Privacy policy
Recomma is operated by iMerch, Inc., and this policy says what we collect when you use it, why, who we share it with, and what you can ask us to do about it.
Who we are
Recomma (recomma.ai and docs.recomma.ai) is a product of iMerch, Inc., 21300 Dexter Dr, Cupertino, CA 95014, United States. For the purposes of data protection law, iMerch, Inc. is the controller of the personal data described in this policy. You can reach us at [email protected].
What Recomma does
Recomma measures how AI assistants such as ChatGPT, Gemini, Google AI Overviews and AI Mode answer questions about a brand. You give it a brand's website and a set of questions; on a schedule it captures the answers those assistants give, records which brands and sources they name, reads the brand's own site for faults an assistant would trip on, prices the market behind the questions, and, if you connect Google Analytics, reports the visits those assistants sent. Most of the data it holds is therefore about a business and its public website, not about a person. This policy covers the parts that are about people.
What we collect
Account data. Your name, email address and a hash of your password when you create an account, and the name of the workspace you create or are invited to. We do not offer sign-in through Google, GitHub or any other social provider, so we hold no social profile.
Workspace content. What you put into the product: brand names and domains, descriptions, competitors, topics, the questions you track, and any notes or actions your team records. Members of the same workspace can see all of it.
Billing data. Your plan, subscription status and invoices. Card details are entered on Stripe's pages and stored by Stripe; we never see or hold a card number.
Google Analytics data. Only if you choose to connect a property. We ask Google for read-only access to that one GA4 property and pull, once a day, sessions that arrived from an AI assistant: the assistant, the landing page, the date, country, device, engaged sessions, key events and any revenue Google attributes to them. We do not pull user-level or identifying analytics data. The refresh token Google gives us is encrypted at rest. Disconnecting the property deletes the token; rows already pulled stay in your workspace until you delete the brand.
Usage and technical data. Server logs of requests to the product — timestamps, the route called, the workspace and user acting, timings and errors — kept so we can run and debug the service. We do not run advertising pixels or third-party analytics scripts on the product or on this site.
Support and email. What you send us at [email protected], and the transactional emails we send you, such as an invitation to a workspace.
Data we gather about brands and websites
To measure a brand, Recomma also collects data that is public or about the brand rather than about you:
- The answers AI assistants give to the questions you track, captured as a reader would see them, with the brands, pages and sources each answer cites.
- Pages of the brand's own website, found from its sitemap and read to check markup, headings, canonical addresses and similar facts. We store the address, HTTP status and the facts extracted, not a copy of the page.
- The site's robots.txt, and a history of how it changes, to report which AI crawlers it allows.
- Keyword volumes, bids and rankings for the brand and its competitors, and the questions Google shows beside a search, licensed from search data vendors.
- Brand logos, fetched from a logo service by domain.
- Where the brand's pages appear in the search indexes an AI agent calls.
If a person's name appears in one of those sources — an author byline on a cited page, say — it is stored as part of that answer or page and treated as public content.
Why we process it
- To provide the service you signed up for: running your workspace, capturing answers, reading your site, pulling your analytics, and showing you the results. This is performance of our contract with you.
- To bill you, and to keep the records that tax and accounting rules require. This is our contract and our legal obligations.
- To keep the service running and secure — logs, error reports, abuse prevention. This is our legitimate interest in operating a reliable product.
- To write to you about your account: invitations, billing notices, changes to the service or to this policy. We do not send marketing email unless you ask for it.
How we use Google user data
Recomma's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: data from your Google Analytics property is used only to show you, inside your workspace, the visits AI assistants sent to your site. It is not used for advertising, not sold, not used to train models, and not transferred to anyone except as needed to run the service or as the law requires. A human at Recomma reads it only with your permission, for security, or to comply with the law.
Who we share it with
We do not sell personal data. We share it with the companies that run parts of the service for us, each bound by its own terms to use the data only to provide that service:
- Amazon Web Services (United States) — hosting for the application and its database.
- Stripe — subscriptions, payments and invoices.
- Google — the OAuth grant and the Analytics Data API, when you connect a property.
- Resend — transactional email, such as workspace invitations.
- Axiom — server logs.
- DataForSEO, and a gateway operated by AISA — capturing AI assistant answers as a reader sees them, and keyword and search data. The questions you track are sent to them; your account data is not.
- OpenRouter, Perplexity and TypeSafe — language-model processing of the questions, answers and site pages Recomma analyses, for example to name the brands in an answer or place a keyword under a topic. Your account data is not sent to them.
- Exa and Brave — search indexes queried with the questions you track.
- Brandfetch — logos, looked up by domain.
We may also share data with a buyer or successor if the business is sold or merged, with our advisers under confidentiality, and with authorities where the law requires it. If we are required to disclose your data we will tell you unless we are forbidden to.
AI agents you connect
Recomma exposes a server that AI agents such as Claude or Cursor can connect to, so an agent can read your workspace and record actions on your behalf. An agent gets access only after you sign in and approve the scopes it asks for, and only to the workspaces you can see. What the agent then does with that data is governed by the agent's own operator, not by us; you can revoke an agent's access at any time.
Cookies
The product sets one cookie: the session that keeps you signed in. It is strictly necessary and is removed when you sign out. Your browser also keeps a few preferences locally — the theme you chose, the brand you last opened — which never leave your device. We set no advertising or analytics cookies and honour no-tracking settings by default, because there is nothing to opt out of.
Where the data is
The application and its database run on servers in the United States. Some of the processors above run elsewhere; where data about people in the European Economic Area or the United Kingdom is transferred to them, we rely on their standard contractual clauses or an adequacy decision.
How long we keep it
- Workspace content and the answers, pages and analytics rows gathered for a brand stay for as long as the brand is in your workspace. Deleting a brand deletes its prompts, answers and everything measured for it.
- If a subscription lapses, the workspace is closed rather than deleted: nothing already collected is removed, and it is all there when a plan is put back on it. Write to us if you would rather it were deleted.
- Account data stays while the account exists. Deleting a workspace removes its content; to delete your account entirely, email us and we will do it within 30 days.
- Server logs are kept for no longer than 90 days.
- Billing records are kept for as long as tax law requires, which is typically seven years.
How we protect it
All traffic to the product is encrypted in transit. Passwords are stored as salted hashes, Google refresh tokens are encrypted at rest, and production access is limited to the people who operate the service. No system is perfectly secure; if we learn of a breach that affects your data we will tell you without undue delay.
Your rights
Wherever you are, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we process it, by writing to [email protected]. We will answer within 30 days. If you are in the EEA or the UK you also have the right to restrict processing, to data portability, and to complain to your supervisory authority. If you are a California resident you have the rights the CCPA gives you, including to know what we collect and to have it deleted; we do not sell or share personal information for cross-context advertising, and we will not treat you differently for exercising your rights. Most of what the product holds you can also see, export and delete yourself from inside your workspace.
Children
Recomma is a business tool for people aged 18 and over. We do not knowingly collect data from anyone under 18; if you believe we have, tell us and we will delete it.
Changes to this policy
If we change this policy in a way that matters, we will email the owners of every workspace before the change takes effect and update the date at the top of this page. Continuing to use the product after that date means you accept the new version.
Contact
Questions about this policy or about your data: [email protected]. Legal notices: iMerch, Inc., 21300 Dexter Dr, Cupertino, CA 95014, United States, or [email protected].