Privacy Policy
Last updated: 7 August 2026
1. Who we are
BotLens is a product of AI-fy.me, operated by:
AI-fy.me; Calle de Corujera de San Juan 24, 38500 Güimar, Santa Cruz de Tenerife; NIF 0Z2593402L
Contact for privacy matters: andreas@ai-fy.me
We are the data controller for the personal data described in this policy, within the meaning of the EU General Data Protection Regulation (GDPR) and, where applicable, the Swiss Federal Act on Data Protection (FADP).
2. Scope
This policy applies to:
- botlens.app and its subdomains
- the BotLens web application (audit, dashboard, Share of Answer, Prompt Tracker, and related features)
- the free tools we publish (robots.txt generator, llms.txt generator, and similar)
- communications with us by email or through our booking links
It does not cover third-party websites you may reach through links on our site.
3. What personal data we process
We collect the following categories of data, depending on how you use BotLens.
Account data. If you create an account: your name, email address, and, if you sign in with Google, the basic profile information Google provides. If you sign in by email magic link, we process the email address needed to send that link.
Audit and tracking data.The website URL you submit for an audit or for Share of Answer / Prompt Tracker analysis, the prompts you configure, and the resulting scores and history. We do not intentionally collect personal data through this process. If a page you submit happens to display personal information, for example staff names on a public "About us" page, our automated checks may incidentally read that publicly available content, in the same way a search engine crawler would.
Free tool and lead data.If you use a free tool, such as the robots.txt or llms.txt generator, and choose to receive the result, we collect your name, your email address, and whether you agreed to receive further marketing communication. Receiving the tool's result never depends on that marketing consent.
Payment data. If you subscribe to a paid plan, payment is processed by Stripe. We do not receive or store your full card number. We receive confirmation of payment, your billing email, and, where applicable, VAT or tax identification details for invoicing.
Technical and usage data.Standard server log data, including IP address, browser type, and timestamps, is processed for security, abuse prevention, and rate limiting, including through Cloudflare Turnstile's bot detection.
Correspondence. Anything you send us directly by email or through a booking link.
4. Why we process this data, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing your account and the BotLens dashboard | Performance of a contract (Art. 6(1)(b)) |
| Running the audit, Share of Answer, and Prompt Tracker features you request | Performance of a contract (Art. 6(1)(b)) |
| Processing payment and issuing invoices | Performance of a contract, and legal obligation for tax records (Art. 6(1)(b) and (c)) |
| Sending the result of a free tool you requested | Performance of a contract, or a pre-contractual step taken at your request (Art. 6(1)(b)) |
| Sending further marketing communication | Consent (Art. 6(1)(a)), only where you have explicitly opted in |
| Rate limiting, abuse prevention, and bot detection | Legitimate interest in keeping the service secure and available (Art. 6(1)(f)) |
| Responding to your enquiries | Performance of a contract if you are already a customer, or legitimate interest in operating our business (Art. 6(1)(b) and (f)) |
5. Who else sees this data
We work with the following service providers, each acting as a data processor under a data processing agreement. None of them may use your data for their own purposes.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (Frankfurt region) |
| Cloudflare | Hosting, bot protection (Turnstile), object storage (R2) | Global network, EU data residency where configured |
| Stripe | Payment processing and tax handling | EU / US |
| Resend | Transactional email (magic links, account notifications) | EU / US |
| Browserless | Rendering PDF reports | EU / US |
| Umami | Cookieless traffic statistics | EU |
| Contentsquare | Heatmaps and session replay, only with your consent | EU |
| Advertising measurement (Insight Tag), loaded on every visit | EU / US | |
| GoHighLevel | Booking and CRM for the Managed tier | US |
| Anthropic (Claude), OpenAI (ChatGPT), Google (Gemini), Perplexity | Generating the AI answers we analyse for the audit and Share of Answer features | US and other locations outside the EU / EEA |
Where a processor is located outside the EU / EEA, we rely on the EU-US Data Privacy Framework where the provider is certified, Standard Contractual Clauses, or another valid transfer mechanism recognised under GDPR Chapter V.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
6. How long we keep data
- Account and subscription data: for as long as your account is active, plus a limited period afterward to meet accounting and tax obligations.
- Free tool leads: until you unsubscribe or ask us to delete them, or after 24 months of inactivity, whichever comes first.
- Audit and tracking history: per your plan's stated retention window, for as long as the account remains active.
- Server logs: a short operational window of 30 days, kept for security purposes only.
7. Your rights
Under the GDPR, and under the FADP if you are in Switzerland, you have the right to:
- Request access to the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to our legal obligation to retain certain records, for example invoices
- Request restriction of processing, or object to processing based on legitimate interest
- Receive your data in a portable format
- Withdraw consent at any time, for any processing based on consent, without affecting processing already carried out
- Lodge a complaint with a data protection supervisory authority. As we are established in Spain, this is the Agencia Española de Protección de Datos (AEPD, aepd.es). You may also complain to the supervisory authority in your own country of residence.
To exercise any of these rights, contact us at andreas@ai-fy.me.
8. Cookies and similar technologies
BotLens uses cookies that are strictly necessary for the service to function: keeping you signed in, remembering your session, Stripe's checkout process, and storing your answer to the cookie banner described below. These do not require consent under the ePrivacy rules, since they are essential to the service you have asked for.
We use Umami for basic traffic statistics (page views, country, device type, referrer). Umami is cookieless, stores nothing on your device and does not track you across other websites, so it runs without consent. It is hosted in the EU.
We also use Contentsquare for behavioural analytics: heatmaps and session replay that show us where people get stuck in the product. Contentsquare does set cookies, so it loads only if you press Accept on our cookie banner. If you press Reject, or simply ignore the banner, it is never loaded. You can change your mind at any time by deleting the "aify_consent" cookie in your browser settings, which brings the banner back.
We also use the LinkedIn Insight Tag, which sets advertising cookies and lets us measure which LinkedIn campaigns bring people to BotLens. Unlike Contentsquare, this tag currently loads on every visit, whether or not you press Accept, and the cookie banner does not control it. LinkedIn may use what it collects as an independent controller under its own privacy policy.
You can stop it in two ways that do not depend on us: opt out of LinkedIn's advertising cookies directly in LinkedIn's own opt-out settings, or block it with any standard tracker-blocking browser or extension, which stops the tag loading at all.
We do not sell your data. Behavioural analytics (Contentsquare) is loaded only if you press Accept; the LinkedIn advertising tag currently loads regardless of that choice, as described above.
9. Children
BotLens is a business-to-business product intended for founders, marketers, and professionals. It is not directed at, and we do not knowingly collect data from, anyone under the age of 16.
10. Security
We apply industry-standard technical and organisational measures, including encryption in transit, row-level access control on our database, and restricted administrative access, to protect your data against unauthorised access, loss, or misuse.
11. Changes to this policy
We may update this policy as our product or legal obligations change. The date at the top shows the last revision. Material changes will be communicated to registered users by email.
12. Contact
AI-fy.me
Andreas Höfelmeyer
andreas@ai-fy.me