NamezAI — Privacy Policy
Effective: July 10, 2026 · Last updated: July 23, 2026
This Privacy Policy explains what NamezAI, operated by Lo Labs, LLC ("we," "us"), collects and how we handle it. Questions: hello@namezai.com.
Most of what we process is business information — but some of it may also be personal information when it identifies an individual (e.g., a sole proprietor, owner, doctor, or office manager). This policy covers that personal information.
1. What we collect
- Account: your email, plus — if you sign in with Google — your name and a stable Google account identifier. We store your email and the account identifier; we don't store your Google profile photo, and we never receive your password.
- Business info you enter: business name, website, category, city/state, and services — plus, if you choose to provide them, the business's public phone number, street address, and opening hours (we use these to check whether AI engines state them correctly).
- Audit inputs & outputs: the customer-style questions we run, the AI responses, cited sources/domains, competitor mentions, scores, recommendations, timestamps, and report metadata.
- Payments: handled by Stripe — we never see or store your full card number; we keep a Stripe customer reference, subscription status, limited verified subscription-lifecycle metadata, and — when you use one of our limited friend promotion codes — the code, redemption time, discount amount, and Stripe checkout/subscription references. We don't store raw Stripe webhook payloads.
- Customer-support and quality records: a searchable index of report metadata and quality flags, plus a limited log when an authorized NamezAI administrator opens a customer/diagnostic report view or grants/reverses a business-specific courtesy audit. The log records the administrator, time, report/account reference, and a short required reason; it does not copy raw AI responses, payment details, authentication tokens, or support-email bodies into the console.
- Account activity and outbound-email records: a bounded timeline of account, business, audit, and report events, plus delivery metadata for account, report, and monitoring emails. While an email is pending, its recipient, subject, and body are encrypted at rest for no more than approximately 23 hours; that encrypted payload is wiped as soon as the message reaches a terminal state. The operational history does not contain the message body, sign-in link or token, recipient address, or raw provider response.
- Messages: emails you send us (e.g., support). Those inbound message bodies remain in the external support inbox and are not copied into the Owner Console.
- Limited first-touch acquisition data: when you first reach an eligible public NamezAI page, we may record UTM source, medium, campaign, and content, the hostname only of an external referring site, the public NamezAI landing path only, and the first-touch time. We do not retain search terms or
utm_term, advertising click IDs, the full referring URL/path/query, or an IP address or browser/device user-agent as part of this acquisition record. If no eligible public first touch was recorded, we store only an unknown marker; we do not invent a landing path or first-touch time from a later sign-in, private route, or audit request. - Limited first-party funnel events: for an eligible public visit, we may record whether the same opaque journey reached these fixed stages: public landing, article audit button, first audit-form interaction, valid audit approval, and completed audit. If you later create an account or begin or complete Stripe Checkout, we use the limited first-touch record already attached to that account to count those outcomes by campaign. We do not attach arbitrary page events or client properties. An illustrative demo run is not counted as a live audit approval or completion, but a real visitor's public landing and any later account or Checkout outcome remain part of that limited campaign journey. Deployments or journeys explicitly labeled as demo or internal quality assurance, and authenticated owner-administrator journeys, are excluded from production campaign totals.
- Limited technical data: IP addresses may be received during normal operation, security, and abuse prevention; where possible we store only a hashed or truncated form (for rate-limiting) and don't keep raw IPs longer than necessary. Plus a session cookie and basic server logs.
2. How we use it
To run your audits and monitoring; generate, store, and (if you share them) serve your reports; send monitoring alerts and account emails; manage your subscription and billing; prevent abuse and enforce free-audit limits; provide customer support; review report quality; keep the Service secure; debug and improve our scoring and recommendations; and comply with the law. We also use the limited first-touch data described above to understand which of our own pages, campaigns, and external referrals lead to a form, audit, account, checkout, or subscription. We don't use it to build a cross-site advertising profile.
3. We don't sell your data — or use it for ads
We don't sell your personal information, and we don't sell or "share" it for cross-context behavioral advertising. We run no third-party ad or cross-site tracking. Because we don't sell or share for ads, we don't currently respond differently to browser "Do Not Track" signals; we'll honor any legally required opt-out preference signals.
4. We don't train AI models on your data
We may use aggregated or de-identified statistics to improve NamezAI, but we don't use your personal information or your private reports to train AI models. The AI providers in §5 process the queries we send under their own terms. For a provider whose free tier would permit training or human review of prompts (e.g. Google's Gemini), we use the paid/commercial API tier, under which providers don't use our inputs or outputs to train their foundation models.
5. Who we share it with (service providers)
We share only what's needed with the providers that run the Service:
| Provider | Purpose |
|---|---|
| Sign-in | |
| Stripe | Payments & subscriptions |
| AI providers (OpenAI/Anthropic/Perplexity/Google/xAI — depending on enabled integrations) | Running audits |
| Render | Hosting |
| Resend | Account & alert emails |
| Cloudflare (Turnstile) | Bot / abuse protection — when enabled |
We may also disclose information if required by law or to protect rights and safety.
The short-lived first-touch cookie and its acquisition fields are not sent to Google Sign-in, Stripe, Resend, or the AI providers. Our hosting provider necessarily processes the application and database where the limited record is stored.
6. What we send to AI providers
To run an audit we send the relevant business details (name, website, city/state, category, services) and the generated customer-style questions. We do not send your payment information, your Google account identifier, or unnecessary account data. Don't submit anything you wouldn't want sent to those providers.
7. Shareable report links
If you share a report link, anyone with that link can view its free diagnosis. Personalized paid report sections remain available only to the signed-in report owner while their subscription is active. Don't include confidential information in your audit inputs. You can ask us to delete a report anytime at hello@namezai.com.
8. No patient or health information
NamezAI is not designed to collect protected health information. Please don't submit patient names or contact info, symptoms or conditions tied to an identifiable person, appointment details, medical histories, insurance information, or treatment records. If we find such information, we may delete it.
9. Cookies
We use first-party cookies only: cookies that keep you signed in and protect the sign-in flow, plus a signed, HttpOnly first-touch cookie that lasts about 20 minutes and carries only the limited acquisition fields described in §1 until an account or report can be created, and a separate signed, HttpOnly funnel cookie that lasts about 24 hours and contains only a random opaque journey identifier and expiry. The longer-lived opaque id lets a careful visitor review the audit questions for more than 20 minutes without losing the original campaign cohort; the acquisition fields remain server-side. Neither cookie is available to page scripts, and neither is a third-party, advertising, or cross-site tracking cookie. We do not run third-party analytics. If we materially change these practices, we'll update this Policy first.
10. How long we keep it
| Data | Retention |
|---|---|
| Account, tracked businesses & saved history | Until you delete your account |
| Anonymous, demo & free-audit reports (including raw responses) | Usually deleted approximately 90 days after creation; an unlisted shared link stops working when its report is deleted |
| Reports saved in a subscriber's tracked-business history | Until you delete your account; deleting the account also disables shared links to those reports |
| Searchable report metadata, quality flags & report-view logs | Follow the underlying report/account: removed when the applicable report retention period ends or the associated account is deleted |
| Courtesy-audit adjustments & linked administrator action records | Until the associated account is deleted |
| Account, business, audit & report activity timeline | While the associated account exists |
| Encrypted pending outbound-email payload | Up to approximately 23 hours, and wiped earlier when Resend accepts the request or the message otherwise reaches a terminal state |
| Outbound-email delivery metadata (type, status, attempts, timestamps & bounded error category) | Up to approximately 90 days, or earlier when the associated account is deleted |
| First-touch acquisition record attached to an account or report | Follows that account or report: removed when the account is deleted or the applicable report retention period ends |
| Privacy-minimal funnel journeys and fixed stage events | Up to approximately 90 days; the opaque cookie itself expires after about 24 hours |
| Short-lived first-touch cookie and sign-in carry state | The acquisition cookie expires after about 20 minutes; the Google sign-in copy expires with its roughly 10-minute signed state, and a private copy associated with a requested one-time magic sign-in token expires with that token and is removed by token cleanup |
| Billing & transaction records | Kept as required for tax, accounting, and legal purposes — held by Stripe (which stores your name, email, amounts paid, and promotion redemptions); we also keep limited billing metadata locally (a Stripe customer reference, plan status, and verified friend-code redemption metadata) until the associated account is deleted |
| Fraud/abuse-prevention hashes (e.g. a hashed IP) | Up to ~90 days (a scheduled purge enforces this) |
| Server logs | Up to ~30 days |
| Email opt-out records | As long as needed to honor your opt-out |
Deleting your account is scheduled with a 48-hour grace period — you can undo it during that window, and you must cancel any active paid subscription first. After the window, we permanently remove your account, tracked businesses, saved history, reports, and the local billing metadata. We keep only what we have a lawful basis to keep: transaction records at Stripe (tax/accounting/legal), limited fraud/abuse-prevention hashes for a short, purged window, and records needed to honor your choices (such as an email opt-out). We do not keep your reports, and we do not keep a marketing profile of you to re-identify you if you return. Canceling your subscription alone doesn't delete your account — delete it (or ask us) for that. Routine backups may persist briefly before they rotate out.
11. Your rights
Email hello@namezai.com to access, correct, export, or delete your information — or delete your account yourself from the "Account settings" card on the Account page (if you have an active subscription, cancel it first). We may verify your identity first and will respond within applicable legal timeframes; some deletions may be limited by legal, billing, or security needs. Depending on where you live, applicable law may give you additional privacy rights — we'll honor legally applicable requests, and we won't discriminate against you for exercising a privacy right.
12. Security
We use reasonable technical and organizational measures (encryption in transit, secret/hash handling, access controls), and we limit access to personal information to the people and systems that need it. We don't store full payment card numbers. No method is 100% secure, but we work to protect your information.
13. Children
NamezAI is for businesses and is not directed to children; we don't knowingly collect data from anyone under 18.
14. Where your data is processed
We operate in the United States. If you use the Service from outside the US, your information may be transferred to, stored, and processed in the US and other countries where our providers operate.
15. Changes
We may update this Policy; we'll post the new version with an updated date. If we materially change how we use personal information, we'll give notice and, where required, get your consent before the change applies.
16. Contact
hello@namezai.com