Privacy policy
How Sight processes personal data under the EU GDPR.
Last updated: 26 July 2026
Who is responsible
0-AI UG (haftungsbeschränkt), Neckartalstraße 127, 70376 Stuttgart, Germany, is the controller responsible for the processing described in this policy. For privacy requests, contact datenschutz@cero-ai.com.
This policy explains what data Sight processes, why we process it, the legal basis, how long we retain it, and your rights.
What we collect
Depending on how you use Sight, we process:
- Website and scan data: the URLs, public website content, project context, crawl and scan results, reports, and any information you enter while using the service.
- Account data: name or username, email address, password hash, passkey credentials where enabled, organisation membership, and account settings.
- Billing data: email address, plan and purchase information, and Stripe customer, subscription, payment-intent, invoice and transaction references. Card details are processed by Stripe and do not reach our servers.
- Technical and security data: IP address, browser and device data, session and security identifiers, request and server logs, and rate-limit data.
- Connected-service data: when you choose to connect Google Search Console, the selected property, encrypted refresh token, and the search-performance data retrieved for that property.
Why we process it, and our legal bases
We process personal data to provide accounts, scans, reports, monitoring, support and billing; to fulfil legal record-keeping duties; and to secure, maintain and improve Sight.
The legal bases are performance of a contract or steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), our legitimate interests in secure and reliable operation, fraud prevention and product improvement (Art. 6(1)(f) GDPR), and consent where required (Art. 6(1)(a) GDPR). You may withdraw consent at any time with effect for the future.
Processors and third parties
We use service providers only where needed to provide and operate Sight. We do not sell personal data. Depending on the feature you use, recipients may include:
- Stripe: payment processing, billing and customer-portal services.
- Resend: transactional email, including verification, account, report and billing messages.
- OpenRouter or DeepSeek: AI-model requests used to analyse public website content and generate Sight results. We do not send account passwords or payment-card data to these providers.
- Google: Google Search Console data, when you explicitly connect it, and Google PageSpeed Insights when a scan requests performance checks.
- Our hosting and infrastructure providers: to host the application, database, backups and technical logs.
- Cero Analytics: our cookieless analytics service at analytics.cero-ai.com, which records page and technical request data without cookies or browser storage. IP address and user agent are used transiently to derive a pseudonymous visitor identifier and are not written into the analytics dataset.
International transfers
Some providers may process data outside the EU/EEA. Where required, we use an adequacy decision, the European Commission's Standard Contractual Clauses, or another valid transfer mechanism, together with additional safeguards where appropriate.
How long we keep it
Terminal scan artifacts, including temporary HTML snapshots, are normally deleted within 48 hours. Account, project, scan and report data are retained while your account or the relevant project remains active, unless deletion is requested or a longer retention period is required. Billing and invoice records are retained for the statutory retention periods. Security logs, rate-limit data and email-delivery records are retained only as long as necessary for security, troubleshooting and delivery, then deleted or anonymised.
Cookies
Sight uses strictly necessary first-party cookies for authenticated sessions and protected report access. These cookies are HTTP-only where technically possible, use SameSite=Lax, and are marked Secure in production. We do not use advertising or cross-site tracking cookies. The marketing site loads Cero Analytics without cookies or browser storage, as described above.
Your rights
Under the GDPR you have the right to access, rectification, erasure, portability and restriction of your personal data, and the right to object to processing based on legitimate interests. Where processing rests on consent, you may withdraw it at any time with effect for the future.
To exercise these rights, email datenschutz@cero-ai.com. You also have the right to lodge a complaint with a data-protection supervisory authority.
Data security
We use technical and organisational measures including encryption in transit, access controls, encrypted storage of integration credentials, and security monitoring. No method of transmission or storage is completely secure, but we work to protect data and limit access to it.
Changes to this policy
We may update this policy to reflect changes to the service or the law. When we make material changes we will update the date above and, where appropriate, notify you by email.
Questions about this document? Email contact@cero-ai.com.