Privacy Policy

Updated: August 10, 2026

Effective immediately for new customers. For existing customers, these changes take effect September 9, 2026 (30 days' notice, per the prior Terms).

Who we are

Geotally is operated by BestDid Technology, LLC (“BestDid”, “we”, “us”). Geotally is an AI brand-visibility tracker: you tell us which brands and which questions (“prompts”) you want to monitor, we ask AI answer engines those questions on a schedule, and we analyse the answers for mentions of your brand and your competitors.

This policy explains what we collect, why, who we share it with, how long we keep it, and what you can do about it. It applies to the Geotally website (geotally.ai), the Geotally web application (app.geotally.ai), and the Geotally iOS app.

Contact: support@geotally.ai

For customers in the EU, EEA, or UK, BestDid Technology, LLC is the controller of the account data described in this policy. Where you use Geotally to process data on behalf of your own clients, we act as your processor under our Data Processing Agreement.

What we collect

We do notcollect your device location, your contacts, your photos, your health data, or any advertising identifier. The “country” you set on a prompt is a market you want measured — it is not read from your device.

How we use your data, and our lawful basis

Under EU and UK data-protection law we must tell you the lawful basis for each purpose (GDPR Article 6).

We do not sell your personal information. We do not share it for cross-context behavioural advertising. We do not use it for advertising of any kind, and we do not track you across other companies' apps or websites. We do not use your brands, prompts, or the AI responses you collect to train our own models, and we use the AI providers listed below on commercial API terms under which submitted content is not used to train their models.

What we send to AI engines

When one of your prompts runs, we send the prompt text you wrote, and a country and language code to the engine providers you have enabled. We do not send your email address, your name, your account identifier, or your billing information to any AI engine.

Two optional features send data to AI providers outside the normal run path. Prompt research and competitor discovery send your brand name, domain, and country to OpenAI or Anthropic to suggest prompts and competitors. Social pulse, where enabled, sends the brand and competitor names (not your prompts) to xAI once a week to summarise public discussion on X, and verifies the cited posts against the X API.

Sub-processors

We share the minimum data necessary with the companies below. Each is bound by a written data-processing agreement.

Infrastructure

AI engines and research

Payments and mobile

Website only

We will notify you by email at least 30 days before adding a sub-processor that materially expands the categories of data processed. You may object; if we cannot accommodate the objection, you may cancel and receive a pro-rated refund of unused fees.

Cookies and tracking

In the web app (app.geotally.ai) we set exactly one cookie: bdgt_session. It holds a signed JSON Web Token that keeps you logged in. It is HttpOnly and Secure, cannot be read by JavaScript, expires after 7 days, and is shared with no third party. It is strictly necessary, so it does not require prior consent under Article 5(3) of the ePrivacy Directive.

There is no analytics in the web app and none in the iOS app.

On the marketing website (geotally.ai) we use Google Analytics to count visits. It is off by defaultunder Google Consent Mode v2 and runs only if you press “Accept” in the cookie banner. You can withdraw consent at any time using the “Cookie settings” link in the footer. Full details are in our Cookie Notice.

We set no advertising cookies, no remarketing pixels, and no social-network tracking pixels. The iOS app contains no advertising SDK, no analytics SDK, and no advertising identifier, and it does not ask for App Tracking Transparency permission because it performs no tracking as Apple defines it.

The iOS app

The Geotally iOS app stores your session token in the device keychain (iOS Secure Enclave-backed secure storage). If you allow notifications, we store your device's push token so we can send you product notifications — a run finishing, a report being ready, a cost-cap warning. We send no marketing or advertising push notifications. You can turn notifications off at any time in iOS Settings, and revoking permission stops delivery.

Subscriptions bought in the app are processed by Apple. We never receive your payment details. See our Terms of Service for the subscription terms.

How long we keep data

Your rights

Depending on where you live you may have the right to access, correct, delete, restrict, object to, or export your personal data, to withdraw consent, and to lodge a complaint with your data-protection authority.

Two of these are self-serve and immediate. You do not need to email anyone.

You can also delete any individual brand from the dashboard at any time, which removes its prompts, runs, snapshots, and reports.

For anything else — access requests, correction, restriction, objection, or if you cannot reach the account settings — email support@geotally.ai from the address on your account. We acknowledge within 5 business days and respond fully within the 30 days required by GDPR Article 12(3). If a request is complex we may extend by up to two further months and will tell you why.

Withdraw consent for the weekly digest at any time via the unsubscribe link in the email or in Account › Preferences.

Notice for California residents

In the last 12 months we collected these categories of personal information under the CCPA/CPRA: identifiers (name, email address, account identifier, IP address, device push token); commercial information (subscription tier and status, transaction identifiers); internet or network activity (login events, request paths, user-agent strings); other information you provide (brand names, prompt text, support ticket content); and inferences (brand-visibility and sentiment scores derived from AI engine responses).

We collect it for the purposes described above and disclose it only to the sub-processors listed above, for those purposes.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16.

You have the right to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them. Use the self-serve export and delete controls described above, or email support@geotally.ai. We will verify your request against the email address on your account. You may use an authorised agent; we will ask for proof of authorisation.

International transfers

Our infrastructure is hosted in the United States. When personal data leaves the EEA, Switzerland, or the UK we rely on:

Copies of the clauses are annexed to our Data Processing Agreement and available on request.

Security

All traffic is encrypted in transit with TLS 1.2 or better. Passwords are stored only as bcrypt hashes. Two-factor secrets and WordPress application passwords are encrypted at rest with AES-256-GCM. Database volumes and backups are encrypted at rest. Sessions can be revoked instantly server-side, and changing your password or disabling two-factor authentication invalidates existing sessions. Access to production systems is restricted to BestDid staff using multi-factor authentication. Accounts are protected by rate limiting on sign-in, password reset, and passkey authentication.

No system is perfectly secure. If you believe your account has been compromised, email support@geotally.ai immediately.

Automated processing

Geotally uses third-party large language models to retrieve and summarise answers to prompts you author, and applies automated extraction to identify brand mentions, recommendations, citations, and sentiment.

These outputs are estimates for marketing analysis, not facts and not guarantees. Geotally does not make automated decisions producing legal or similarly significant effects concerning you within the meaning of GDPR Article 22. You remain in control of every business decision you make with the information.

Children

Geotally is a business tool for adults. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, email support@geotally.ai and we will delete it.

Changes to this policy

We may update this policy. If we make a material change we will email the address on your account and post the updated policy here with a new effective date. Where a change requires your consent, we will ask for it before it takes effect.

Contact

Questions about this policy, or about your data:

BestDid Technology, LLC support@geotally.ai

You also have the right to lodge a complaint with your local supervisory authority. In the UK that is the Information Commissioner's Office (ico.org.uk).