Privacy Policy
Last updated: February 28, 2026
1. Introduction
Discover Sentinel ("we", "our", "us") is a Chrome extension and web service that helps content creators evaluate their articles for Google Discover eligibility using artificial intelligence. This Privacy Policy explains what data we collect, how we use it, how we protect it, and what rights you have.
By using Discover Sentinel, you agree to the practices described in this policy. If you do not agree, please discontinue use of the service immediately.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. Continued use of the service after changes constitutes acceptance.
2. Information We Collect
We collect the following categories of data:
- Account data — email address and hashed password when you register an account.
- Usage data — scan count, plan type, timestamps of scans, and general activity metrics. We also collect product analytics events (e.g. popup opened, scan started, scan completed, PDF export, share link created, upgrade click) to understand how the extension is used and improve the service. These events are recorded on our own servers — we do not use any third-party analytics services such as Google Analytics.
- Scanned content — the text of articles you submit is sent directly to the AI model for real-time processing and is never stored on our servers. We retain only the analysis result (score, confidence metrics, and recommendations) — not the original article text or full content.
- Scanned URLs — the URL of the page you scan is stored alongside scan results for your scan history.
- Shared reports — if you generate a shareable link or PDF export, the report (including the scanned URL, readiness score, and AI-generated recommendations) becomes accessible to anyone with the link. Shared reports do not contain the original article text. You control whether to share a report — reports are private by default.
- Payment data — we do not collect or store payment card details. All billing is handled exclusively by Lemon Squeezy (see Section 5).
- Technical data — browser type, extension version, operating system, and anonymized error logs for debugging and service improvement.
3. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — processing necessary to provide the service you have requested (account management, scan processing, subscription management).
- Legitimate interests (Art. 6(1)(f) GDPR) — analytics, abuse prevention, service improvement, and security monitoring.
- Legal obligation (Art. 6(1)(c) GDPR) — where we are required to retain data for tax, regulatory, or legal compliance purposes.
- Consent (Art. 6(1)(a) GDPR) — for optional communications such as product updates. You may withdraw consent at any time.
4. How We Use Information
- To provide, maintain, and operate the Discover Sentinel service.
- To process article scans via AI and return readiness scores and recommendations.
- To manage your account, subscription, and enforce plan limits.
- To send transactional emails (account confirmation, billing receipts, service notifications).
- To monitor, detect, and prevent abuse, fraud, or violations of our Terms of Service.
- To analyse aggregated product analytics (feature usage, conversion funnel, error rates) in order to improve the quality and reliability of the service.
- To comply with legal obligations.
We do not sell, rent, or trade your personal data to third parties. We do not use your content for advertising purposes.
5. AI Processing Disclosure
Article analysis is powered by the Google Gemini API. When you submit an article for scanning, its text is transmitted in real time to Google's API infrastructure for processing. The original article text is not stored on our servers — it passes through our service only for the duration of the API request.
Google's handling of data submitted through the Gemini API is governed by Google's own privacy policy and API terms of service. We encourage you to review Google's data practices.
Important disclaimer: AI-generated analysis is provided for informational purposes only. Results may be inaccurate, incomplete, contradictory, or not reflective of Google's actual ranking or Discover inclusion criteria. AI models are probabilistic by nature and may produce different outputs for the same input at different times. You must independently verify all recommendations before making any content or business decisions.
6. Payment Processing
All subscription payments are processed by Lemon Squeezy, which acts as the merchant of record for all transactions. When you purchase a subscription, you enter into a payment relationship with Lemon Squeezy. We do not receive, process, or store your full payment card details at any time.
Lemon Squeezy handles billing, tax calculation (including VAT), invoicing, and refund processing. Their privacy policy governs all payment-related data. Invoices and receipts are issued by Lemon Squeezy on our behalf.
7. Data Retention
- Account data is retained for as long as your account is active, and for up to 30 days after account deletion to allow recovery.
- Scan results (scores, metrics, and recommendations) are retained for the duration of your active plan's history window, then automatically deleted. The original article text is never stored — it is transmitted to the AI model during processing only.
- Scanned URLs are retained alongside scan results and deleted on the same schedule.
- Usage logs and product analytics events are retained for up to 12 months for operational, security, and abuse-prevention purposes, then automatically deleted.
- Billing records may be retained as required by applicable tax and accounting laws.
You may request earlier deletion at any time (see Section 8).
8. Your Rights (GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of access (Art. 15) — request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten").
- Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests.
- Right to restriction (Art. 18) — request that we limit processing in certain circumstances.
- Right to withdraw consent (Art. 7) — where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@discoversentinel.com. We will respond within 30 days. If you believe we have not adequately addressed your request, you have the right to lodge a complaint with your local data protection supervisory authority.
9. Data Security
We implement reasonable technical and organisational measures to protect your data, including:
- Encrypted connections (HTTPS/TLS) for all data in transit.
- Hashed and salted password storage.
- Role-based access controls for internal systems.
- Regular security reviews.
No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee absolute security. We are not liable for any unauthorized access, data breach, or data loss resulting from circumstances beyond our reasonable control.
10. International Data Transfers
Your data may be processed outside the European Economic Area (EEA) when transmitted to third-party services:
- Google Gemini API — article text is transmitted to Google's API infrastructure, which may process data in the United States or other jurisdictions where Google operates.
- Lemon Squeezy — payment data may be processed in the United States.
Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission. By using the service, you acknowledge these transfers as described.
11. Third-Party Services
Discover Sentinel relies on the following third-party services:
- Google Gemini API — AI-powered article analysis.
- Lemon Squeezy — subscription billing, payment processing, tax handling, and invoicing.
We do not use third-party analytics or tracking services (e.g. Google Analytics, Mixpanel, Segment). All product analytics are collected and stored on our own infrastructure.
Each service listed above operates under its own terms of service and privacy policy. We are not responsible for the data practices of these third-party services. We encourage you to review their policies.
12. Children's Privacy
Discover Sentinel is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at support@discoversentinel.com.
13. Contact
For privacy-related questions, data requests, or concerns, contact us at:
support@discoversentinel.com