Screaming Engine
Menu
Features How it works Pricing Blog About Sign in
Sign in Start free
Legal Privacy Policy Version 2.1

Privacy Policy

How Screaming Engine collects, uses, shares and protects personal data, and the rights you have over it.

EFFECTIVE 18 AUGUST 2026
LAST UPDATED 18 AUGUST 2026

This policy explains what we do with personal data when you visit screamingengine.com, create an account, run a scan, contact us or receive our emails. We have written it to be read rather than skimmed past. If anything here is unclear, ask us and we will explain it in plain terms.

1. Who we are

Screaming Engine (“Screaming Engine”, “we”, “us”) provides answer engine optimisation software that measures how AI search engines read and describe brands. For the personal data described in this policy we act as the data controller, except where we process data on a customer's behalf as part of delivering the service, in which case we act as a processor under our Data Processing Addendum.

Our privacy contact is info@screamingengine.com. Registered company details and our registered office address are available on request and are shown on our invoices.

2. Scope of this policy

This policy covers our website, our web application, our reports and exports, our support channels and our marketing communications. It does not cover third-party websites we link to, the AI engines whose public interfaces we query, or the sites you ask us to scan, each of which operates under its own terms and privacy notices.

Where you use Screaming Engine through an agency or a partner, that organisation is responsible for its own handling of your data and for the workspace it administers.

3. Data we collect

Account and identity data

Name, work email address, password hash, company name, job title where you give it, workspace membership and role, and your communication preferences.

Billing data

Billing name and address, VAT or tax identifiers, plan, invoice history and the last four digits and expiry of your card. Full card details are entered directly with our payment processor and never reach our servers.

Scan and project data

The domains you add, the prompts and competitor names you configure, the publicly accessible page content our crawler retrieves, the engine responses we record, and the scores, citations, issues and reports we generate from them. Page content we crawl may incidentally contain personal data that you have published, such as author names or staff contact details.

Usage and technical data

IP address, approximate location derived from it, device and browser type, pages and features used, timestamps, referring URLs, error and performance logs, and session identifiers.

Communications

Enquiry forms, support tickets, demo bookings, call notes and email correspondence, including whether marketing emails were opened or clicked.

We do not intentionally collect special category data, and we ask that you do not submit it to us in prompts, support tickets or scan configuration.

4. Why we use it

We use personal data to create and administer accounts; to run scans and produce scores, reports and action plans; to take payment and meet our tax and accounting duties; to provide support and answer enquiries; to secure the service, investigate abuse and prevent fraud; to understand which features are used so we can improve them; to send service notices; and, where permitted, to send marketing about our own products.

We also produce aggregated, de-identified statistics about the AI search landscape — for example how often a category is answered without a citation. These statistics cannot be linked back to an individual or a customer domain, and we may publish them.

5. Lawful bases

Under the UK GDPR and the EU GDPR we rely on the following bases.

ContractProviding the platform, running scans, billing, and support connected to your subscription.
Legitimate interestsSecuring and improving the service, product analytics, business-to-business marketing to existing and prospective customers, and defending legal claims. We balance these against your interests and you may object.
ConsentNon-essential cookies and analytics, and marketing email where consent is required. You can withdraw consent at any time.
Legal obligationKeeping invoices and tax records, and responding to lawful requests from authorities.

6. Scans, crawling and AI engines

When you run a scan we retrieve publicly accessible pages from the domain you specify and we send the prompts configured in your workspace to third-party AI engines and their public interfaces. Prompts are written to be about brands, products and categories. We do not include your account details or any customer personal data in them, and you must not put personal data into a prompt.

Once a prompt reaches a third-party engine, that provider handles it under its own terms and may retain it. We cannot control or delete data held by those providers, and we do not represent that they will treat prompts as confidential.

You must have the right to have a domain scanned before you add it. Our crawler identifies itself, respects rate limits and honours robots directives except where you have explicitly authorised a deeper crawl of a domain you control.

7. Cookies and analytics

We use strictly necessary cookies for sign-in, session security and load balancing. These cannot be switched off without breaking the service. With your consent we also use analytics cookies to understand which pages and features are used, and measurement tags to see which campaigns bring people to us.

You can change or withdraw your cookie choices at any time through the cookie settings link in our footer, and you can block or delete cookies in your browser. Some parts of the application will not work correctly if necessary cookies are blocked.

8. Who we share data with

We do not sell personal data and we do not share it for third-party advertising. We disclose it to categories of recipient who need it to run the service: cloud hosting and storage providers; the AI engines and search interfaces we query; payment and invoicing processors; email delivery and support desk tools; product analytics and error monitoring; and our professional advisers.

Each processor is engaged under a written contract limiting them to our instructions. A current list of subprocessors is available on request and, for enterprise customers, is maintained as an annex to the Data Processing Addendum with advance notice of changes.

We may also disclose data where required by law, to enforce our terms, to protect the rights or safety of others, or as part of a merger, acquisition or asset sale, in which case we will tell affected customers.

9. International transfers

Our infrastructure is operated in the United Kingdom, the European Economic Area and the United States, and several AI engines we query are operated in the United States. Where personal data leaves the UK or the EEA we rely on adequacy regulations where they exist, and otherwise on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with a transfer risk assessment and technical measures such as encryption in transit. Copies of the relevant safeguards are available on request.

10. How long we keep it

We keep personal data only as long as we need it for the purposes above.

Account dataFor the life of the account, then 12 months after closure.
Scan historyFor the retention window of your plan, or until you delete the project. Deletion removes it from live systems immediately and from backups within 35 days.
Billing recordsSix years after the end of the relevant financial year, as tax law requires.
Support and enquiries24 months from the last contact.
Security logsUp to 12 months, longer where needed to investigate an incident.

11. Security

We encrypt data in transit with TLS and at rest, restrict access on a least-privilege basis with multi-factor authentication for staff, log administrative access, separate production from test environments, review code before release, patch on a defined schedule and test our defences. No system is perfectly secure, but we will notify affected customers and, where required, the regulator without undue delay if a breach puts personal data at risk.

12. Your rights

Subject to the conditions in data protection law, you have the right to be informed, to access a copy of your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, to withdraw consent, and to object to direct marketing at any time.

Email info@screamingengine.com to exercise any of these. We respond within one month and will tell you if we need longer because a request is complex. We may ask you to verify your identity. Exercising your rights is free and will not affect your service. If your data sits in a workspace administered by an agency or employer, we will pass the request to that customer as controller.

13. Automated decision-making

Our scores, rankings and action plans are produced by automated analysis of websites and engine responses. They describe domains and content, not individuals, and we do not use them to make decisions that have a legal or similarly significant effect on any person. We use automated checks to detect abuse and fraudulent sign-ups; a person reviews any decision to suspend an account.

14. Children

Screaming Engine is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

15. Changes to this policy

We update this policy when our practices or the law change. The version number and effective date at the top always reflect the current text. For material changes we will email account holders and post a notice in the application at least 14 days before the change takes effect.

16. Contact and complaints

Write to us at info@screamingengine.com with any question about this policy, a rights request, or a complaint. We would rather hear from you first and put something right.

You also have the right to complain to a data protection authority. In the United Kingdom that is the Information Commissioner's Office; in the EEA it is the supervisory authority where you live or work.

Read the Terms of Service → Contact us →