Security & methodology
How the data is collected — and protected
Every number in Answr traces to one of two first-party sources: answers sampled directly from each platform's official API, or AI crawler and referral activity captured on your own properties. No scraped chats, no gray-market logs.
SOURCE 01
Direct API sampling
Your prompt set runs against each platform's official API on a fixed daily schedule — consistent, trendable, reproducible, and within each provider's terms.
SOURCE 02
First-party telemetry
AI crawler and referral activity captured on your own site through a first-party endpoint — no cookies, no third-party trackers, no shared data.
NEVER
No scraping sessions
No browser extensions harvesting private chats, no purchased session logs, no gray-market data. Ever.
Encryption in transit
HTTPS everywhere, served from the edge
First-party only
No third-party chat scraping
Region choice
Deploy in the region you choose
Compliance
SOC 2 & GDPR alignment on the roadmap
Found a vulnerability?
security@answr.io · we review every responsible-disclosure report and will get back to you.
Responsible disclosure
Data lifecycle
COLLECT
Sampled API answers and first-party telemetry only.
PROCESS
Brand entities and citations extracted; raw text minimized.
STORE
Encrypted at rest with your database provider, in your chosen region.
DELETE
Full workspace purge within 30 days of a closed account.
Subprocessors
VENDORPURPOSEREGION
VercelHosting & edge networkConfigurable region
Your providersModel / database / email keys you connectPer provider
The connected model, database, and email providers you configure become subprocessors. A full list with DPAs is published once those integrations are live.