Legal

Privacy Policy

Leadstore · Effective October 2, 2026

1. Who We Are

Leadstore (https://leadstore.xyz) is an AI visibility platform. This Privacy Policy applies to the Leadstore mobile app, web app, ChatGPT plugin and MCP connector ("the App"). When this policy says "we", "us", or "our", it means the team that operates Leadstore.

Questions or requests about this policy should be directed to support@leadstore.xyz.

2. What Data We Collect

We collect the following categories of data when you use the App:

■Account data: email address, username, hashed password (never stored in plaintext), email verification status, and, if you use Google Sign-In, a Google account identifier.
■Site profile data: business website URLs, Google Play listing URLs, and App Store listing URLs that you add to your account.
■Audit and analytics data: audit scores, channel results, generated files (llms.txt, llm-data.json), and tag telemetry collected by the Leadstore tracking tag you deploy on your own websites.
■Session data: JWT access tokens and refresh tokens stored locally on your device and used to authenticate API requests.
■Integration data: access tokens or credentials for services you connect (Google Search Console, Google Analytics 4, and CMS platforms such as WordPress, Webflow, Shopify, Sanity and Framer), and the data those services return for your sites.
■Content and research data: blog drafts, content plans, keywords, competitors, tracked prompts, knowledge-base entries and off-site opportunities you create or approve.
■Billing data: plan and subscription status. Payments are handled by our payment processor; we do not receive or store full card numbers.
■Device data: push notification tokens, if you allow notifications.
■Usage data: server logs including IP addresses, request timestamps, and API endpoints accessed, retained for security and debugging purposes.

3. How We Use Your Data

We use the data we collect exclusively to:

■Create and authenticate your account.
■Run audits and return results for the site profiles you add.
■Generate and serve llms.txt and llm-data.json files.
■Display tag telemetry and analytics tied to your connected site profiles.
■Send email verification and password reset emails you request.
■Process and execute account deletion requests.
■Detect and prevent abuse, fraud, and unauthorised access.

We do not sell your personal data. We do not use your data to train AI or machine learning models. We do not share your data with third parties for advertising or marketing purposes.

4. Who We Share Data With

We share data only with service providers that help us run the App, and only what each needs to do its job:

■AI model providers (OpenAI, Anthropic, Google, Perplexity, Groq): the prompts, site content and brand details needed to run visibility checks and write or review content.
■Search and SEO data providers (such as DataForSEO): keywords, domains and competitor names needed for rankings, backlinks and keyword research.
■Email delivery (Resend): your email address, for account and notification emails.
■Payment processors (Paddle, Chargebee): billing details for subscriptions.
■Hosting, security and network providers (such as Vercel and Cloudflare) and IP geolocation (IPinfo): request data needed to serve the App and protect it from abuse.
■Services you connect (Google, your CMS): the data needed to read reports or publish content you approve.
■Authorities, when required by law.

5. AI Assistant Plugin and MCP Connector

Leadstore is also available as a plugin in the ChatGPT plugin directory and as an MCP connector for other AI assistants. The ChatGPT plugin is published by Towsif Ahamed, one of the people who operate Leadstore, and this policy covers it.

When you connect the plugin, you sign in to your own Leadstore account through OAuth. The plugin acts only as you and can read or change only your own Leadstore data. It receives the inputs the assistant sends to each tool call; it does not read your chat history. Tool results are returned to the assistant you are using, whose provider handles them under its own privacy policy. Billing and subscription details are never returned to the assistant.

You can revoke the plugin's access at any time by disconnecting it in your assistant's settings or by contacting us.

6. Tag Telemetry

The Leadstore tracking tag is a JavaScript snippet you choose to deploy on your own website. It collects visitor traffic signals (events, bot classifications, page URLs, device types, geography, referrers) from your website and sends them to our collection endpoint. This data is associated with your site profile, not with individual end users of your website. Leadstore is a data processor for this telemetry; you, as the website operator, are the data controller and are responsible for appropriate disclosures to your own users.

7. Google Sign-In

If you register or sign in with Google, we receive a Google ID token containing your email address and Google account identifier. We do not receive or store your Google password. You can unlink Google Sign-In by deleting your account.

8. Data Retention

We retain your account data for as long as your account is active. When you request account deletion, a 7-day grace period begins during which you may cancel the request. If the request is not cancelled, your account credentials are permanently scrambled (email, username, and password are overwritten with irreversible random values), your Google identifier is cleared, and your account is flagged as deleted. Your site profiles, audits, and tag telemetry remain in our database in anonymised form for aggregate analytics purposes; they are no longer linked to you or any identifiable individual.

Server logs are retained for up to 90 days for security purposes. Integration credentials are kept while the integration is connected, and you can disconnect any integration from the Integrations screen.

9. Security

Passwords are stored using bcrypt hashing. Tokens are JWT-based and scoped to your account. All API communication is over HTTPS. We enforce mobile-app-only access for account deletion operations to meet platform security requirements.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

■Access the personal data we hold about you.
■Correct inaccurate personal data.
■Request deletion of your account and personal data (see Section 6).
■Object to or restrict certain processing.

To exercise any of these rights, contact us at support@leadstore.xyz. You can also delete your account directly from the Settings screen inside the App.

11. Children

The App is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, contact us at support@leadstore.xyz and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.

13. Contact

For any privacy-related questions, contact us at support@leadstore.xyz.