Who is responsible

Pharolo
Pelle Krukow (sole proprietor)
Ballindamm 3
20095 Hamburg
Germany
Email: [email protected]

What Pharolo does

Pharolo reads a public website you name, asks 4 AI assistants (ChatGPT by OpenAI, Gemini by Google, Claude by Anthropic, Perplexity) questions a buyer of that industry would ask, and stores the answers so you can see whether the site is named. This notice explains which data that involves, why, and for how long.

Scanning public websites and AI answers

When you run a scan we fetch the home page, robots.txt, llms.txt, the sitemap and up to 3 pages of the named site, and we store the answers of the assistants word for word, including the names of businesses and pages they mention. Legal basis is Art. 6 (1) f GDPR, our legitimate interest and yours in measuring whether a business is recommended, using only information that is already public. Where an answer names a third party, Art. 14 (5) b GDPR applies, because informing every named business individually would take a disproportionate effort, so this notice is the public information instead. A named business can ask us at [email protected] to see or delete what we hold.

Data the scan stores about you

To limit scans per day we store a salted hash of your IP address and of its network, valid for one day, plus a hashed session key made from IP, browser string, a secret and the day. The raw IP address and browser string are not stored. The IP hashes on the scan are removed after 24 hours; the session key is covered under Cookies and measurement. Legal basis is Art. 6 (1) f GDPR, our interest in keeping the free scan available and in preventing abuse.

The email gate and double opt in

If you ask for the full report we store your email address, a confirmation token, the time of your confirmation, a salted hash of the IP address and the browser string at the moment of confirmation, and the version of the consent text. This is the proof of your double opt in. Legal basis is Art. 6 (1) b GDPR, performance of the service you asked for. The report link works for 7 days; the record is kept as long as the scan is kept.

Tips by email (marketing)

Only if you tick the separate box do we store a marketing consent with the same proof and send occasional emails with tips on AI visibility and measure whether you open them. These emails carry an open pixel and an unsubscribe link, because the consent text says so. Legal basis is Art. 6 (1) a GDPR. You can withdraw at any time through the link in every email; the withdrawal is stored for 3 years as proof.

Accounts, billing and invoices

For a paid plan we store your company name, address, VAT ID, email, password hash, plan, and the Mollie customer and mandate identifiers. To grant one trial per payment method we also store a salted hash of the fingerprint Mollie gives us for the payment method, never the card number. Payments are processed by Mollie B.V., Amsterdam; we never see the full card number. Invoices are kept for 10 years under § 147 AO. Legal basis is Art. 6 (1) b and c GDPR.

Recipients

Every recipient gets only what its job needs.

  • OpenAI (USA) answers the buyer questions as ChatGPT. It receives the question, the country of the market and the language to answer in, never your email or account data. Transfer under standard contractual clauses.
  • Google (USA) answers as Gemini and receives the same. Transfer under standard contractual clauses.
  • Anthropic (USA) answers as Claude and receives the same. Anthropic also runs our analyst, which detects the industry, writes the questions and extracts the competitors from the answers. For that it receives the text of the pages we fetched from the scanned site, the industry, language, market and place, and the assistants' answers word for word. Transfer under standard contractual clauses.
  • Perplexity (USA) answers as Perplexity and receives the question, the market and the language. Transfer under standard contractual clauses.
  • Mollie B.V. (Netherlands) processes payments and holds the payment mandate.
  • Mailjet (France, Sinch) sends our email. It receives the address and the content of every email.
  • Hetzner (Germany) hosts our servers.
  • Cloudflare (USA) sits in front of the site and forwards every request to us, so it sees your IP address and the pages you call. Transfer under standard contractual clauses.
  • Discord (USA) receives error alerts for the founder. Email addresses and tokens are removed before sending. Transfer under standard contractual clauses.

A copy of the standard contractual clauses is available from [email protected].

Cookies and measurement

The public pages set no cookies and use no tracking pixels or fingerprinting. We count steps of the funnel server side with the hashed session key described above, without identifying you, under § 25 (2) TDDDG and Art. 6 (1) f GDPR. The key changes every day, and the funnel events are deleted after 90 days. Signed in users get one session cookie, which is strictly necessary for the service.

Retention

  • Free scans and their answers: 30 days, 90 days once a report link for the scan was confirmed.
  • IP hashes on scans: 24 hours.
  • Report links: 7 days after confirmation; the confirmation record stays as long as the scan.
  • Funnel events with the daily pseudonymous session key: 90 days.
  • Consent proof for marketing emails, including the browser string: until withdrawal, then 3 years as proof.
  • Mail log with the address, kind and subject of every email we send: 1 year.
  • Hash of the payment method fingerprint for the one trial per payment method: 2 years after it was last seen.
  • Account data: for the contract plus the legal retention periods, invoices 10 years.
  • Error logs: 90 days.
  • Support emails: 1 year.

Right to object

You can object at any time to processing that rests on Art. 6 (1) f GDPR for reasons arising from your particular situation, and we then stop unless we can show compelling legitimate grounds. You can object to direct marketing at any time without giving reasons, through the unsubscribe link in every marketing email or by writing to [email protected].

Your rights

You can ask for access, rectification, erasure, restriction and portability of your data. Write to [email protected]. You can complain to a supervisory authority; ours is the Hamburg Commissioner for Data Protection and Freedom of Information.

Version

This notice is version 2026-09-01. The German version is the binding one.