Maxfound AI/Privacy Policy

Privacy Policy

Version v1.1 · Effective 2026-05-28 · GDPR + China PIPL dual-compatible

1. Scope

This Privacy Policy applies to your access to maxfound.ai and its subdomains, and to all products provided through Maxfound AI (including but not limited to AI visibility monitoring, AEO rewriting, AutoMedia content distribution, AI support, Webhook integrations, and the API).

This policy is designed to be compatible with both the EU GDPR and applicable data-protection law. Where you are located in a jurisdiction with specific privacy regulations (e.g. GDPR or CCPA), those regulations apply to your personal data as described below.

2. What Data We Collect

  • Account information: email, phone number, display name, avatar URL, and third-party OAuth profile (e.g. GitHub, Google, Feishu, and others).
  • Brand data: brand name, category, website, competitor list, monitored keywords, and Schema markup.
  • Scan data: your brand's visibility in AI answers, mention positions, sentiment, and citation sources.
  • Payment data: if you choose to pay online, we process only the corresponding payment reference (transaction ID). We do not store card numbers · PCI-isolated.
  • Usage data: login times, IP address, user agent, and activity logs (audit_log).
  • Cookies: a session cookie (httpOnly, 30 days) plus theme/language preference (localStorage).
[Sensitive personal information notice] We collect your phone number, email, and third-party login identifiers only with your explicit consent. This information is used solely for account identification and service delivery; we do not collect it by default, do not use it for automated decision-making, and do not disclose it externally.

3. How We Use Data

  • Delivering core features such as AI visibility monitoring and report generation.
  • Payments, billing, invoicing, and renewal reminders.
  • System security: abuse prevention, rate limiting, and anomalous-login alerts.
  • Customer success: product improvement, NPS surveys, and weekly digests (you can unsubscribe).
  • Compliance auditing: records retained for 1 year (5 years on Enterprise).
  • Aggregate analysis: we may use de-identified, aggregated data for industry reports (never exposing any individual customer).

4. Third-Party Sharing · Full Subprocessor Disclosure

All third-party processors have signed a Data Processing Agreement (DPA); all transferred data is de-identified with sensitive personal information removed.

ProviderPurposeData scopeLocation
Neon PostgresPrimary DBAll structured dataus-east-1
VercelHosting + edgeHTTP traffic + logsiad1 · global
CloudflareCDN + DDoSHTTP trafficGlobal
Payment processorOnline payment processing if you choose it (optional)Payment reference (no card numbers)Per processor
ResendEmail deliveryRecipient email + contentus-east
FeishuFeishu integration (optional)Feishu ID after your authorizationChina
SentryError monitoringStack traces · no PIIus-east
LLM providersAI queriesPrompt + brand name (no PII)Global

All subprocessors have signed a DPA. To request the full DPA, email legal@maxfound.ai.

5. Cross-Border Data Transfers

This platform handles cross-border data transfers in accordance with applicable data-protection law, including the following safeguards:

  1. Storage at rest: structured business data is stored on Neon servers (us-east-1); all data is de-identified with sensitive personal information removed.
  2. LLM transfers: when a cross-border scenario triggers a third-party AI model, we transmit only de-identified prompts and publicly available brand information, never your phone number, email, or account information.
  3. Legal basis: transfers are limited to what is necessary to perform our service contract with you, and do not involve important data or large-scale personal-information export.
  4. Your control: Maxfound AI selects AI models based on your brand's business type. To adjust or restrict which models are called, change your brand's business-type setting or contact legal@maxfound.ai for assistance.
  5. Recipient obligations: all recipients have signed a Data Processing Agreement (DPA) committing not to use the data for model training and not to redistribute it.

6. LLM Data-Use Policy

  • The prompts we send to LLM providers contain no PII — your name, email, and phone never appear in a prompt.
  • All LLM providers have signed a DPA committing not to train models on your data, not to cache it, and not to retain your queries (pure API-call mode, unlike consumer AI products).
  • You can enable "opt out of training" under Data & Privacy in /dashboard/settings (on by default).
  • AI-generated content on the platform is for reference only and does not constitute business advice or any guarantee of results.

7. Your Rights (GDPR + CCPA)

  • Access: GET /api/me + /api/audit-log
  • Rectification: edit directly in /dashboard/settings
  • Portability: POST /api/me/data-export · full ZIP delivered by email within 24h
  • Erasure: DELETE /api/me/data-purge · reversible within a 30-day grace period
  • Withdraw consent: decline cookies at any time — core functionality is unaffected
  • Complaints: if you disagree with how your data is handled, email legal@maxfound.ai · response within 72 business hours

8. Data Retention

  • Primary account data: for the life of the account + a 30-day grace period after deletion.
  • Scan history: Free 30 days / Starter 90 days / Growth 365 days / Enterprise unlimited.
  • Audit logs: 1 year (5 years on Enterprise).
  • Payment records: retained as required by applicable accounting and tax law.
  • Closed accounts: backups purged within 30 days of hard deletion.

9. Security Measures

We use HTTPS-only, TLS 1.3, Neon AES-256 encryption, and HMAC-SHA256 sessions. For detailed security practices, see /security. If you discover a vulnerability, please disclose it responsibly to security@maxfound.ai.

10. Protection of Minors

Maxfound AI is a B2B business tool and is not directed at children under 13. We do not knowingly collect personal information from minors. If you believe a minor has registered an account, please contact legal@maxfound.ai and we will promptly close the account and delete the data.

11. Cookies and Local Storage

  • We use only essential session cookies to keep you signed in and the service running.
  • No marketing or tracking (non-essential) cookies.
  • You can disable cookies in your browser at any time without affecting core functionality.
  • Local storage holds only your theme/language preference — no private or business data.

12. Changes to This Policy

We may update this policy as law or our business changes. For material changes (expanded data use or new third-party sharing), we will give 30 days' notice via email and a banner at the top of your dashboard. Continued use constitutes acceptance of the new version. Past versions are archived at /changelog.

13. Governing Law and Contact

Disputes arising from your use of this service shall first be resolved through good-faith negotiation. The governing law and dispute-resolution venue are set out in our Terms of Service.