Privacy Policy

Last updated September 22, 2026

Visibility Kit is a service that tells a website owner how much of their traffic came from AI tools like ChatGPT, Claude, Gemini, and Perplexity. This page explains exactly what that involves: what the tracking script collects, what actually reaches our database, what we throw away, and how long we keep the rest.

Who we are

Visibility Kit is built and operated from Austin, Texas, United States. For anything on this page, write to [email protected].

Two kinds of data, two different roles

It matters which one you are asking about, because our legal role is different in each case.

  • Visitor data. When a site owner installs our tracking script, we process data about that site’s visitors on the site owner’s behalf. They decide to run it and they decide why. Under GDPR they are the controller and we are the processor. If you visited a website and want to know what was recorded about you, the site you visited is the first place to ask, and we will help them answer.
  • Account data. When someone connects a site, we store the email address they connected with and the domain they connected. That is our own record and we are the controller for it.

What the tracking script collects

The script runs in the visitor’s browser on pages of the site that installed it. On each page view it sends us:

  • A random session identifier and a random visitor identifier. Both are generated in the browser. Neither is derived from anything about the person or their device.
  • The referring URL, the landing page URL, the current page URL, and the page title.
  • Campaign parameters in the URL (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and advertising click identifiers (gclid, msclkid, fbclid, ttclid, gbraid, wbraid), when they are present.
  • A timestamp, and which method loaded the script.

No record is sent at all from URLs containing login, password, or unsubscribe, so sign-in and unsubscribe pages are never reported to us.

What we actually keep

Most of what arrives is discarded on receipt and never written down. We only store a record when the visit came from an AI tool. Everything else (direct traffic, organic search, paid clicks, ordinary referrals) is dropped at the point it reaches us and is never stored.

For an AI-referred visit, the record we keep contains:

StoredWhat it is
sessionIdRandom identifier for one visit
visitorIdRandom identifier that ties repeat visits together
source, medium, referrerKeyWhich AI tool sent the visit
referrerThe referring URL
landingPageThe first page of the visit
utmSource, utmMedium, utmCampaign, utmTerm, utmContent, gclidCampaign parameters from the URL, when present
firstSeenAt, lastSeenAt, pageViewsWhen the visit started, when it was last seen, how many pages

The current page URL and the page title are sent by the script but are not written to our database.

What we do not collect

  • No IP addresses. We do not record the visitor’s IP address in our database. Like any web request, the request itself necessarily reveals an IP address to the infrastructure that carries it, and it may appear briefly in our hosting and network providers’ operational logs. We do not extract it, store it, or use it.
  • No user agent, device, or browser fingerprinting. We do not record what browser or device the visitor used, and we do not build a fingerprint.
  • No form data. We do not read, receive, or store the contents of forms submitted on your site, so we hold no names, email addresses, phone numbers, or postal addresses belonging to visitors.
  • No prompts. We do not see the question someone asked an AI tool. The tools do not pass it along, so it never reaches us.
  • No cross-site tracking. The identifiers are first-party. They are scoped to the site that set them and are not shared or matched across the sites that use Visibility Kit.
  • Not anonymous, though. A persistent identifier can still single out a person, so the records count as pseudonymous personal data under GDPR and we treat them that way.

Cookies

The script sets first-party cookies on the site that installed it, and mirrors the same values into that site’s browser storage. The full list, with what each one does and how long it lasts, is on the cookie notice.

Where consent is required, obtaining it is the site owner’s responsibility as the controller. Site owners should connect Visibility Kit only after wiring the script into their consent flow, so that no cookie is set before consent is given.

How long we keep it

  • Visitor records: 30 days. A scheduled job runs every night and deletes every session record older than 30 days. This is automatic and is not something a site owner has to ask for.
  • Account data (the connecting email address and domain) is kept while the account exists, and deleted on request.

Where it is processed

Visibility Kit runs on servers in the United States, in Atlanta, Georgia. If you are in the UK or the European Economic Area, using the service involves transferring data to the United States. Our data processing agreement covers those transfers and incorporates the European Commission’s Standard Contractual Clauses. It applies automatically to every connected site, so there is nothing to request and nothing to sign.

Who else touches it

We do not sell data, we do not share it with advertisers, and we do not use it to train AI models. We use a small number of service providers to run the service, and they are listed, with what each one does and where it is located, on the subprocessor page.

Only our hosting and network providers touch visitor data at all. No analytics provider, advertising network, data broker, or AI vendor receives any part of it.

Security

Traffic to and from Visibility Kit is encrypted in transit. Access to the production database is limited to the people who operate the service. The tracking dataset is deliberately narrow: it holds no IP addresses, no user agents, and no contact details, so the amount of personal data at risk in any incident is small by design, and it is deleted after 30 days.

If we become aware of a breach affecting a site owner’s data, we will notify them without undue delay so they can meet their own obligations.

Your rights

If you are in the UK or the EEA you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive a copy of it. You also have the right to complain to your national data protection authority.

For visitor data the site you visited is the controller, so ask them first and we will help them answer. You can also write to [email protected] directly. Include the value of your _vk_vid cookie if you have it, which lets us find and delete every record tied to you. Clearing your cookies also severs the link, and anything left is deleted within 30 days either way.

If you run a site that uses Visibility Kit

  • You are the controller. You decide to run the script and you are responsible for telling your visitors about it and for obtaining consent where your law requires it.
  • Declare our cookies in your own cookie policy. The cookie notice lists them in a form you can copy.
  • Our data processing agreement already applies to you. It takes effect when you connect a site, so there is nothing to request and nothing to sign.
  • You can stop all collection at any time by disconnecting in the plugin settings, which removes the script from your site.

Changes

If we change what we collect or how we use it, we will update this page and change the date at the top. Where a change is significant we will tell connected site owners directly.

Contact

Visibility Kit is operated by Complete Web Resources LLC, Austin, Texas, United States.
[email protected]