The short version. This site counts visits with Vercel Web Analytics, which sets no cookies and strips query strings before sending anything. It also loads one advertising pixel, from X, to learn which of our X ads lead to a citation request, book request or a contact message, and it skips that pixel entirely when your browser sends Global Privacy Control or Do Not Track. Book access requires an email verification link and a necessary, signed access cookie that lasts 30 days. Two forms email us: the contact form on the home page and the book download form on the book page. Contact inquiries may also be retained for up to 30 days in Upstash as a delivery-recovery copy; the book form is still email-only. Neither adds you to a mailing list. Inbox copies are retained as described below. The other parties that see anything about your visit are Google Fonts, Vercel, X, Stripe, Upstash and Resend, all described below.
What this site collects
The contact, download and AI citation check forms email what you enter; when the citation scan is sold, Stripe takes the card payment. The prospect audit form passes a website URL to Agent Studio. seo.suedeai.ai uses serverless endpoints for forms and verified access. Visits are counted by Vercel Web Analytics, described under Site analytics below; there is no tag manager or session-replay tool. The one advertising pixel, X's, is described under Advertising measurement below. A necessary cookie keeps your book access verified; it is not used for analytics or advertising.
The contact form
When you submit the form on the home page, its contents are posted to /api/contact,
a function on this domain. The function checks the form identifier, submission timing, request
origin and server-side rate limits to discard automated spam. An accepted submission is written
to a delivery-recovery record in Upstash for up to 30 days and
sent to Suede's operating inboxes by Resend, our transactional
email provider. The recovery record contains the contact fields you submitted and a delivery
status; it is not added to a marketing list and expires automatically.
If email sending fails after the recovery copy is written, the page still offers a
mailto: link so you can contact us directly. The recovery copy remains available
for the retention window so a mail-provider failure does not silently erase the inquiry.
Verified book access
The Screenshot is free, but every online chapter and all PDF, EPUB and Markdown downloads require a verified email. The standalone checklist is public and requires no email or access cookie. The public book page describes the book and lists its contents.
When you submit the book form, your email address, form source and campaign labels are posted to /api/unlock. Our transactional email provider, Resend, first sends our team inbox an unverified book-request record, then delivers a verification link to your address. The record includes an opaque request ID and the campaign labels supplied in the page address (source, medium, campaign, content and term), with no full URL, click identifier or referrer. The link expires after 20 minutes. Submitting an address alone does not grant access or prove a download. We may contact you to help with this book request. We do not add you to a mailing list or send a marketing sequence.
Opening a valid link creates a signed, necessary access cookie in that browser for 30 days. The cookie is HttpOnly, so page scripts cannot read it, and is used only to check book access. After it expires, or if you use another browser or clear your cookies, verify your email again. Direct chapter and download URLs check the same access cookie.
The verification flow writes to no site database, file or mailing list; the request is retained in our team inbox. To limit abuse, the server temporarily keeps hashed email and IP identifiers in memory for about 10 minutes, without storing the raw email address in those rate-limit records. Operational logs contain the opaque request ID and campaign labels, not the submitted email address. Resend processes both emails under its own terms; our hosting provider processes requests as described below. Keep your verification link private.
The AI citation check
When you use the AI citation check page, the domain, the few words
you typed about what the business sells, and your email address are posted to
/api/ai-citation-check, a function on this domain. It reads that domain's public homepage,
robots.txt, llms.txt and sitemap.xml to show you the site read. On submission, it immediately emails
your request to info@suedeai.ai, marked as unverified, so we can
respond even if you do not confirm. That record includes the website, email, description and the
campaign labels (source, medium, campaign, content and term) present in the page address. We do not
copy the full page address, click identifier or referring URL into that record. Submitting requests
contact about this check; it does not subscribe you to a mailing list. The function also emails a confirmation link,
delivered by Resend. The link carries your request in signed form and
expires after 24 hours; the four buyer questions wait until you click it.
When you do, and our search data provider is connected, the function asks those questions of Perplexity and Google's AI Overview through DataForSEO, which receives the questions and the domain but never your email address, returns the answer to your browser, and emails the result and your confirmed address to info@suedeai.ai. When it is not connected, clicking the link runs a structural audit instead: the function fetches your homepage, robots.txt, llms.txt, sitemap.xml and the pages at /pricing, /about, /faq, /blog and /compare, emails the audit to your confirmed address, and emails a copy with your address to that inbox. Nothing is sent to DataForSEO and nothing is charged. The free confirmation flow writes to no database, file or mailing list on this site, and the email in our inbox is the only record, handled as described under Email below.
When the scan is offered as a paid product, the form opens a Stripe Checkout for $4.79 in place of the confirmation link, unless your email address is at the domain being checked: a company address is never charged and goes through the free confirmation flow above. Your card details are entered on Stripe's own pages and never touch this site; Stripe receives your email address and the domain, as the order description, and keeps the payment record under its own terms. Once Stripe reports the payment complete, a signed Stripe webhook runs the questions even if you close the checkout page. The paid result and delivery flags are held for 30 days in an Upstash Redis-compatible store, without your email address, so webhook and browser retries return the same result instead of buying and sending another scan. The result is emailed to you and to our inbox.
The check is rate limited per visitor. If it refuses or fails, the page says so and offers the inbox address instead, and a paid scan that never ran is refunded on reply to the receipt.
Site analytics (Vercel)
We count visits with Vercel Web Analytics,
loaded from /assets/analytics.js and /_vercel/insights/script.js on this
domain. It sets no cookies. Vercel records the page path, the referring site, the country, and the
browser, operating system and device type, and tells one visit from another with a hash of the request
that Vercel discards after 24 hours, so it cannot follow you across days or across sites. Before
anything is sent, the page address is stripped of every query parameter except utm_
campaign tags, so confirmation, book-access, payment-return and outreach links never reach it. We
also count four actions by name: a form sent, a phone link tapped, a booking link clicked and a
free-teardown button clicked. No form content is sent. Analytics loads on public pages, not on the
book chapters.
Advertising measurement (the X pixel)
We advertise on X. To learn which of those ads lead to a citation request, book request or a contact
message, public pages on this site load /assets/x-pixel.js, which in turn loads X's
advertising pixel from static.ads-twitter.com. When it loads, X receives the page address,
the referring page, your IP address and user agent, and reads or sets its own cookies and identifiers.
X can link that to an X account you are signed in to and uses it for ad measurement and targeting under
X's privacy policy.
When the citation check or book form successfully saves your request to our team inbox, or the contact form queues your message, the page tells X which form finished, once per visit. A book request is not a verified download. It sends an opaque request ID for deduplication, with nothing you typed: not your email address, domain, name or message. Page addresses that carry a private token, such as a Stripe return link, a confirmation link or a fresh book verification, and outreach links that name your website, load nothing from X.
When it does not run. The loader checks for a Global Privacy Control or Do Not Track
signal before it requests anything from X, and loads nothing when either is on. We treat Global Privacy
Control as your opt-out of sharing for cross-context behavioural advertising. The verified book chapters
never load it. You can also turn off personalized ads in your X account's privacy settings, or block
static.ads-twitter.com in your browser; the site works the same without it.
Fonts (Google)
Typefaces load from fonts.googleapis.com and fonts.gstatic.com. To
serve them, Google receives your IP address, user agent, and the referring page. We set no Google
cookie and run no Google analytics product, but this request happens on page load and you cannot
opt out of it without blocking those hosts. We are noting it because most privacy policies quietly
omit it.
Hosting (Vercel)
The site is served by Vercel, which keeps standard operational request logs (IP address, user agent, timestamp, path) for security and delivery. That processing is Vercel's, under its own terms and retention.
When you email us we hold what you send: your name, your email address, whatever URL and detail you include, and our replies. We use it to answer you and, if you become a client, to run and deliver the work. We do not sell it, rent it, or add you to a marketing list you did not ask for.
We keep it while the inquiry or engagement is live, plus a reasonable period for support and refund handling, then delete it on request.
Client work
Scans, reports, and patches produced for a client are kept private and are never published without that client's written permission. The one estate we publish about is our own, and that is our choice to make, including the measurements where Suede performs badly.
Your rights
Email info@suedeai.ai to ask what we hold about you, to correct it, or to have it deleted. We reply within 5 business days.
Changes
If this policy changes materially, the effective date above changes with it. There is no archived version history for this page yet; ask us and we will tell you what changed and when.
Contact
Suede AI, a service of JC Investment Group LLC, info@suedeai.ai. Press inquiries: press@suedeai.ai · newsroom.