1. Who we are and how to reach us
UsableByAI is operated by PE Petro Ukolov, an individual entrepreneur (FOP) registered in Ukraine, tax ID 3302302937, registered address: 94A Vasylkivska Street, Kyiv, 03022, Ukraine. We are the data controller for personal data processed through https://usablebyai.com and the account cabinet.
For privacy questions and requests, write to legal@usablebyai.com. For everything else there is support@usablebyai.com.
We have not appointed a representative in the EU at this stage. If you are in the EEA, contact us directly at legal@usablebyai.com — we handle privacy requests from every country the same way.
2. What we collect
Account data: your name, email address and password. The password is stored only as a hash by Google Firebase Authentication — we never see it. If you sign in with Google, we get your Google account identifier instead.
Billing profile: your billing country, which determines your billing currency.
Collected automatically: your browser's time zone (saved when you sign in and updated if it changes), interface language and theme, and your email preferences (such as the product reminders toggle).
Analytics — only if you agree: if you accept analytics cookies, Google Analytics 4 collects pseudonymous usage data about the site and the cabinet — pages viewed, how far down a page you scrolled, clicks on links that take you to other websites, approximate location (country/city, derived from your IP by Google), device, browser and language, the referral source, and a few product events (sign-up, free site check, checkout started, purchase completed). These events carry no name, email, account identifier or the URL of the website you audit. If you decline, none of this is collected.
Order data: the website URL and scenario you submit, the consents you give (with the exact consent text version, time and language), and the results we generate — reports, screenshots and videos.
Scenario prechecks and Fit Check: when you use the free scenario precheck or the free website check (Fit Check), we store what you submitted (scenario text, URL) together with the automated verdict.
Payment records: product, amount, currency, status and payment reference. Payment card details never touch our servers — you enter them on LiqPay's page and they stay with LiqPay.
Support and feedback: your support cases (topic, message text, your email) and any feedback you send, including whether you agreed to have a review published.
Technical logs: identifiers and statuses we need to run and secure the Service. Logs do not contain the content of your emails or support messages.
One thing to know about audit artifacts: screenshots and videos record what your website shows during the test, so they can incidentally capture personal data of third parties visible on those pages (for example, names in customer reviews or demo data). These artifacts are part of your report: private to your account by default and deleted together with the report.
3. Why we process it and on what legal basis
To provide the Service — your account, running audits, delivering reports, keeping your run balance, and transactional emails (welcome email, payment receipt, report digest, account deletion notices). Legal basis: performance of a contract. Name and email are required to create an account — without them we cannot provide the Service.
To send product reminders about unused audit runs. Legal basis: your consent. The toggle is off by default; you can switch it on in Settings, switch it off there at any time, and every such email contains an unsubscribe link.
To publish a review you submitted, together with your name. Legal basis: your explicit consent, which you can withdraw at any time.
To see how the site and the cabinet are actually used — which pages people read, how far they read them, what they click on, and how many visitors reach sign-up or a purchase — so we can improve the product. Legal basis: your consent, given in the cookie banner and withdrawable at any time.
To keep the Service secure, enforce usage limits and prevent abuse. Legal basis: our legitimate interest in running a safe and fair service.
To keep payment and accounting records. Legal basis: legal obligation under tax law.
4. Who receives your data
We do not sell personal data and we do not share it for targeted advertising. We share data only with the providers below, and only to run the Service.
Google (Firebase / Google Cloud) — sign-in and authentication, database and file storage in Europe (eur3 region), cloud functions in the US (us-central1), and technical logs.
Google (Google Analytics 4, property G-72PJW49FQF) — our traffic measurement tool, and only if you accept analytics cookies. It receives the usage data described in section 2 and processes it in the US. For this data Google acts as our processor. We do not use Google Ads, remarketing or advertising pixels, and we do not send analytics data anywhere else.
LiqPay — the payment service of JSC CB PrivatBank (Ukraine) — receives the amount, currency, plan description and our internal order identifiers. Card details are entered on LiqPay's page and never reach us.
Resend (US, us-east-1) — delivers our outgoing emails and receives the recipient address, subject and email content. Open and click tracking is disabled.
Cloudflare — routes incoming mail to our support, legal and info addresses; Google (Gmail) hosts the mailbox where we read and answer that mail.
AI providers — OpenAI, Anthropic and Google (Gemini API). This is the core of the Service: during an audit they receive screenshots of the pages of the website being tested, the scenario text and the URL, so their agents can walk your scenario. Under the terms of their APIs, this data is not used to train their models. We do not send your name or email to the AI agents.
5. International transfers
We are based in Ukraine. Your data is stored in the EU (Google Cloud, eur3) and is also processed in the US (cloud functions, email delivery, AI provider APIs and — if you accept analytics cookies — Google Analytics) and in Ukraine, where we operate.
If you are in the EEA, transfers to these providers are protected by the EU Standard Contractual Clauses (SCC) and/or the providers' certification under the EU–US Data Privacy Framework. To ask about these safeguards or get copies of the relevant terms, write to legal@usablebyai.com.
6. How long we keep it
Account and profile data — while your account is active. If you request deletion, you have 30 days to change your mind (just sign in again); after that the account is permanently purged.
Reports, screenshots, videos, Fit Check and precheck history — until you delete the report or the account. A deleted report disappears from your account immediately and its files are permanently purged within 30 days.
Payment records — 3 years — required by tax law; they are kept even after account deletion.
Support cases — 3 years after the case is closed — the general limitation period for legal claims.
Email delivery log (message type and status, without email addresses) — 1 year — to prove delivery and investigate problems.
Analytics data in Google Analytics — 14 months, after which Google deletes it automatically. The consent cookie lives 182 days on your device.
After full account deletion we keep only an irreversible hash of your email address, to prevent abuse of free limits by re-registration. The email address itself, and everything else listed above except the categories with their own retention periods, is deleted.
7. What can become public
Share link: every finished report has a share link. Anyone who has it can open the report page, including screenshots and videos. The link is unguessable, hidden from search engines and not password-protected.
You decide who receives that link, and you are responsible for that disclosure. You can revoke the link in your account at any time: the page stops opening immediately, but files the recipient has already downloaded stay with them. Deleting the report also kills the link.
Public confirmation page: if an audit completes with an Agent-Ready Score of 75 or higher, a public confirmation page is created automatically on our site. It shows your website's domain, the score, the audit date, the list of agents and a masked version of the scenario (email addresses and phone numbers are masked). It contains no account identifiers and disappears when you delete the report or the account.
8. Cookies, analytics and local storage
We use two kinds of things on your device: strictly necessary ones, which the Service cannot work without, and analytics, which are set only if you agree. No advertising pixels, no remarketing, no sale of data.
Strictly necessary — always on:
Firebase Authentication cookies and tokens — keep you signed in.
ubai_consent (cookie, 182 days) — remembers your cookie choice, so we do not ask again.
ubai.locale (localStorage) — remembers your language.
ubai.account (localStorage) — a local sign-in hint (initials, name, email, currency) stored only on your device so the site can greet you without an extra request; it never leaves your browser.
ubai.prefill (localStorage) — remembers what you typed into the check form so you don't retype it.
ubai.auth-prefill (sessionStorage) keeps a temporary copy of your form entries and selected plan for the email confirmation tab. It is cleared after filling the destination form or when the tab session ends; entries older than 24 hours are ignored.
Analytics — only after you accept:
_ga and _ga_* (cookies, up to 2 years) — set by Google Analytics 4 to tell visits and sessions apart. They contain a random identifier, not your name or email.
Scrolling and outbound clicks are counted by Google Analytics itself, without any extra cookie: _ga and _ga_* stay the only analytics cookies we use, and everything switches off together when you withdraw your consent.
Nothing happens before you choose. Until you accept, the Google Analytics script is not loaded at all and not a single request goes to Google (Consent Mode v2 with every category denied by default). The banner itself is served from our own servers, so before your choice your browser contacts no third-party domain.
The banner is shown to every visitor, wherever you are. "Accept" and "Reject" are equally prominent, one click each; rejecting is a normal, complete answer and the banner does not come back.
You can change or withdraw your choice at any time: "Cookie settings" in the site footer and in Settings in your cabinet. After you withdraw, collection stops immediately and the _ga and _ga_* cookies are deleted.
Analytics data is kept separate from your account data: we do not merge the two, we do not build profiles and we do not make decisions about you based on analytics.
Our emails contain no tracking pixels.
9. Your rights
You can do a lot yourself: view and correct your data in Settings, export your reports, delete individual reports and schedule deletion of the whole account.
You also have the right to request access to your data, rectification, erasure, restriction of processing, data portability, and to object to processing based on our legitimate interest. You can withdraw any consent at any time — product emails switch off right in Settings, analytics in "Cookie settings" in the footer or in Settings. Write to legal@usablebyai.com; we respond within 30 days.
You can lodge a complaint: in Ukraine — with the Ukrainian Parliament Commissioner for Human Rights (Ombudsman); in the EEA — with your local supervisory authority.
We do not make automated decisions that produce legal or similarly significant effects about you. The Agent-Ready Score describes your website, not you — it is the informational product you ordered, not a decision about a person.
10. Security and incidents
Data lives in Google Cloud under strict access rules: clients cannot read other clients' data, report files are not publicly listed and open only through an unguessable link that carries an access token, payments are verified on the server with signed callbacks, and API keys are kept in a dedicated secret manager.
No system is perfectly secure, so here is what happens after an incident: if a data breach is likely to put you at high risk, we will notify the competent regulator and the affected users as the law requires — in the EEA within the GDPR deadlines, including 72 hours for notifying the supervisory authority.
11. Children
The Service is for adults (18+) acting for business purposes. We do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, write to legal@usablebyai.com and we will delete it.
12. Changes to this Policy
We may update this Policy as the product evolves. The current version always lives on this page; material changes are announced here with a new last updated date. If a change concerns a new recipient of your data or a new purpose, we will update the relevant section before the change takes effect.
Questions about this document? Write to legal@usablebyai.com