Privacy Policy
Last updated: 2 August 2026
This Privacy Policy explains what personal data LLMBOO collects, why we collect it, and the choices you have. We have written it to describe what we actually do — not generic boilerplate. LLMBOO is a cookieless product: we do not use tracking cookies, cross-site tracking, ad networks, or advertising profiles.
LLMBOO measures how often AI assistants recommend a brand, diagnoses gaps, and generates suggested fixes. To be clear about scope: we do not control the AI systems we query, and we do not guarantee any ranking, recommendation, traffic, or sales outcome. This policy is about your data, not results.
1. Who we are (Data Controller)
The controller responsible for your personal data is:
- Legal entity: Piruz Afruz, MB, a Lithuanian small partnership (mažoji bendrija), registration code 306655229 (not VAT-registered)
- Registered address: Laisvės pr. 60, LT-05120 Vilnius, Lithuania
- Contact for privacy questions: hello@llmboo.com
If you have any question about this policy or want to exercise your rights, email us at hello@llmboo.com.
2. What we collect and why
(a) Product analytics — cookieless
Our internal analytics ("war room") is first-party and cookieless. We do not set tracking cookies, we do not track you across other websites, and we do not use ad networks. For visits to our site we store:
- Page views
- Referrer (the site or link you arrived from)
- UTM parameters (campaign tags in the link you clicked)
- Funnel events (for example: scan started, lead captured, paid)
- Country, derived from your IP address using a local, offline GeoIP database (MaxMind / geoip-lite) that runs on our own servers
Your IP address is used transiently to derive an approximate country and is not sent to any third party for geolocation. We store the resulting country, not a profile of you.
Legal basis: our legitimate interest in understanding how our product is used, keeping it secure, and measuring public brand visibility.
(b) Free scanner inputs (and optional email)
When you use the free scanner, you submit a brand name and a category, and optionally a URL. To measure how AI assistants respond, these queries are sent to third-party AI providers (OpenAI, Anthropic, Google, and Perplexity) — see the subprocessors table below. If you choose to provide an email address to receive a report, we store that email so we can send it to you.
Legal basis: your consent — you provide it when you submit the scan, and separately when you ask us to email you a report. We rely on that consent to run the scan you requested and to send your report.
Separately — aggregate visibility research: where we use de-identified, aggregated scan results to study how brands appear across AI assistants, the legal basis for that distinct purpose is our legitimate interest in producing that aggregate research, balanced against your rights.
(c) "Claim your business" submissions
When you submit the claim form, we store the information you provide: your name, email address, your chosen monthly plan budget, and your message.
Legal basis: steps taken at your request prior to entering into a contract — namely handling and responding to your claim enquiry.
(d) Billing and payments
Paid subscriptions are processed by Stripe. Your card details are entered into and handled by Stripe; they are not stored on LLMBOO servers. We receive limited billing information from Stripe (such as your subscription status and the fact that a payment succeeded or failed) so we can provide the service.
Legal basis: performance of our contract with you, to provide the paid service; and, as a separate purpose, compliance with our legal obligations, to keep the billing and tax records we are required by law to retain.
(e) Transactional email
We use Postmark to send transactional emails, such as your scan report, receipts, and account or service notices. To do this we share the recipient email address and message content with Postmark.
Legal basis: performance of our contract with you — sending the receipts, account, and service notices that are part of providing the paid service you signed up for.
3. Legal bases (GDPR / UK GDPR)
Where the EU General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to deliver the paid service you signed up for.
- Legitimate interests — for product analytics, security, and measuring public brand visibility, balanced against your rights.
- Consent — where required, for example when you submit a scan or ask us to email you a report. You can withdraw consent at any time.
- Legal obligation — where we must retain records, such as for tax and accounting.
4. Subprocessors
We use a small number of trusted service providers to run LLMBOO. Each processes personal data only as needed for the purpose shown.
| Subprocessor | Purpose | Region |
|---|---|---|
| Hetzner | Hosting and infrastructure | Germany (EU) |
| Postmark (Wildbit) | Transactional email | United States |
| Stripe | Payment processing | United States / Ireland |
| OpenAI | AI query processing (recommendation measurement) | United States |
| Anthropic | AI query processing (recommendation measurement) | United States |
| AI query processing (recommendation measurement) | United States | |
| Perplexity | AI query processing (recommendation measurement) | United States |
5. Where your data is stored and international transfers
Our application and analytics are hosted on Hetzner infrastructure in Germany, giving EU data residency for the data we store ourselves. Some subprocessors are located in the United States (see the table above). Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), and, where applicable, the EU-US Data Privacy Framework.
6. How long we keep data (retention)
These are the retention periods we apply:
- Analytics events (page views, referrer, UTM, funnel, country): retained for about 12 months, after which they are aggregated and anonymised so that no individual record remains.
- Scanner inputs and reports: retained for about 12 months, unless you ask us to delete them sooner.
- Claim submissions and lead emails: retained for about 12 months, unless you ask us to delete them sooner.
- Billing and tax records: retained for 6–10 years, as required by applicable tax and accounting law.
- Email addresses: retained until you unsubscribe or ask us to delete them, and in any case no longer than about 12 months after our last contact for scanner and lead emails.
You can ask us to delete your data sooner — see your rights below.
7. Your rights
Depending on where you live, you have rights over your personal data. Under the GDPR and UK GDPR these include the rights to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Data portability (receive your data in a portable format)
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Withdraw consent at any time, without affecting processing already carried out
To exercise any of these rights, email hello@llmboo.com. You also have the right to lodge a complaint with your local data protection authority.
8. California privacy (CCPA)
If you are a California resident, you have the right to know what personal information we collect, to request access to or deletion of it, and to not be discriminated against for exercising your rights. We do not sell your personal data, and we do not share it for cross-context behavioural advertising. To make a request, email hello@llmboo.com.
9. Security
We take reasonable technical and organisational measures to protect your data, including EU-based hosting, encryption in transit, restricted access, and reliance on established providers (such as Stripe for payments, so we never store card details). No method of transmission or storage is completely secure, but we work to protect your information and to limit what we collect in the first place.
10. Children
LLMBOO is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact hello@llmboo.com and we will delete it.
Two different age figures appear across our documents, and they are not the same thing: our Terms of Service require you to be at least 18 to enter into a contract and hold an account (a contractual-capacity requirement), whereas the 16 referred to here is the GDPR threshold below which we will not process a child's personal data. One is about who can form a binding contract; the other is about whose data we may process.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Please check back periodically.
12. Contact
For any privacy question or request, contact:
- Piruz Afruz, MB
- Laisvės pr. 60, LT-05120 Vilnius, Lithuania
- hello@llmboo.com
- Governing law / jurisdiction: the laws of the Republic of Lithuania; courts of Vilnius, Lithuania