Privacy Policy
What we collect, why we collect it, who else touches it, and how to have it deleted.
Last updated 8 September 2026.
Who controls your data
SPARKX TECH, a sole proprietorship registered in Hong Kong (Business Registration No. 41707724), trading as GeoShark, is the data controller. Reach us about anything on this page at hello@geoshark.io.
What we collect
- Account details. Your name and email address, through Google sign-in. We never see your Google password.
- What you set up. The domains you track, the competitors you name, and the questions in your prompt set.
- What a run produces. The answers the engines gave, the pages they cited, and everything derived from them — scores, sources, sentiment and recommendations.
- Billing details. Handled by Stripe, our payment processor. We store your plan and a Stripe customer reference; we never see or store your card number.
- Product analytics. Aggregate counts of a few events, with no identity attached — enough to know whether a screen is used, not who used it.
What we do not collect
We do not read your email, your CMS, your analytics or your advertising accounts. GeoShark never asks for access to a client's website: it reads the same public pages anyone can, and the answers the engines give.
Why we process it
- To run the service you are paying for — collecting answers, storing runs, producing reports.
- To take payment and to tell you about your subscription.
- To keep the service working and secure, and to fix what breaks.
- To send you a small number of service emails. We will not add you to a marketing list you did not ask for.
Who else processes it
Running GeoShark means a handful of other companies touch your data. Each one is used for one job:
- Vercel — hosting the application and storing report files.
- Neon — the database your brands and runs live in.
- Stripe — payment processing and subscription management.
- DataForSEO — collecting the answers from the AI engines.
- Google — sign-in (your name, email address and profile picture).
- Google (Gemini API) — reading answers to classify sources, claims and how a brand is described.
We do not sell your data, and we do not use one customer's runs to produce another customer's report.
How long we keep it
Runs are kept for the history window your plan carries — 14, 30 or 90 days on the paid plans — and are removed after that. Account and billing records are kept while your account is open and for as long afterwards as we are required to keep them. Ask us to delete your account and we will remove your brands, runs and reports.
Your rights
You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Write to hello@geoshark.io and we will answer within 30 days.
Where your data is held
In the United States. The database is hosted on Neon in AWSus-east-1 (Northern Virginia), and the application and its stored report files run on Vercel in the same region. The processors listed above may handle data in other countries under their own terms — Stripe, Google and DataForSEO each operate internationally.
If you are in the United Kingdom or the European Economic Area, using GeoShark means your data is transferred outside it. Those transfers rest on the standard contractual clauses each of the processors above publishes; we do not move your data anywhere they do not cover.
Cookies
We use the cookies needed to keep you signed in and to remember whether you chose the light or dark theme. We do not run advertising trackers.
Changes
If we change this policy in a way that affects you, we will say so before it takes effect.