Legal
Privacy Policy
Effective July 10, 2026
Who this policy covers
“We” means Daily AI Agents LLC, a Texas limited liability company operating usedailyai.com. This policy explains the personal data we process when you visit the site, contact us, book a call, join the email list, purchase a product, or previously requested an AI-visibility scan.
Questions or privacy requests: support@usedailyai.com.
What we collect and why
- Email and contact details. We use details you submit to deliver what you requested, reply, manage an ongoing plan, perform basic fraud and abuse checks, and keep records required for purchases.
- Consulting inquiry data. A calendar or email inquiry may include your name, company, message, scheduling details, and any material you choose to share. We use it to evaluate and deliver the requested work.
- Purchase data. Mercury or Gumroad processes payment data. We do not receive or store full card numbers. We may receive transaction metadata such as buyer email, product, amount, and time so we can deliver and support the purchase and maintain accounting records.
- Newsletter data. Beehiiv processes the email address and delivery activity needed to deliver the newsletter and honor removal requests.
- Historical scan data. If you previously requested an AI-visibility scan, we may hold the submitted domain, prompts, email, captured public answers, fetched public pages, and rendered report under the retention commitments below.
- Aggregate redirect attribution. A first-party
/go/redirect may record a timestamp, campaign, source and medium, coarse bot/mobile/desktop class, and a referring page shortened to 120 characters. The redirect does not store an email with the click, store the raw user-agent string, or set an application cookie. - Hosting logs. Cloudflare may process standard request information, including IP address and user agent, to secure and deliver the site under its own policy. We do not export those logs into an advertising profile.
What we do not do
- We do not place third-party advertising pixels or ad-network scripts on the static pages we serve.
- We do not sell personal data or share it for cross-context behavioral advertising.
- We do not enroll you in the newsletter unless you submit or confirm the signup.
- We do not use redirect records to build a per-person advertising profile.
Calendaring, payment, newsletter, and social destinations run on third-party domains. Those providers apply their own privacy and cookie policies when you leave usedailyai.com.
Retention
- Historical scan request data and reports: 12 months, then deleted, or earlier on a verified request, subject to the limited public-evidence exception below.
- First-party redirect records: configured for 90-day expiry.
- Newsletter email: while enrolled, subject to provider suppression records needed to honor a removal request.
- Transaction records: seven years, unless a longer legal hold applies.
- Consulting inquiries: 24 months, then deleted.
- Backups and security logs in systems we control: configured for no more than 90 days. Provider-managed logs follow the provider’s policy.
Deletion and access requests
Email support@usedailyai.com from the address associated with the data. If you no longer control it, include enough information for us to verify the request, such as a transaction or historical scan request ID.
- We verify that the request comes from the data subject or an authorized representative.
- We respond within 30 days and delete or provide the personal data in systems we control, unless law requires retention.
- Where a processor holds the data on our behalf, we submit the corresponding request there and describe the outcome.
- We identify anything retained, the reason, and the expected deletion date.
Payment processors and other providers may retain records under their own legal obligations. Deleted data may remain in a rotating backup until that backup expires.
Service providers
| Provider | Data | Purpose |
|---|---|---|
| Cloudflare | Site requests, redirect attribution, and historical form records | Hosting, security, and request handling |
| Email you send and email we send | Founder-operated email | |
| SendGrid | Historical transactional-email delivery records | Transactional delivery |
| Mercury | Invoice and payment metadata | Service invoicing |
| Gumroad | Digital-product purchase data | Payment and product delivery |
| Beehiiv | Newsletter email and delivery data | Newsletter delivery |
| Cal.com | Scheduling details you submit | Call scheduling |
Security
We limit access to the founder and service credentials needed for a bounded task, use multi-factor authentication where a provider supports it, and keep credentials in a password or secrets manager. No transmission or storage system can be made completely secure. If a breach triggers a legal notification duty, we will notify affected people and regulators as required by applicable law.
Historical scan commitments
- A submitted domain, prompts, requester identity, and private report are not published without explicit prior permission.
- After the 12-month window, a verification dataset may retain only evidence drawn from public web content: checked claim text from a public answer, cited public URL, fetched public-page evidence, and support verdict. It excludes requester email, requester identity, and submitted prompt text.
- You may ask us to remove scan-derived public-evidence rows about your domain as part of a deletion request.
Children
Our services are for businesses and are not directed to children under 18. We do not knowingly collect personal data from children.
Changes
We post changes here and update the effective date. If a material change affects what we collect, how long we retain it, or how a provider processes historical scan or paid-service data, we will provide notice when required by law or an existing customer commitment.