notice in the Service at least 30 days before the change takes effect, and where the law requires it we will ask for your consent. The "Last updated" date at the top shows when the Policy last changed, and prior versions are available on request.
19. Contact
Privacy Officer: Adam Day, Chief Executive Officer Tangent49 Inc., carrying on business as DepthFinder 23 Alhambra Ave, Toronto, Ontario M6R 2S4, Canada privacy@depthfinder.ai