Privacy Policy
Bridger AI
Last Updated: July 24, 2026
This Privacy Policy explains how Bridger AI ("we," "us," or "our") collects, uses, stores, and protects personal information when you use the Bridger platform and related services. We are committed to protecting your privacy and handling your data responsibly.
1. Information We Collect
We collect the following categories of information: Account Information: name, email address, and subscription/billing status. Usage Data: website URLs submitted for analysis, report generation activity, tab interactions, leaderboard opt-in status, shareable teaser link creation, AI Brief generation, presentation and full-report share link creation, shared client Fix Tracker (Client Portal) views, Fix Tracker updates, scheduled re-analysis configurations, Competitor Watch configurations, Compete/Compare sessions, agency outreach pipeline activity (prospect domains, generated emails, send status), bulk audit activity, auto-discovered page URLs (Growth/Agency plans), public API call logs including timestamps and analyzed URLs (API plans), team member invitations (Agency plan), integration connection status (Slack, HubSpot, Notion, Google Docs), promo code redemption activity, and session interaction logs. Device & Technical Data: IP address, browser type, operating system, and device identifiers collected automatically via standard web server logs. Payment Data: Payments are processed by Stripe. BRIDGED does not store full payment card numbers. We retain Stripe customer IDs, subscription IDs, and subscription status to manage your plan. Agency Credentials (Agency plan only): If you use the outreach pipeline, you provide a Hunter.io API key and connect your own Gmail account via OAuth to send outreach emails. The Hunter.io key is stored encrypted; Gmail access is granted through an OAuth token you authorize and can revoke at any time. These are used solely to execute outreach on your behalf and are not used for any other purpose. Website Content Data: Publicly accessible webpage content (HTML, headings, body copy, meta tags, structured data, navigation links, CTA buttons) is temporarily fetched and processed by AI models to generate analysis results. Raw HTML is not stored beyond what is needed to produce the report. Screenshot Data: Page screenshots are captured via Thum.io (image.thum.io) as part of the visual analysis and are stored as part of the report. Rendered Content Data (via Jina Reader): For JavaScript-heavy websites, page content is fetched through Jina Reader (r.jina.ai), which renders the page and returns it as markdown. This data is used for content analysis and auto page discovery (Growth/Agency plans). SEO & Performance Data: We retrieve Core Web Vitals (LCP, FCP, CLS, TTI) and performance, accessibility, SEO, and best-practices scores from the Google PageSpeed Insights API for analyzed URLs. Traffic Estimation Data: Website URLs are submitted to Ahrefstop (via Jina) to estimate monthly visitor counts for revenue loss calculations. No personal identifiers are associated with these queries. Security & Reputation Data: Analyzed domain names are checked against Google Safe Browsing API (for malware/phishing threats), DNS-based blocklists (SURBL via multi.surbl.org, Spamhaus DBL via dbl.spamhaus.org) queried through Cloudflare DNS (1.1.1.1), and Whois.com (for domain registration age). These checks produce reputation signals but do not transmit any user personal data. AI Visibility Data: Analyzed domain names are checked against Perplexity.ai search results (via Jina) to determine whether the domain appears in AI-generated answers for relevant industry queries. Promo Code Data: If you redeem a promotional code, we record the code used, your user ID, and the resulting tier and expiry.
2. How We Use Your Information
We use collected data to: provide and operate the Service, generate AI-powered website analysis reports across all scoring dimensions (design, messaging, trust, conversion, SEO, performance, accessibility, generational reactions, AEO, psychological friction, dark patterns, AI visibility, content freshness, intent alignment, form friction, pricing friction, and industry percentile), process Google PageSpeed and accessibility data, fetch rendered page content via Jina Reader, capture page screenshots via Thum.io, estimate traffic data via Ahrefstop, check domain reputation via Google Safe Browsing, DNS blocklists (SURBL, Spamhaus), and Whois.com, check AI visibility via Perplexity.ai, run Competitor Watch monitoring and alerts, power the Compete/Compare tool, auto-discover and crawl additional pages (Growth/Agency plans), generate shareable teasers and AI Briefs, track Fix Tracker progress, execute agency outreach pipeline runs (Hunter.io lookup + Gmail SMTP delivery), process bulk audit requests, manage agency client records (creative approvals, scope tracking, client asset library), serve public API calls and enforce monthly call limits (500 or 5,000), send invited team members their invitation emails (Agency plan), push report data to connected integrations (Slack, HubSpot, Notion, Google Docs) on your behalf, schedule and execute automated re-analysis on user-configured intervals, auto-discover internal pages via Jina link summaries for multi-page analysis (Growth/Agency), display public leaderboard rankings for opted-in analyses, process payments and manage subscription status, validate and apply promo code redemptions, generate AI-powered copy rewrites for headlines, meta descriptions, CTAs, and value propositions (Pro+ plans), communicate service updates and support responses, detect and prevent fraud and abuse (including automated trust flagging of scam sites via Google Safe Browsing and DNS blocklists), and improve platform performance and develop new features. We may use aggregated, anonymized data for research and product improvement with no individual identification.
3. AI and Third-Party Services
To provide the Service, we transmit relevant data to the following third-party providers: — AI Language Model Providers (OpenAI, Google Gemini, Anthropic Claude): Website content, metadata, structural signals, and contextual business information are sent to LLM APIs to generate analysis scores, summaries, persona models, improvement recommendations, copy rewrites, and competitor benchmarks. These providers process data under their respective privacy policies. — Google PageSpeed Insights API: Website URLs are submitted to Google to retrieve Core Web Vitals and performance, accessibility, SEO, and best-practices metrics. — Jina Reader (r.jina.ai): Website URLs are submitted to Jina to fetch rendered page content as markdown. Jina renders JavaScript-heavy pages that standard HTTP requests cannot fully render. Jina also provides link summaries for auto page discovery on Growth and Agency plans. Data handling is governed by Jina's privacy policy. — Thum.io (image.thum.io): Website URLs are submitted to Thum.io to capture visual screenshots of analyzed pages for inclusion in reports. — Ahrefstop (via Jina): Domain names are used to estimate monthly website traffic volumes. No personal user data is transmitted. — Google Safe Browsing API: Analyzed URLs are checked against Google's threat database (malware, social engineering, unwanted software). No personal user data is transmitted. — Cloudflare DNS (1.1.1.1): Domain names are queried against DNS-based blocklists (SURBL multi.surbl.org, Spamhaus DBL dbl.spamhaus.org) to check domain reputation. Cloudflare processes DNS queries under their privacy policy. Only the domain being analyzed is transmitted — no personal user data. — Whois.com: Domain names are queried to retrieve registration dates for domain age assessment. No personal user data is transmitted. — Perplexity.ai (via Jina): Industry-related search queries are submitted to Perplexity to check whether the analyzed domain appears in AI-generated answers. No personal user data is transmitted. — Stripe: Payment and subscription data is processed by Stripe under their privacy policy. We do not store payment card details. — Hunter.io (Agency plan, outreach pipeline): Prospect domains are submitted to Hunter.io to discover contact emails. This is governed by Hunter.io's privacy policy. Your Hunter.io API key is used solely for lookups you initiate. — Gmail (Agency plan, outreach pipeline): Outreach emails are sent via your own connected Gmail account using an OAuth token you authorize. BRIDGED does not read your Gmail inbox or access any data beyond sending the outreach emails you approve. You can revoke Gmail access at any time from your Google account settings. — Slack, HubSpot, Notion, Google Docs (optional integrations): Report data you choose to push is transmitted to these platforms using OAuth tokens you authorize. Data handling on those platforms is governed by their respective privacy policies. — Email Delivery: We use a transactional email provider to send report emails, team member invitations, API welcome emails, payment receipts, and system notifications. All third-party services are selected for their data protection standards. We do not sell data to third parties.
4. Leaderboard and Public Data
Users who opt in to the public leaderboard consent to having their website domain, analysis scores, and summary metrics displayed publicly on www.mybridged.app. This data is visible to all visitors. Users may remove their listing at any time from within their analysis report page. Sites flagged by our automated trust analysis system — which includes Google Safe Browsing, DNS blocklists (SURBL, Spamhaus), and Whois.com checks — as potentially fraudulent are automatically excluded from public display.
5. Shareable Links and AI Briefs
When you generate a shareable teaser link or AI Brief for an analysis, a summary of that analysis (scores, key findings, website URL) becomes accessible to anyone with the link. You control whether to generate or share these links. You may deactivate shareable content from within your analysis at any time. BRIDGED is not responsible for downstream distribution of shared links.
6. Agency Outreach Pipeline
If you use the Agency outreach pipeline, prospect contact emails discovered via Hunter.io and the generated outreach emails are stored associated with your agency account to support your review and approval workflow. This data is not shared with other users or sold. Prospect data is retained until you delete it or your Agency subscription ends. You are responsible for ensuring lawful basis to contact prospects under applicable laws (CAN-SPAM, GDPR, CASL, etc.). Gmail access is granted via OAuth — BRIDGED never sees or stores your Gmail password.
7. Public API
API plan subscribers' call logs (timestamps, analyzed URLs or analysis IDs, response metadata) are retained to enforce monthly usage limits (500 or 5,000 calls) and for billing verification. API keys are derived via HMAC-SHA256 from a server-side secret and the user ID — they are not recoverable in plaintext after creation. API keys must be passed in the X-API-Key HTTP header and must match the "brg_" + 40 hex character format. Rate limit headers (X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Reset) are returned with each API response.
8. Team Accounts (Agency Plan)
When an Agency plan subscriber invites a team member, we collect and store the invited member's name and email address in order to send the invitation and associate them with the agency account. Team member data is deleted or marked as removed when the account owner removes the member or when the Agency subscription ends.
9. Cookies and Tracking
We use session cookies and local/session storage to maintain user state (e.g., login sessions, pending analysis submissions, theme preferences). We do not use third-party advertising trackers or behavioral targeting cookies. Analytics data, if collected, is aggregated and anonymized. Users may disable cookies through browser settings, though some features (including authentication) require cookies to function.
10. Data Sharing
We do not sell personal information. We share data only with: AI model providers (OpenAI, Google Gemini, Anthropic Claude — for analysis generation), Google (PageSpeed Insights API, Safe Browsing API), Jina Reader (r.jina.ai — page content rendering), Thum.io (screenshot capture), Ahrefstop (traffic estimation, via Jina), Cloudflare DNS (1.1.1.1 — blocklist queries), Whois.com (domain age lookups), Perplexity.ai (AI visibility checking, via Jina), Stripe (payment processing), Hunter.io (Agency outreach prospect lookup), email delivery providers (for report and invitation emails), Slack / HubSpot / Notion / Google Docs (when you explicitly push data via integrations), and legal or regulatory authorities when required by applicable law. All providers are contractually required to protect data appropriately.
11. Data Security
We implement industry-standard security measures including: TLS encryption in transit, encrypted storage of sensitive credentials (API keys, Hunter.io keys, Gmail App Passwords), access controls and authentication requirements, API key format validation and header-only transmission (no URL parameters), rate limiting on public API and analysis endpoints, secure cloud infrastructure, and regular security reviews. However, no system is completely secure. You transmit information to the Service at your own risk and should use secure network connections.
12. Data Retention
Analysis records are retained as long as your account is active and for up to 90 days after account termination. Subscription and billing records are retained as required by applicable financial regulations. Raw scraped HTML is not stored beyond immediate processing needs — only extracted signals, scores, and the final analysis result are persisted. Rendered page content from Jina Reader is used for analysis and not permanently stored. Agency outreach prospect records are retained until deleted by the account owner or until subscription termination. API call logs are retained for the current and previous billing month for usage enforcement. Team member records are retained until removed by the account owner or until subscription termination. Promo code redemption records are retained for audit purposes. You may request deletion of your personal data at any time by contacting support@mybridged.net.
13. User Rights
Depending on your jurisdiction, you may have rights including: access to your personal data, correction of inaccurate data, deletion of your data, restriction of processing, data portability, and the right to withdraw consent. To exercise any of these rights, contact us at support@mybridged.net. We will respond within 30 days.
14. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect personal data from minors. If we become aware that a minor has created an account, we will delete the account promptly.
15. International Data Transfers
Your data may be processed in countries where our infrastructure providers, AI model providers, and third-party services operate, including the United States and EU member states. This includes processing by OpenAI, Google, Anthropic, Jina, Thum.io, Cloudflare, and other service providers operating globally. We take reasonable measures to ensure appropriate data protection standards are maintained across all processing locations.
16. GDPR Compliance
For users in the European Economic Area (EEA), we process personal data under the following lawful bases: contractual necessity (to deliver the Service), legitimate interests (security, fraud prevention via Google Safe Browsing and DNS blocklists, product improvement), consent (leaderboard opt-in, shareable links, marketing communications), and legal obligation. EEA users have the right to lodge a complaint with their local data protection supervisory authority. Contact us at support@mybridged.net to exercise your GDPR rights.
17. CCPA Compliance
For California residents, we comply with the California Consumer Privacy Act (CCPA). You have the right to: know what personal information is collected about you, request deletion of your personal information, opt out of the sale of personal information (we do not sell personal information), and not be discriminated against for exercising your rights. To make a CCPA request, contact support@mybridged.net.
18. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our data practices, the Service, or applicable law. We will make reasonable efforts to notify users of material changes via email or in-app notice. Continued use of the Service after updates constitutes acceptance of the revised policy.
19. Contact Information
For questions, data requests, or privacy concerns, contact: BRIDGED — support@mybridged.net