Sercient Privacy Policy
Effective Date: July 17, 2026
Controller: Sercient, LLC, a North Carolina limited liability company and subsidiary of Honey Bear Holdings, LLC ("Sercient," "we," "us," "our")
Contact: privacy@sercient.ai · 9529 Huntsham Rd, Charlotte, NC 28227
This Privacy Policy describes how Sercient, LLC collects, uses, discloses, retains, and protects information in connection with the Sercient websites (sercient.ai and app.sercient.ai) and the Sercient search-intelligence platform and related services (collectively, the "Service"). This Policy covers two distinct categories of data: information about our users and site visitors, and information about third-party websites that our users ask us to analyze. Please read this Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Policy.
1. Who We Are and Our Data Protection Roles
Sercient is a business-to-business search-intelligence platform that measures brand visibility across traditional search engines and AI answer platforms.
For the purposes of applicable data protection laws, including the General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and analogous U.S. state privacy statutes:
(a) Sercient is a data controller with respect to the personal data of our account holders, Organization members, and website visitors.
(b) Sercient is a data controller with respect to publicly available business data we collect about third-party websites that are the subject of audits.
(c) Where a customer (such as a marketing agency) uses the Service to analyze domains on behalf of its own clients, Sercient may act as a data processor on that customer's behalf. In such cases, the customer's own privacy notice governs the processing of its end-users' data, and our processing is governed by a Data Processing Agreement ("DPA") between us and that customer. If you require a DPA, please contact us at privacy@sercient.ai.
2. Scope
This Policy applies to the Sercient marketing website (sercient.ai), the Sercient application (app.sercient.ai), and all related services, tools, and communications. This Policy does not apply to third-party websites we analyze in the course of performing audits, nor to any third-party websites, services, or applications that we may link to, each of which is governed by its own privacy practices.
3. Information We Collect About Users and Visitors
3.1 Information You Provide to Us
(a) Account Information. When you create an account, we collect your email address and password. Your password is stored in cryptographically hashed form by our authentication provider, Supabase. Sercient does not store or have access to plaintext passwords.
(b) Organization Information. If you create or join an Organization, we collect the Organization name, your role within the Organization (e.g., owner, administrator, viewer), and the email addresses of users you invite to join the Organization.
(c) Billing Information. When you subscribe to a paid plan, we collect your subscription plan details, billing cycle, and a payment-processor customer identifier linked to your account. We do not collect, receive, store, or have access to your full payment card number, card expiration date, CVV, or other payment card details. All payment card data is collected, transmitted, and stored exclusively by our payment processor, Stripe, Inc., in accordance with Stripe's privacy policy and PCI-DSS compliance standards.
(d) Communications. If you contact us for support, provide feedback, or otherwise communicate with us, we collect the information you provide in those communications, including your email address and message content.
3.2 Information Collected Automatically
(a) Product Usage and Analytics Data. We collect information about how you use the Service, including pages viewed, features accessed, actions taken (such as initiating an audit, completing signup, or starting a checkout), and your journey through the product. This data is associated with your user ID and email address and is collected through PostHog, our product analytics provider. Our PostHog implementation operates in cookieless mode (in-memory persistence only) and does not set tracking cookies or persistent local storage identifiers.
(b) Device and Log Data. When you access the Service, our servers automatically collect certain technical information, including your Internet Protocol ("IP") address, browser type and version, operating system, referring URL, and request metadata. This information is recorded in server access logs maintained by our hosting providers.
(c) Error and Diagnostic Data. We collect technical error and diagnostic information when errors occur during your use of the Service, which may include your user ID, IP address, browser details, and the technical context of the error. This data is collected through Sentry, our error-monitoring provider, for the purpose of identifying and resolving technical issues.
3.3 Sensitive Data
We do not intentionally collect sensitive personal data as defined under GDPR Article 9 (including data concerning racial or ethnic origin, political opinions, religious beliefs, health, sexual orientation, or biometric data), nor do we collect Social Security numbers, driver's license numbers, or financial account credentials. Stripe isolates all payment card data; Sercient does not handle or store it.
4. Information We Process About Third-Party Websites (Audited Domains)
This section describes a category of data processing that is specific to Sercient's business model and is not addressed by standard privacy policy templates. Please read it carefully.
4.1 What We Collect
To deliver audits, Sercient collects and analyzes publicly available information about the domains our users submit for analysis, both the user's own brand and its competitors. This includes:
(a) Audited Entity Information. The brand domain name, brand name, and industry classification as submitted by the user. This may be the user's own brand or a third-party competitor.
(b) Competitor Entity Information. Competitor domain names, as submitted by the user or as automatically identified through third-party SEO data analysis (via DataForSEO).
(c) Keyword and Search Ranking Data. Keyword universes, search volume data, and search engine ranking positions for audited and competitor domains, obtained from our third-party SEO data provider, DataForSEO.
(d) Publicly Accessible Web Page Content. Content from publicly accessible web pages of audited domains, including HTML content, JSON-LD structured data (schema markup), page metadata, and page freshness signals (such as publication and modification dates). Our automated crawler accesses a maximum of approximately fifty (50) publicly accessible pages per domain per audit cycle, with a fifteen-second (15s) timeout per page.
(e) AI Answer Engine Query Results. The results of natural-language queries submitted to publicly accessible AI answer engines (currently Perplexity) to measure whether and how those platforms cite or reference the audited brand.
(f) Derived Analysis. Topic clusters, visibility scores, gap analyses, competitive assessments, and strategic recommendations generated by Sercient's proprietary methodology using AI and LLM technologies (currently Anthropic Claude).
4.2 What We Do Not Collect
Sercient collects only publicly available information about third-party domains. We do not access, crawl, scrape, or attempt to retrieve any content or data from:
- password-protected or login-gated pages;
- pages behind authentication barriers or paywalls;
- pages excluded by robots.txt directives applicable to our crawler;
- private databases, internal networks, or non-public systems;
- any portion of a website that is not freely accessible on the open internet.
4.3 Legal Basis
We process publicly available business data about audited domains on the basis of our legitimate interest in providing a business-intelligence service that measures publicly observable search visibility, which is a standard practice in the search engine optimization industry. Users are required to represent that they have a lawful and legitimate business purpose for requesting each audit (see our Terms of Service, Section 4).
4.4 Third-Party Data Subject Rights
If you are the operator of a website that has been included in a Sercient audit and you wish to object to our processing of your publicly available business data, please contact us at privacy@sercient.ai. We will review your request in good faith and respond within thirty (30) days. Please note that because we process only publicly available business information (not personal data of individual website visitors), such requests are evaluated on a case-by-case basis. We are committed to respecting the reasonable objections of third-party domain operators.
5. How We Use Information
We use the information we collect for the following purposes:
(a) To provide, operate, maintain, and improve the Service, including generating audits, reports, scores, and recommendations;
(b) To authenticate users, manage accounts, Organizations, roles, and invitations;
(c) To process subscriptions, billing, and payments, and to prevent payment fraud;
(d) To analyze product usage patterns and user behavior in order to improve Service features, performance, and the overall customer experience;
(e) To provide customer support and respond to your inquiries and requests;
(f) To send transactional communications, including account verification, subscription confirmations, audit completion notifications, billing receipts, and security alerts;
(g) To send product updates and Service-related communications where permitted by applicable law;
(h) To detect, investigate, and prevent security incidents, fraud, abuse, and violations of our Terms of Service;
(i) To comply with applicable legal obligations, respond to lawful requests from public authorities, and enforce our Terms of Service and other agreements;
(j) To create aggregated, anonymized, or de-identified data for benchmarking, research, and product development purposes, provided such data does not identify any individual or Organization.
(k) To identify your Organization as a customer of the Service in customer lists and marketing materials, as described in Section 8.7 of our Terms of Service. We do not publish case studies, testimonials, or results that identify your Organization without prior written approval, and we do not use a named individual's photograph, likeness, title, or quotation without that individual's separate consent. You may withdraw customer-identification permission at any time by contacting privacy@sercient.ai.
Legal Bases (GDPR / UK GDPR)
Where applicable, we process personal data on the following legal bases:
- Performance of a contract: Processing necessary to provide the Service pursuant to our Terms of Service (e.g., account management, audit generation, billing).
- Legitimate interests: Processing necessary for our legitimate business interests, including securing and improving the Service, product analytics, business operations, and processing publicly available business data for search-intelligence purposes, where those interests are not overridden by your fundamental rights and freedoms.
- Consent: Where required by applicable law (e.g., certain marketing communications). Where processing is based on consent, you may withdraw your consent at any time.
- Legal obligation: Processing necessary to comply with applicable legal requirements.
6. Cookies and Similar Technologies
6.1 Essential Cookies
The Sercient application (app.sercient.ai) uses strictly necessary cookies to maintain your authenticated session. These cookies are required for the Service to function and do not require your consent under applicable privacy laws. These session cookies are set and managed by our authentication provider, Supabase.
6.2 Analytics
We use PostHog for product usage analytics. Our PostHog implementation is configured to operate in cookieless mode using in-memory persistence only (persistence: 'memory'). This means PostHog does not set cookies, does not use persistent local storage, and does not track users across sessions or across websites.
6.3 Marketing Site
Our marketing website (sercient.ai) does not set any cookies.
6.4 No Advertising or Cross-Site Tracking
Sercient does not use advertising cookies, cross-site tracking pixels, retargeting technologies, or social media tracking scripts. We do not serve advertisements within the Service.
6.5 Browser Controls
You may control cookies through your browser settings. Because the Service uses only essential session cookies, disabling all cookies may prevent you from logging in to the application.
7. How We Share Information; Sub-Processors
7.1 No Sale of Personal Information
We do not sell, rent, or trade your personal information. We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) or any other applicable U.S. state privacy law. We have not sold or shared personal information in the preceding twelve (12) months.
7.2 Service Providers (Sub-Processors)
We share information with the following third-party service providers ("sub-processors") who process data on our behalf, under written contract, and solely for the purposes described below:
| Sub-Processor | Purpose | Data Processed | Data Region |
|---|---|---|---|
| Supabase, Inc. | Database hosting and user authentication | Account information (email, hashed password, user ID), Organization data, invitation data, audit data | United States |
| Vercel, Inc. | Application and website hosting | HTTP request data, server logs | United States / Global Edge Network |
| Railway Corporation | Backend API hosting and audit execution | HTTP request data, audit processing data, server logs | United States |
| PostHog, Inc. | Product usage analytics (cookieless) | User ID, email address, usage events, page views | United States (us.i.posthog.com) |
| Stripe, Inc. | Payment processing | Billing identity, Stripe customer ID, payment card data (held exclusively by Stripe) | United States / Global |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | Error context data, user ID, IP address, browser details | United States |
| Resend, Inc. | Transactional email delivery | Recipient email address, email message content | United States |
| DataForSEO | Keyword, search volume, and search ranking data | Audited and competitor domain names, keyword data | United States |
| Perplexity AI, Inc. | AI answer engine query testing | Generated natural-language queries containing brand and category terms | United States |
| Anthropic, PBC | AI-powered analysis and recommendation generation | Audit-derived data including topic clusters, page analysis data, and structured analytical inputs | United States |
We may update this sub-processor list from time to time. Material changes to our sub-processors will be reflected in an updated version of this Privacy Policy.
7.3 Other Disclosures
We may also disclose information:
(a) As required by applicable law, regulation, legal process, or governmental request, including in response to a subpoena, court order, or similar compulsory legal process;
(b) To enforce our Terms of Service, investigate potential violations, or protect the rights, property, or safety of Sercient, our users, or the public;
(c) In connection with a merger, acquisition, reorganization, bankruptcy, asset sale, or similar corporate transaction, in which case the successor entity will be bound by this Privacy Policy with respect to your personal data; or
(d) With your prior consent or at your direction.
8. AI and Large Language Model Processing
8.1 How We Use AI
Sercient uses artificial intelligence and large language model ("LLM") technologies, including services provided by Anthropic (Claude) and Perplexity, to generate visibility scores, competitive analyses, content gap assessments, and strategic recommendations. When we process data through these AI providers, we transmit audit-derived data (such as topic clusters, structured page analysis data, and brand/category terms) through their commercial APIs.
8.2 Data Training Assurance
We use Anthropic and Perplexity exclusively through their commercial and enterprise API offerings. Under the commercial API terms of service of both Anthropic and Perplexity as of the date of this Policy, data submitted through their commercial APIs is not used to train their respective foundation models. We have selected these providers in part because of these commitments. We recommend that you independently review the current API terms of each provider if this assurance is important to your evaluation of the Service.
Note: Sercient has reviewed and relies upon the published commercial API terms of Anthropic and Perplexity. Users who require a written, bilateral representation regarding model training should contact us to discuss a Data Processing Agreement.
8.3 Output Limitations
All AI-generated output is informational and constitutes estimates, not guarantees. Output may contain errors or omissions. Our system employs automated verification measures, including hallucination filtering that discards recommendations that cannot be corroborated against source data, but no automated system is infallible. See our Terms of Service, Section 6, for additional disclaimers.
9. International Data Transfers
Sercient and its sub-processors are primarily located in and process data within the United States. If you access the Service from outside the United States, including from the European Economic Area ("EEA"), the United Kingdom, or Switzerland, your personal data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those of your jurisdiction.
Where we transfer personal data from the EEA, UK, or Switzerland to the United States or other countries, we rely on appropriate transfer mechanisms recognized under applicable law, including:
(a) Standard Contractual Clauses ("SCCs") adopted by the European Commission, as incorporated into the data processing agreements of our sub-processors;
(b) The UK International Data Transfer Agreement or Addendum, where applicable; and
(c) Other legally recognized transfer mechanisms as may be appropriate.
For more information about international data transfers and the safeguards we rely upon, please contact us at privacy@sercient.ai.
10. Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this Policy, including providing the Service, complying with our legal obligations, resolving disputes, and enforcing our agreements. Specific retention periods are as follows:
(a) Account Data. We retain your account information for as long as your account remains active. Following account closure (whether by you or by us), we will delete or anonymize your personal data within ninety (90) days, unless a longer retention period is required by applicable law or is necessary for legitimate business purposes (such as resolving pending disputes or maintaining legally required records).
(b) Audit Data. Audit reports, scores, and associated analytical data are retained for as long as your account remains active and until deleted by you, or until ninety (90) days following account closure, whichever occurs first. You may delete individual audit data at any time through the Service interface.
(c) Billing Records. Transaction records and billing history are retained for a minimum of seven (7) years following the transaction date, as required for tax, accounting, and legal compliance purposes.
(d) Analytics Data. Product usage analytics data collected through PostHog is retained in accordance with our PostHog configuration. Because our analytics operate in cookieless, in-memory mode, no persistent user-level tracking identifiers are stored by PostHog.
(e) Server Logs. Server access logs and error diagnostic data are retained for a maximum of ninety (90) days.
(f) Backups. Database backups may retain data for a limited period following deletion from the primary database, consistent with our backup rotation schedule. Deleted data will be purged from all backups within ninety (90) days of deletion from the primary database.
11. Security and Internal Access
11.1 Security Measures
We implement administrative, technical, and organizational security measures designed to protect the confidentiality, integrity, and availability of your personal data, including:
- Encryption in transit (HTTPS/TLS) for all communications between your browser and the Service;
- Cryptographic hashing of passwords (via Supabase authentication);
- Row-Level Security ("RLS") policies on database tables to ensure strict tenant isolation between Organizations;
- Payment isolation through Stripe (Sercient does not handle or store payment card data);
- Access controls limiting internal access to personal data to authorized personnel on a need-to-know basis;
- Audit logging of internal administrative actions.
11.2 Internal Access and Account Impersonation
Authorized Sercient personnel may access user accounts, including through a support "impersonation" capability that allows an administrator to view the Service as a specific user, solely for the purposes of operating, supporting, troubleshooting, and securing the Service. All impersonation sessions are logged and are subject to internal access controls and oversight.
11.3 Limitations
No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee absolute security. In the event of a data breach that is reasonably likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the appropriate supervisory authority, within the timeframes required by applicable law.
12. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights with respect to your personal data. We are committed to honoring these rights in accordance with applicable law.
12.1 Rights Under GDPR / UK GDPR
If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have the right to:
- Access the personal data we hold about you and receive a copy;
- Rectify inaccurate or incomplete personal data;
- Erase your personal data ("right to be forgotten"), subject to certain exceptions;
- Restrict certain processing of your personal data;
- Data portability: receive your personal data in a structured, commonly used, machine-readable format;
- Object to processing based on our legitimate interests;
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing; and
- Lodge a complaint with your local data protection supervisory authority.
12.2 Rights Under CCPA / CPRA and U.S. State Privacy Laws
If you are a resident of California or another U.S. state with an applicable privacy statute (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others), you may have the right to:
- Know what personal information we collect, use, disclose, and sell or share;
- Access your personal information;
- Delete your personal information, subject to certain exceptions;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information: as stated above, we do not sell or share your personal information;
- Limit the use of sensitive personal information: we do not process sensitive personal information for purposes beyond those permitted under applicable law; and
- Non-discrimination: we will not discriminate against you for exercising your privacy rights.
12.3 How to Exercise Your Rights
To exercise any of the rights described above, please contact us at privacy@sercient.ai. We will verify your identity before processing your request and will respond within the timeframes required by applicable law (generally thirty (30) days for GDPR/UK GDPR requests and forty-five (45) days for CCPA/CPRA requests, with extensions as permitted by law). You may also designate an authorized agent to make a request on your behalf, subject to verification.
12.4 Third-Party Website Operators
If your website was analyzed as part of a Sercient audit and you wish to object to our processing of your publicly available business data, please contact us at privacy@sercient.ai. We will review your request in good faith and respond within thirty (30) days. See Section 4.4 for additional information.
13. Children's Privacy
The Service is intended exclusively for business and professional use and is not directed to individuals under the age of eighteen (18). We do not knowingly collect, solicit, or maintain personal data from children under 18. If you believe that a child under 18 has provided personal data to us, please contact us immediately at privacy@sercient.ai, and we will take prompt steps to delete such data from our systems.
14. Do Not Track
Some browsers transmit a "Do Not Track" ("DNT") signal to websites. Because there is no universally accepted standard for how to respond to DNT signals, the Service does not currently alter its data collection or use practices in response to DNT signals. However, as described in Section 6, our analytics are configured to operate in cookieless mode and we do not engage in cross-site tracking.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will (a) update the "Effective Date" at the top of this Policy and (b) provide additional notice by email to the address associated with your account or through a prominent in-application notification. Your continued use of the Service after the effective date of any updated Policy constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.
16. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
Sercient, LLC 9529 Huntsham Rd, Charlotte, NC 28227
Privacy inquiries: privacy@sercient.ai General support: support@sercient.ai Security concerns: security@sercient.ai
If you are located in the EEA or UK and are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.