Privacy policy

Last updated: 8 June 2026

Nearsited is operated by Again Labs, a proprietorship registered in Kerala, India. This policy explains what data we collect, why we collect it, and how we handle it. We built Nearsited as a solo founder product — we have no data-brokering business, no ad network, and no incentive to sell your information.

1. What We Collect

1.1 Account information

When you sign up, we collect your email address and full name. If you use Google OAuth, we receive only your name and email from Google — we do not receive access to your Google Drive, Calendar, or any other Google service.

1.2 Business discovery data (Google Places)

When you run a discovery search, Nearsited queries the Google Places API on your behalf. The results — business names, addresses, phone numbers, websites, ratings, and review counts — are returned by Google and cached in our database for up to 7 days to reduce redundant API calls. This cache is scoped to your account. The data belongs to Google’s Places index; we are intermediaries, not the source.

1.3 Website audit data (PageSpeed)

When you run an audit on a business website, we send the website URL to Google’s PageSpeed Insights API. The API returns performance scores, SEO scores, and Core Web Vitals (FCP, LCP, TBT, CLS). We store these results in your account’s audit history so you can reference them without re-running the audit. We do not store any content from the target website itself — only the scores and metrics.

1.4 Website screenshots (ScreenshotCore)

Design analysis requires a screenshot of the target website. We send the website URL to ScreenshotCore, which captures a full-page screenshot and returns it as an image. We temporarily hold this image in memory for the duration of the Gemini analysis call, then we do not persist it to storage. The URL of the target website is shared with ScreenshotCore only for the duration of the screenshot request.

1.5 Pitch generation inputs (Gemini AI)

When you generate a pitch, we send a prompt to Gemini (Google AI) that includes: the business name and type, performance scores from the audit, design issues identified by the analysis, and your selected tone and channel. We do not send your personal details or contact list to Gemini.

These inputs are not used to train AI models.We use the Gemini API under Google Cloud’s standard terms, which prohibit using API requests to improve Google’s models unless you explicitly opt in. We have not opted in.

1.6 Leads, pipeline, and pitches (your data)

Leads you save, pipeline entries, notes, and generated pitches are stored in your account on our Supabase database. This data is yours. We do not analyse it, share it, or use it for any purpose other than providing the service to you.

1.7 Usage analytics

We collect basic usage data — which pages you visit, which features you use, and how often — to understand how the product is being used and where it needs improvement. This data is anonymised and not tied to identifiable individuals in our analytics system.

2. How We Use Your Data

  • To provide and maintain the Nearsited service.
  • To process payments and manage your subscription via Dodo Payments.
  • To send service-related emails: payment receipts, subscription updates, account notifications. We do not send marketing emails unless you opt in.
  • To improve the product based on how it is used (anonymised usage data only).
  • To detect and prevent abuse, fraud, or violations of our Terms of Service.

We do not sell your data. We do not share your leads with competitors. We do not use your business data to train AI models. We do not use your data for advertising.

3. Third-Party Services

Nearsited relies on the following third-party services to operate. Each service receives only the minimum data required for its function:

Supabase (Supabase Inc., USA)

Database, authentication, and file storage. Stores your account data, leads, pitches, audits, and pipeline entries. All data at rest is encrypted. We use Supabase’s Row Level Security to ensure users can only access their own data.

Dodo Payments

Payment processing for Solo, Agency, and Scale subscriptions. We never store, see, or access your full payment card details. Dodo Payments holds all payment instrument data. Dodo shares only subscription status, renewal dates, and payment confirmation with us.

Google Cloud — Places API, PageSpeed API, Gemini API

Places API: receives city name and business type to return business listings. Returns business names, addresses, websites, ratings.
PageSpeed API: receives the URL of a target business website (not your URL) and returns performance metrics.
Gemini API: receives structured prompts containing business data and your pitch preferences (tone, channel, focus). Returns generated pitch text. Inputs are not used for model training.

ScreenshotCore

Receives the URL of a target business website to capture a screenshot for design analysis. We do not send any personal data to ScreenshotCore. Screenshots are used transiently for Gemini analysis and are not stored.

Each third-party service is subject to its own privacy policy. We review these annually and will update this section if our service stack changes.

4. Data Retention

  • Account data: retained for as long as your account is active.
  • Leads, audits, pitches, pipeline: retained until you delete them or delete your account.
  • Google Places cache: individual place records expire after 7 days and are refreshed on next lookup.
  • PageSpeed audit results: retained until you delete the associated lead or your account.
  • After account deletion: all personal data is deleted or anonymised within 30 days. Anonymised aggregate usage data (e.g. “N users ran searches in this city”) may be retained for product analysis.
  • Payment records: retained for 7 years as required by Indian GST regulations.

5. Cookies & Tracking

We use only the cookies necessary to run the service:

CookiePurposeExpires
sb-access-tokenSupabase session auth token — keeps you logged in1 hour
sb-refresh-tokenRefreshes your session token automatically7 days

We do not use advertising cookies, tracking pixels, or any third-party analytics platform that links usage to your identity. Blocking the Supabase session cookies will prevent you from logging in.

6. Your Rights

Regardless of where you are located, you have the following rights over your data at any time:

  • Access: request a copy of the personal data we hold about you.
  • Correction: update or correct inaccurate data in your account settings.
  • Deletion: delete your account and all associated data from Settings → Data & Privacy.
  • Export: download a JSON export of all your data from Settings → Data & Privacy.
  • Objection: opt out of usage analytics by emailing us — you will retain full service access.

6.1 EU / EEA / UK users (GDPR)

If you are in the EU, EEA, or UK, the General Data Protection Regulation applies to our processing of your personal data. In addition to the rights above, you have:

  • The right to data portability (machine-readable export — available from Settings).
  • The right to restrict processing (we stop using your data while a dispute is pending).
  • The right to withdraw consent at any time.
  • The right to lodge a complaint with your local supervisory authority.

Our lawful basis for processing: performance of contract (providing the service) for account and lead data; legitimate interest (improving the product) for anonymised usage data.

6.2 UAE users (PDPL)

If you are in the UAE, the Personal Data Protection Law 2021 applies. You have the right to access, correct, and request deletion of your personal data. Contact us at nearsitedlabs@gmail.com to exercise these rights. We will respond within 30 days.

6.3 California users (CCPA)

We do not sell personal information as defined by the CCPA. California residents have the right to know what personal information we collect, request its deletion, and opt out of any sale (there is none). To exercise these rights, email nearsitedlabs@gmail.com.

To exercise any of these rights, email nearsitedlabs@gmail.com. We will respond within 30 days. Account deletion is available immediately from your account settings.

7. International Transfers

Again Labs is based in Kerala, India. Our infrastructure is hosted on Supabase (servers in USA and EU regions), and we use Google Cloud services (global). By using Nearsited, you acknowledge that your data may be processed in the USA, EU, or India.

For EU/EEA users, transfers to the USA rely on Standard Contractual Clauses (SCCs) as the safeguard mechanism. For UK users, the UK International Data Transfer Agreement (IDTA) applies where relevant.

8. Changes to This Policy

We will notify you by email of any material changes to this policy — those that change what data we collect, with whom we share it, or how long we retain it — at least 14 days before the changes take effect. Minor clarifications may be made without notice; the “Last updated” date at the top of this page reflects every change.

Privacy questions or data requests? Email nearsitedlabs@gmail.com — we aim to respond within 2 business days.

See also: Terms of Service