Skip to main content

Security & Data Handling

How AnswerMetrix handles your data and your visitors' data.

This page describes what the AnswerMetrix platform collects, how it is used, where it is stored, and how it is protected. Last updated: 15 September 2026.

If you have a security concern or vulnerability to report, contact us at [email protected].

What the embed script does

The AnswerMetrix embed script (engine.js) is a lightweight JavaScript file served from api.answermetrix.com. When installed, it:

  • Applies compatible, authorised browser changes, such as supported schema and image descriptions, when the page loads
  • Reads the current page URL to determine which approved fixes to apply
  • Uses the page path and configured improvement data for SEO delivery; standard web requests also expose network information to the serving infrastructure
  • Does not set first-party cookies on visitor browsers
  • Uses browser storage for functions including a per-tab visit identifier, caching and installed modules; it does not require a visitor account

Embed changes are applied in the browser. Removing the script stops those changes on subsequent page loads. Native CMS and edge changes use separate delivery and rollback paths.

AI Crawler Intelligence events

The embed can record recognised crawler user agents and AI referral sources when its JavaScript runs. These observations do not prove indexing or capture crawlers that never execute the script. Events are sent to api.answermetrix.com/api/snippet/ai-event.

This event contains:

  • The page path being visited
  • An event type and recognised crawler or referral source
  • A per-tab session identifier; the server records the event time
  • Your website identifier

Page paths, referral observations and session identifiers are usage data. Removing the embed stops its browser events on subsequent loads; separately configured server or edge integrations have their own controls.

Connected analytics and visitor tools

Where a website owner configures them, the embed can load Google Tag Manager, GA4, Microsoft Clarity or Hotjar. Those services may set cookies or collect visitor activity under their own configuration and policies. The SEO embed itself does not set browser cookies, but that does not mean every connected service is cookie-free.

Website owners should configure their analytics, consent controls and public notices for the tools they enable. See our Cookie Policy for the AnswerMetrix website and app.

Account and integration data

When you create an AnswerMetrix account or connect an integration, we store:

  • Your name and email address (provided via Clerk authentication)
  • Your connected website URLs and site keys
  • OAuth tokens for Google Search Console and Google Analytics 4 integrations — stored encrypted at rest
  • Scan results, fix history, AI visibility scores, and keyword data for your connected sites

Sensitive integration credentials are encrypted before storage and used for the connection you authorise. Read access and supported write actions depend on the integration and granted permissions.

You can disconnect integrations and delete your account at any time from your account settings.

AI processing and provider fidelity

AnswerMetrix uses task-appropriate AI models for analysis and generation. Model selection may change based on task suitability, quality, privacy and availability.

  • Only website content, business brief data and instructions relevant to the requested task are sent for AI processing
  • Account credentials, payment information and unrelated account data are not intentionally included in AI requests
  • No-training and zero-retention processing modes are requested where supported
  • When a report names a specific AI provider as the measured source, the measurement request is sent to that provider rather than simulated through a different model
  • General AI-generated recommendations are not represented as responses from any particular public AI engine

Encryption and access controls

  • Production web and API endpoints use HTTPS
  • OAuth tokens and sensitive credentials are encrypted at rest
  • Access to production systems is restricted to authorised team members
  • Authentication is managed via Clerk, which provides multi-factor authentication support
  • Private account APIs require authentication and permission checks. Public delivery endpoints serve website payloads, and shared-report access uses its own controls.

AnswerMetrix does not hold payment card data. Billing is processed via PayPal.

Data retention and deletion

  • Account data is retained for the duration of your subscription
  • Scan data, fix history, and AI visibility results are retained to power your dashboard and trend views
  • AI Crawler Intelligence event logs are retained for up to 90 days
  • Request account and data deletion through account controls or our privacy contact. Our team handles requests under the Privacy Policy’s 30-day commitment, subject to required legal retention

To request deletion of your data, contact [email protected].

Subprocessors

AnswerMetrix uses the following key subprocessors:

ProviderPurpose
ClerkAuthentication and user management
Replit / PostgreSQL infrastructureApplication hosting and account/scan data storage
CloudflareConfigured edge delivery and associated infrastructure
PayPalPayment processing
Approved AI processing providersAI-assisted generation, analysis, and provider-specific visibility measurement
SMTP2GOTransactional email delivery

Script removal and rollback

  • Rollback is available for supported changes and routes; inspect the rollback result and live verification
  • Removing the embed script from your site's <head> stops subsequent browser injection; it does not undo native CMS writes or independently configured edge changes
  • Some rollback paths require a CMS action, configuration change or developer assistance

Security contact and incident reporting

To report a security vulnerability, suspected data breach, or any security concern, contact:

[email protected]

We aim to acknowledge all security reports within 2 business days. We do not operate a public bug bounty programme at this time.

In the event of a data breach affecting your account, we will notify affected users in accordance with our obligations under applicable data protection law, including POPIA.

This page was last updated in 15 September 2026. For privacy-specific information, see our Privacy Policy. For terms of use, see our Terms of Service.