Legal
Privacy Policy
Last updated: September 16, 2026
This Privacy Policy describes how Superstellar LLC, operating as Serge, collects, uses, discloses, and protects personal data when you visit serge.ai or use our platform. It applies to all users worldwide. If anything is unclear, contact us at privacy@serge.ai.
Advertising measurement
Allow Serge to share confirmed actions and available ad click references with OpenAI to measure our ads. Optional; you can change this on the Privacy page.
Who we are
- Serge is operated by Superstellar LLC (“we”, “us”, “our”), registered office at Baarerstrasse 52, 6300 Zug, Switzerland, registered in the Commercial Register of the Canton of Zug.
- Controller — Superstellar LLC is the controller for account administration, billing, service security and its own website. For Customer-directed processing of campaign materials, website content and visitor data, our role depends on who determines the purposes and means of that processing; where we process on the Customer’s documented instructions, we act as its processor.
- Processor — When a Customer installs the Serge tracking snippet on a Customer-owned site, the Customer is the data controller for the resulting visitor data and Superstellar acts as the data processor on the Customer's behalf. A Customer Data Processing Agreement, compliant with GDPR Art. 28 and the Swiss Federal Act on Data Protection (nFADP), is available on request to legal@serge.ai.
- For all privacy inquiries, contact us at privacy@serge.ai.
- Company identification and Swiss VAT number — CHE-433.879.620 MWST.
Information we collect
- Scan data — When you scan a domain, we crawl publicly-available resources (homepage, robots.txt, sitemap.xml, llms.txt, OpenAPI specs, structured data on the page) and store the resulting check results, scores, and domain.
- Account data — When you sign up for a Serge account (via Clerk), we receive your email address, name, and any additional OAuth claims you authorise from your chosen identity provider. We use this to bind the account to a workspace.
- Workspace data — Workspaces hold the sites you register, snippet site IDs, invited members, billing state, and per-workspace configuration. We process this to operate the Service.
- Snippet event data — When a Customer installs Serge's tracking snippet (serge.js), the snippet sends agent-detection events, page-path and referrer metadata, browser/device signals, and client-side classification results to our ingestion API; it does not transmit form values. Standard mode uses sessionStorage for a per-tab session ID and short-lived caches, and may read allowlisted campaign parameters (utm_* and advertising click identifiers such as gclid or msclkid) plus an advertising platform's own first-party click-reference cookie where present. Storage-free mode, selected with data-privacy=storage-free, performs no cookie, localStorage, or sessionStorage read or write; its session ID exists only in page memory. In either mode, when request IP and User-Agent are available, our server truncates the IP address (/24 for IPv4, /64 for IPv6) and combines those inputs to derive a daily-rotating pseudonymous visitor hash scoped to that Customer workspace and site; the application does not place the raw IP address in analytics event tables, create a cross-site identifier, or combine visitors into cross-site behavioural profiles. With require-consent enabled, the snippet holds network measurement while the choice is unknown; a denial switches it to storage-free measurement rather than disabling measurement. The Customer must choose the appropriate mode, legal basis, notices, and consent or objection mechanism for its deployment. Storage-free describes device behavior and is not, by itself, a legal-compliance determination.
- Replay session data — When you dispatch an active replay under Investigate Mode against a URL under your direction, we capture the agent's reasoning, navigation steps, DOM snapshots, screenshots, accessibility-tree snapshots, and network metadata for that single session. Replays do not capture data from sessions other than the one you initiated.
- Email addresses — When you request a full scan report or sign up for a Serge account, we collect your email address. This is PII.
- Billing data — Stripe processes payment details, billing names and addresses, and business tax identifiers where provided. We process the customer and subscription identifiers, invoice and payment records and billing information needed to administer the purchase and meet accounting obligations. We do not receive or store full payment-card numbers.
- Technical and usage data — Request IP addresses are processed for security and rate limiting and, for snippet traffic where request IP and User-Agent are available, the IP is truncated (/24 for IPv4, /64 for IPv6) and those inputs are combined to derive the daily-rotating workspace-and-site-scoped pseudonymous hash described above. Browser and device information and error data are processed for service operation and debugging via Sentry, with directly identifying fields scrubbed before transmission where configured.
- Customer-directed processing — When a Customer submits a domain or URL as a scan target or as a replay target via Investigate Mode, the Customer directs us to crawl publicly-available resources at that target. Any personal data incidentally present in those resources (visitor reviews, agent reasoning that quotes target content, third-party page content) is processed under the Customer's direction; the Customer remains the controller for any further use of that data and is responsible for the lawfulness of the target submission under our Acceptable Use Policy.
- Snippet URL hygiene — The Customer is responsible for ensuring that pages where the Customer installs the Serge tracking snippet do not expose personal data in URL paths or query parameters, and for stripping sensitive parameters before snippet events are emitted. The Customer remains the controller of its visitors' personal data and is responsible for lawful collection, including any cookie / consent disclosure required on the Customer's own site.
- Advertising data — We process business and brand profiles, website content and images you supply or ask us to retrieve, campaign objectives, audience notes, markets, budgets, creatives, drafts, approvals, connected advertising-account identifiers and permissions, encrypted credentials, and platform status and performance reporting. We also record the wording and version of your pre-checkout eligibility acknowledgement, your account identifier, the time, language and quoted subscription amounts to document the transaction.
- AI-assisted preparation — Anthropic receives the website excerpts, business facts, images where supported, audience notes and creative instructions needed to extract a brand profile or generate a campaign recommendation. Those materials can contain personal data if you include it or it appears on the source website. Do not submit sensitive personal data or confidential material you are not authorised to share. Generated profiles and campaign drafts are saved in your workspace.
- Google Search Console — If you connect Google, we access the available website properties and aggregate search-query reports for the property you select. We store an encrypted refresh token so reports can be loaded when you use Customer Journeys. We do not obtain individual visitors’ Google searches or AI prompts through this connection.
How we use your information
- Service delivery — We process the information described above to provide website analysis, campaign preparation, connected-account operations, reporting and the other features you request. For individuals contracting with us, the GDPR basis is performance of contract (Article 6(1)(b)); for Customer representatives and team members, it is our legitimate interest in providing and administering the Customer’s service (Article 6(1)(f)). Where we act as a processor, the Customer determines the lawful basis and our processing follows its instructions.
- Communication — We send requested reports, account messages, billing receipts, renewal reminders, service and sub-processor notices. These are service communications, not marketing consent. We use contract performance or our legitimate interest in administering the Customer relationship, as applicable. Marketing requires a separate lawful basis and, where required, your opt-in.
- Billing — Stripe processes your payment instrument and issues invoices; we process the minimum metadata needed to operate the subscription. Legal basis: performance of contract (Art. 6(1)(b)) and legal obligation for accounting records (Art. 6(1)(c)).
- Security and abuse prevention — We use IP-based rate limiting, audit logging, and replay-safety scanning to protect the platform, your data, and the third-party sites we crawl on your behalf. Legal basis: legitimate interest in platform security (Art. 6(1)(f)).
- Product improvement — We use anonymized, aggregated usage analytics to understand how people use Serge and to improve the product. Legal basis: legitimate interest (Art. 6(1)(f)), balanced against your privacy through strict anonymization.
- Legal compliance — We may process data to comply with applicable laws, respond to lawful requests from public authorities, or establish, exercise, or defend legal claims. Legal basis: legal obligation (Art. 6(1)(c)) or legitimate interest (Art. 6(1)(f)).
Data sharing and sub-processors
- We do not sell your personal data. With your separate advertising-measurement consent, Serge shares confirmed website actions, event identifiers and available advertising click references with OpenAI to measure our ads. You can withdraw this consent on this page. Other service data is shared with sub-processors to operate and maintain Serge.
- The current list of sub-processors that handle Customer data on our behalf — together with each sub-processor's role, location, and certifications — is published at https://www.serge.ai/subprocessors. As of this version it includes Vercel (application hosting), Neon (PostgreSQL database), Clerk (authentication), Anthropic (LLM API for replay reasoning and content moderation), Browserbase (managed headless browsers for replays), Fly.io (replay worker compute), Stripe (billing), Upstash (rate limiting and ephemeral caching), Sentry (error monitoring), Resend (transactional email), and Slack (operator handling of submitted support and feedback, and customer-directed briefing or alert delivery when separately enabled).
- Each sub-processor processes the minimum data necessary for its function and is bound by a data-processing agreement appropriate to its role.
- We will notify active customers at least 30 days before engaging a new sub-processor that processes personal data, giving you the opportunity to object before processing begins.
- Right to object — Notify privacy@serge.ai during the 30-day notice period if you object to a new sub-processor on data-protection grounds. We will consider an alternative in good faith. If no suitable alternative is available, you may terminate the affected service before the new processing begins, with a pro-rata refund of prepaid fees for the unused period after termination.
- Business transfers — In the event of a merger, acquisition, reorganisation, sale of substantially all of our assets, or insolvency, personal data may be transferred to the successor or acquiring entity, subject to this Privacy Policy or an equivalent updated policy. Where required by applicable law, we will notify affected users in advance and they will retain their rights described in this Policy.
- Connected advertising platforms — When you connect an account or request a campaign operation, we exchange the necessary account, creative, campaign, budget and reporting information with that platform. OpenAI processes advertising-service data under its own Advertising Terms and privacy notices; it is not simply a hosting sub-processor of Serge. Its privacy notice is at https://openai.com/policies/privacy-policy/. Your ChatGPT conversations are not made available to Serge through this advertising connection. Platform-held data remains subject to that platform’s retention and rights-request procedures after you disconnect Serge.
International data transfers
- Processing locations — Serge uses providers operating in the European Union and the United States; support, administrative systems and connected advertising platforms can process data outside the region of an application server. The provider-specific locations and transfer information are listed at https://www.serge.ai/subprocessors. Selecting an EU email sending region does not give Resend EU data residency: Resend stores customer data in the United States.
- EU and EEA transfers — Where a sub-processor is certified under the EU-US Data Privacy Framework (DPF) adopted by Commission Decision (EU) 2023/1795, we rely on its DPF certification as the primary transfer mechanism. For sub-processors not DPF-certified, or for transfers to other third countries, we rely on the European Commission's Standard Contractual Clauses (SCCs, Decision (EU) 2021/914).
- United Kingdom transfers — For transfers from the United Kingdom we rely on the UK Extension to the EU-US Data Privacy Framework for DPF-certified sub-processors, and the UK International Data Transfer Addendum to the EU SCCs (ICO IDTA) otherwise.
- Switzerland transfers — For transfers from Switzerland we rely on the Swiss-US Data Privacy Framework for DPF-certified sub-processors, and on the Swiss Federal Data Protection and Information Commissioner (FDPIC)-approved Standard Contractual Clauses otherwise.
- Supplementary safeguards — In addition to the legal-transfer mechanisms above, we apply technical and organisational measures appropriate to the data being transferred, including encryption in transit (TLS 1.2 or higher) and at rest, role-based access controls, audit logging, and Data Processing Agreements that flow GDPR Article 28 obligations to each sub-processor.
- Transfer safeguards — Applicable safeguards must cover the actual recipient and transfer, including any relevant Swiss adaptations or UK Addendum to the EU SCCs. We assess transfers and supplementary measures where required. Contact privacy@serge.ai for information about the safeguards applicable to your data.
- Copies of the applicable transfer mechanisms are available upon request at privacy@serge.ai.
Data retention
- Scan results — Scan scores, findings, and the submitted domain are retained indefinitely for benchmarking. Scans are associated with domains, not individuals. You may request deletion of scans you initiated by contacting privacy@serge.ai.
- Account and workspace data — Retained while your account is active and for up to 90 days after deletion to support reversal and audit.
- Snippet event data — Free and Pro workspaces retain analytics events for 12 months; Agency retains them for 24 months; an approved extended-retention override can retain them for up to 24 months.
- Replay session data — Free workspaces retain replay artifacts (screenshots, DOM snapshots, accessibility-tree snapshots, agent reasoning, network metadata) for 7 days; Pro retains them for 90 days; Agency retains them for 365 days.
- Support, contact, and feedback conversations — Local copies are retained for up to 24 months. When feedback linked to Slack is erased or expires, we retain only non-content provider locators until an operator verifies deletion in Slack.
- Email addresses — Retained for report delivery and account follow-up. You may request deletion at any time by contacting privacy@serge.ai.
- Transactional email delivery metadata — Recipient addresses, provider identifiers, delivery errors, and template metadata are retained for up to 90 days for retry and operational forensics, then deleted. Account erasure redacts attributable delivery-ledger rows immediately.
- Billing records — Stripe-stored billing data is retained per Stripe's own policy and our statutory accounting-record obligations (Swiss Code of Obligations art. 958f — typically 10 years).
- Audit and abuse logs — Replay-safety events and platform audit logs are retained for up to 12 months as described in our Acceptable Use Policy.
- Error-tracking data — Retained for 90 days via Sentry.
- Advertising records — Local brand profiles, campaign drafts, creative assets and connected-account records follow the account and workspace retention schedule, unless a more specific schedule applies. Disconnecting a platform stops future authorised use of the connection; it does not delete records at that platform. Eligibility acknowledgements in the application audit log follow the audit-log schedule. Payment and invoice records follow the billing-record schedule.
- Contract and legal-request records — Completed purchase confirmations and the accepted contractual text are retained for ten years from purchase for accounting evidence and legal claims, including after account deletion. Abandoned checkout snapshots are deleted after 30 days. Withdrawal and cancellation declarations, identity-verification evidence, decisions and delivery records are retained while unresolved and for two years after resolution. Access is restricted to authorised billing and legal operations. Requests involving a retained contract can be obtained through privacy@serge.ai after identity verification.
- Search Console connections — Disconnecting a project deletes its saved Google credential immediately. Cached query reports expire within five minutes and become inaccessible through that connection immediately after disconnecting. Google retains its own records under its policies.
Security measures
- Encryption — All data in transit is protected by TLS 1.2 or higher. Database storage is encrypted at rest via Neon’s managed encryption.
- Application security — We use access controls, security headers, input validation, rate limiting and monitoring to protect the Service. These controls reduce risk but do not guarantee that every incident can be prevented.
Security incidents and breach notification
- Incident response — We maintain an incident-response process to identify, contain, investigate, and remediate security incidents affecting personal data.
- Notification to authorities — Where the EU or UK GDPR applies, we notify the competent authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless it is unlikely to result in a risk to individuals’ rights and freedoms. Under Swiss FADP Article 24, breaches likely to result in a high risk to personality or fundamental rights are reported to the FDPIC as soon as possible. These legal thresholds and timing rules are distinct.
- Notification to data subjects — Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, we will notify affected data subjects without undue delay (GDPR Art. 34).
- Notification to Customers acting as controllers — Where Superstellar acts as processor on a Customer's behalf and a breach affects Customer-controlled data, we will notify the Customer without undue delay so that the Customer can comply with its own notification obligations.
Your privacy rights
- Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data. We honor these rights for all users regardless of location, to the extent permitted by applicable law.
- Right of access — You may request confirmation of whether we process your personal data and, if so, receive a copy of that data in a structured, commonly used format.
- Right to rectification — You may request correction of inaccurate personal data.
- Right to erasure — You may request deletion of your personal data.
- Right to restrict processing — You may request that we limit how we use your data while a dispute or request is being resolved.
- Right to data portability — You may request your data in a machine-readable format (JSON) for transfer to another service.
- Right to object — You may object to processing based on our legitimate interest.
- To exercise any of these rights, email privacy@serge.ai with your request. We will respond within 30 days.
- If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.
- Withdrawal of consent — Where we rely on consent, you may withdraw it at any time using the relevant preference control or by contacting privacy@serge.ai. Withdrawal does not affect processing already carried out lawfully. We may need to verify your identity proportionately before handling a rights request.
Additional rights for California residents
- Where the CCPA/CPRA applies, California residents may know, access, correct and delete covered personal information, opt out of sale or sharing, and exercise rights without unlawful discrimination. Meta Pixel can constitute sharing for cross-context behavioural advertising. It requires your opt-in. Global Privacy Control (GPC) overrides an earlier grant. Use Privacy settings in the footer or contact privacy@serge.ai; an authorised agent may also submit a request.
- To exercise your California privacy rights, email privacy@serge.ai.
Provisions for Swiss residents
- For residents of Switzerland, we process personal data in compliance with the Swiss Federal Act on Data Protection (nFADP).
- The competent supervisory authority for data protection matters in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.
International representatives
- Superstellar LLC is established in Switzerland and is directly reachable at the address above; a Swiss representative for a foreign controller is therefore not applicable. We have not appointed an EU or UK representative. If our activities fall within the territorial scope of the EU or UK GDPR, the representative requirement must be assessed for those activities; a small business or low volume alone does not establish the occasional-processing exemption.
- EU, UK, and Swiss data subjects retain all rights described in this Policy and may exercise them directly with us at privacy@serge.ai or by post to Superstellar LLC, Baarerstrasse 52, 6300 Zug, Switzerland.
- Should our processing reach a scale or risk level that triggers a mandatory representative appointment, we will appoint one and update this Policy accordingly.
Cookies and similar technologies
- Advertising and social pixels — Paid-traffic landing pages, currently /lp/chatgpt-ads, load Meta Pixel from connect.facebook.net only after your explicit opt-in, in every country. Meta receives your IP address, page visits and conversion information and may use cookies and this information for advertising under its own privacy terms. Until you opt in, the pixel is not requested. A Global Privacy Control (GPC) signal overrides any earlier grant. Use Privacy settings in the footer to withdraw or change your choice; reopening settings stops further optional measurement until you grant permission again. The pixel is not installed on authenticated product pages. We remember your choice for 180 days in the essential serge_consent_v2 cookie; older choices are not reused after the purpose disclosure changes.
- Essential authentication storage — Clerk uses first-party session and client-state cookies when you sign in or sign up. They are required to authenticate you and maintain your session; blocking or removing them prevents sign-in or logs you out. They are not used for advertising.
- Analytics — Serge uses no third-party analytics SDK on serge.ai. For our own product observability we read directly from operational database tables. Meta Pixel is the only third-party analytics or advertising script we load, and it is limited to the consent-controlled paid-traffic landing pages described above. Clerk's client code supports essential authentication and is not an analytics SDK.
- Advertising measurement on serge.ai — Advertising consent is separate from analytics consent and is off until you explicitly allow it. We store your advertising choice in the serge_advertising_consent_v1 cookie. Serge sends consented conversion events to the configured OpenAI destination from its servers; there is no separate OpenAI browser pixel. Pending or declined advertising consent prevents conversion sharing. The Serge snippet may measure visits without device storage after denial. No contact-form contents or email addresses are included in our conversion calls.
Children’s privacy
- Serge is available to businesses and adult consumers. You must be at least 18. We do not knowingly collect personal data from minors; contact privacy@serge.ai if you believe a minor has provided personal data.
Changes to this policy
- We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
- Material changes — We will notify you at least 30 days before the changes take effect via email and in-app notification.
- This notice explains our processing; continued use is not consent to new purposes. Where consent is required, we request it separately and you may withdraw it without affecting the lawfulness of processing before withdrawal.
Contact and supervisory authorities
- Privacy inquiries and rights requests — privacy@serge.ai
- General legal inquiries — legal@serge.ai
- Postal address — Superstellar LLC, Baarerstrasse 52, 6300 Zug, Switzerland
- Serge is operated by Superstellar LLC, registered in the Commercial Register of the Canton of Zug, Switzerland.