Privacy Policy
Last updated: August 10, 2026
Operator and data controller
s6s.aiRandstad 20, 1314 BB Almere
KvK: 42088310
BTW-id: NL005486095B61
Contact: [email protected]
1. Overview
s6s.ai, identified above as the data controller ("S6S", "we", "us"), provides AI Visibility monitoring, reports, and evidence-backed recommendations, with an automation layer available for developer use. This policy describes how we collect, use, store, and protect your information when you use our website and services at s6s.ai.
2. Information We Collect
2.1 Account Information
When you sign up via Google OAuth, we receive your name, email address, and profile picture from Google. When you sign up via email/password, we collect your email and an encrypted password hash. We also store your authentication provider (Google, GitHub, or email) and a unique account identifier.
2.2 AI Visibility Data
When you track a brand, run a check, or create a report, we store the brand name, domain, keywords, competitors, target markets, selected AI engines, report surfaces, observations, source-readiness signals, recommendations, and report/run history needed to provide the service. For a permitted measurement surface this may include the submitted buyer question, provider response text and JSON, citations, request outcome, token/cost telemetry, and scores or entities derived from that evidence.
2.3 Developer Automation Data
If you use the developer automation layer, we store the automations you create, their configuration, execution logs, and run history so you can monitor, debug, and manage them.
2.4 Third-Party Credentials
When you connect external services (Google Sheets, Google Drive, Slack, Discord, Telegram, etc.), we store the OAuth tokens or API keys needed to provide the connected service. All credentials are encrypted using AES-256-GCM at rest.
2.5 AI Chat Data
When you use the AI chat builder, we store your chat sessions and messages to provide conversation history and improve the quality of AI Visibility recommendations and developer automation suggestions.
You can opt out of contributing your chat data to platform improvements in your account settings. Opting out does not affect your ability to use the chat builder.
2.6 Usage Data
We collect basic usage telemetry such as API request counts, report/run metrics, and error logs to operate and improve the service. We do not use third-party analytics or tracking scripts on authenticated pages.
3. Google OAuth & Google API Data
S6S.ai uses Google OAuth for two purposes: authentication (sign-in) and service integration (connecting Google services to your approved actions).
3.1 Google Sign-In Scopes
When you sign in with Google, we request the following scopes:
openid— Verify your identityemail— Receive your email address to create your accountprofile— Receive your name and profile picture for your account
We do not access any other Google data during sign-in.
3.2 Google Service Integration Scopes
When you explicitly connect a Google service to use in approved actions, we request only the scopes necessary for that service. You must grant these permissions separately from sign-in:
https://www.googleapis.com/auth/spreadsheets— Read and write to Google Sheets files referenced by your approved actionshttps://www.googleapis.com/auth/drive.file— Access only the specific Google Drive files your approved actions reference
S6S.ai only accesses the specific files and data your approved actions reference. We never browse, index, or scan your Google Drive or other Google data beyond what those actions explicitly require.
3.3 How We Use Google Data
- Google sign-in data (name, email, picture) is used solely to create and identify your S6S account.
- Google Sheets data is read/written only when an approved action explicitly targets a specific spreadsheet.
- Google Drive data is accessed only when an approved action explicitly references a specific file.
- We do not use Google data for advertising, profiling, or any purpose unrelated to providing the approved action.
- We do not sell, rent, or share Google user data with any third party.
3.4 Google API Services User Data Policy Compliance
Limited Use Disclosure
S6S.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the S6S.ai service as described in this policy.
- We do not transfer Google user data to third parties except as necessary to provide the service (e.g., a connected action that writes to Google Sheets), with your explicit consent, or as required by law.
- We do not use Google user data for advertising or to serve ads.
- We do not allow humans to read Google user data unless: (a) you provide explicit consent, (b) it is necessary for security purposes (investigating abuse), or (c) it is required to comply with applicable law.
3.5 Revoking Google Access
You can revoke S6S.ai's access to your Google data at any time by:
- Removing the Google credential connection in your S6S account settings (this deletes the stored connection)
- Visiting your Google Account Permissions page and removing S6S.ai
Revoking access at Google prevents further access but may not notify S6S to remove its encrypted token record. Remove the connection in S6S as well, or contact us to request deletion.
4. How We Use Your Information
We use collected information to:
- Provide and operate the S6S.ai service
- Create AI Visibility reports, run checks, and store recommendations for your tracked brands
- Run connected actions on your behalf using your connected credentials
- Authenticate your identity and secure your account
- Store chat sessions and recommendation history for your convenience
- Improve recommendation quality using anonymized, aggregated interaction data (with your consent)
- Monitor service health, fix bugs, and improve performance
- Communicate important service updates
5. Cookies
S6S.ai uses a minimal number of cookies, all essential for the service to function:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
s6s_session | Authentication session | 30 days | Essential |
oauth_state | CSRF protection during Google/GitHub OAuth | 10 minutes | Essential |
oauth_from | Redirect destination after OAuth sign-in | 10 minutes | Essential |
All cookies are HTTP-only, Secure (HTTPS only), and use SameSite=Lax. We do not use any advertising, tracking, or analytics cookies.
6. Data Sharing
We do not sell, rent, or share your personal data with third parties, except:
- To run connected actions: When a connected action calls a third-party API (e.g., updating a Google Sheet), the data you configured is sent to that service as directed by you.
- Funded AI Visibility providers: For a permitted measurement, S6S sends the buyer question and relevant market/category context to the enabled business API provider, currently OpenAI or Perplexity. S6S stores returned evidence as described in section 2.2. Gemini grounded measurement and automated consumer-app capture are disabled unless the exact data use is separately authorized.
- AI providers (BYOLLM): If you use your own LLM API key, your chat messages are sent to your configured AI provider (OpenAI, Anthropic, etc.) to generate recommendations or developer automation drafts.
- Infrastructure and operations: Hosting, database, error-monitoring, and email providers may process the minimum data required to operate and secure the service. The final paid-pilot privacy notice will identify active subprocessors, regions, and transfer safeguards.
- Legal requirements: We may disclose data if required by law, regulation, or legal process.
7. Data Security
- All third-party credentials are encrypted at rest using AES-256-GCM
- Sessions use HTTP-only, Secure, SameSite cookies
- All data is transmitted over HTTPS (TLS 1.2+)
- API keys are hashed with SHA-256 at rest
- Security headers enforced: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- Secrets are redacted from execution outputs and logs
- Access to production systems is restricted to authorized personnel
8. Data Retention
- Account data: Retained while your account is active. The account-deletion control removes the account and its associated records from the active database; limited backups, provider logs, security records, or records required by law may follow the separate periods described below.
- AI Visibility data: The current private alpha has no plan-based expiry. Removing a tracked brand hides it from the active product but retains its associated measurement evidence and history. Account deletion or a valid statutory erasure request uses the separate deletion path described above.
- Service improvement: Records retained after a brand is removed may be used to operate and improve the service. This private-alpha retention does not override account deletion, a valid statutory erasure request, or other applicable legal obligations.
- Developer automation data: The current private alpha has no plan-based run-history expiry. Data remains while the automation/account exists unless you delete it.
- Google OAuth tokens: The stored connection is deleted when you remove it in S6S. Revoking only at Google prevents access but should be followed by removal in S6S or a deletion request.
- Chat sessions: Retained for as long as your account is active. You can delete individual sessions at any time.
- AI interaction data: Anonymized interaction metadata (prompt type, accept/reject, latency) may be retained for service improvement. This never includes your credentials, personal data, report content, or automation content unless you opt in.
- Backups, provider logs, and security records: These may follow separate limited retention periods. Exact schedules and subprocessors will be published before a paid external pilot.
9. Your Rights
You have the right to:
- Access your account information and request a copy of data S6S holds about you
- Use the current automated export for a structured subset of account, automation, and AI Visibility records; provider raw output and security-sensitive records are excluded
- Request account deletion or statutory erasure; the active-database deletion path removes the account and associated records, subject to the limited backup, provider-log, security, and legal retention described in section 8
- Remove individual tracked brands from the active product; associated AI Visibility evidence is retained as described in section 8
- Delete individual automations, chat sessions, and credentials using the available controls
- Revoke third-party service connections and remove the stored connection in S6S
- Opt out of contributing AI interaction data for platform improvement
- Opt out of non-essential communications
To exercise any of these rights, contact us at [email protected] or use the controls in your account settings.
10. Children's Privacy
S6S.ai is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes via email or through the platform. Continued use of S6S.ai after changes constitutes acceptance of the updated policy.
12. Contact
If you have questions about this privacy policy, your data, or how we handle Google user data, contact us at:
Email: [email protected]