Privacy Policy
Effective date: July 8, 2026. Last updated: July 8, 2026.
1. What Data We Collect
Account information: your name and email address, and authentication metadata. Usage data: pages viewed, tools tracked, comparisons created, and feature usage. Technical data: IP address, browser type, and device information collected via server logs. Analytics: aggregated, privacy-preserving usage statistics via Plausible (a cookieless analytics tool). We do not collect payment card numbers directly; these are handled by our payment processor.
2. How We Use Data
We use data to: provide and operate the Service; authenticate and secure accounts; send transactional emails and, where you opt in, digests and alerts; improve features and reliability; and comply with legal obligations. We do not sell your personal data, and we do not use it for advertising.
3. Data Sharing
We share personal data only with essential service providers acting on our behalf: Cloudflare (network, security, and edge delivery), Sentry (error monitoring), Zepto Mail (transactional email delivery), and third-party LLM API providers (used solely to run benchmarks — benchmark prompts are standardized and contain no personal data). None of these providers are used for advertising. We may also disclose data where required by law.
4. Your Rights under the GDPR
If you are in the European Economic Area, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent at any time. To exercise these rights, contact privacy@gptradar.io. You also have the right to lodge a complaint with your local supervisory authority.
5. Your Rights under India's DPDP Act 2023
If you are in India, under the Digital Personal Data Protection Act, 2023 you have the right to access your personal data, to correction and erasure, to grievance redressal, and to nominate another person to exercise your rights in the event of death or incapacity. To exercise these rights, contact our Grievance Officer or privacy@gptradar.io.
6. Data Retention
Account data is retained until you delete your account, plus a 30-day grace period, after which it is permanently erased. Aggregated benchmark data is retained indefinitely because it is not personal data. Server logs are retained for 90 days. Backups are cycled on a rolling basis and purged within this window.
7. Cookies
We use only strictly necessary cookies (for authentication and security) and cookieless analytics. We do not use advertising or cross-site tracking cookies.
8. International Data Transfers
The Service uses globally distributed infrastructure, so your data may be processed and stored in server locations outside your country, including outside the EEA and India. Where required, we rely on appropriate safeguards for such transfers.
9. Children's Data
The Service is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If we learn we have done so, we will delete it.
10. Security Measures
We protect data using encryption in transit (TLS) and at rest, role-based access controls, least-privilege access, and regular backups. No system is perfectly secure, but we take reasonable measures aligned with industry practice.
11. Data Breach Notification
In the event of a personal data breach likely to result in risk to your rights, we will notify affected users and the relevant authorities without undue delay and in accordance with applicable law (including GDPR and the DPDP Act).
12. Grievance Officer / DPO
As required under India's DPDP Act, our Grievance Officer is reachable at privacy@gptradar.io. For general privacy inquiries, contact privacy@gptradar.io.
13. Updates to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-product notice, and the “last updated” date above will change.