Privacy Policy

Effective: March 11, 2026 | Last reviewed: March 11, 2026

This Privacy Policy explains how GenLP AI LLC collects, uses, stores, and discloses personal information when you use GenLP.ai, including the public marketing site, account flows, and hosted pages we operate.

Controller and contact information

The controller for the personal information described in this notice is GenLP AI LLC, 1021 E Lincolnway Suite #9630, Cheyenne, Wyoming 82001, United States. Contact privacy@genlp.ai for privacy questions or contact@genlp.ai for general support.

Regional privacy contact

We do not currently publish separate EU or UK representative contacts in this notice. Contact privacy@genlp.ai for regional privacy requests while counsel confirms whether Article 27 appointments are required for specific processing activities.

Information we collect

  • Account and contact details such as name, email address, and login metadata.
  • Billing metadata and transaction status received from Stripe.
  • Prompts, uploaded assets, generated content, and configuration settings you choose to store.
  • Operational logs, device data, page visits, and error diagnostics.
  • Data about visitors to customer-published pages where we process the data on the customer's behalf under the Data Processing Addendum.

Why we use information

  • To create, host, secure, and support the service.
  • To manage subscriptions, refunds, fraud review, and account operations.
  • To respond to support issues, privacy requests, and abuse reports.
  • To measure product performance and improve the service when analytics consent has been granted.
  • To comply with legal obligations and protect users, customers, and the service.

Legal bases and disclosures

Where privacy law requires a legal basis, we rely on contract performance, legitimate interests, consent, and legal obligations as appropriate to the activity. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising on this surface.

Processors and service providers

Provider:Google Cloud (Firestore, Cloud Run, Cloud Storage)
Role:Infrastructure and storage
Data:Account data, generated content, public assets, logs
Purpose:Host and secure the service
Location:United States and regional locations as configured
Transfers / Notes:
Contractual safeguards and regional hosting controls as applicable
Hosts public-by-default assets for customer pages.
Provider:Cloudflare
Role:DNS, CDN, and custom-domain delivery
Data:IP addresses, request metadata, TLS and routing data
Purpose:Deliver published pages and protect availability
Location:Global network
Transfers / Notes:
Contractual safeguards and regional controls as applicable
Used for custom hostname and edge delivery flows.
Provider:Google Analytics
Role:Optional analytics
Data:Cookie and usage data when analytics is enabled
Purpose:Measure site usage and performance
Location:United States and other Google-operated regions
Transfers / Notes:
Google contractual safeguards as applicable
Analytics events are blocked until consent is granted on this surface.
Provider:Stripe
Role:Payment processor
Data:Payment details, billing metadata, transaction status
Purpose:Process subscriptions, refunds, and fraud checks
Location:United States, EU, and other Stripe-operated regions
Transfers / Notes:
Stripe contractual safeguards as applicable
Card details are provided directly to Stripe at checkout.
Provider:Resend
Role:Transactional email delivery
Data:Email address and message-delivery metadata
Purpose:Send service notices and operational messages
Location:United States
Transfers / Notes:
Contractual safeguards as applicable
Transactional email tracking pixels are not enabled by default.
Provider:Sentry
Role:Error monitoring
Data:Error reports and limited runtime metadata
Purpose:Monitor reliability and investigate incidents
Location:United States and EU regions
Transfers / Notes:
Contractual safeguards as applicable
Captures technical diagnostics, not payment content.
Provider:Google Cloud Vertex AI (Gemini)
Role:Generative AI for site content and editing
Data:Business profile inputs, page content, editor chat messages and uploaded reference material submitted for generation
Purpose:Generate and edit site content, translations and image briefs on request
Location:United States and regional locations as configured
Transfers / Notes:
Google Cloud contractual safeguards and regional controls as applicable
Prompts are processed under Google Cloud's data processing terms; they are not used to train Google models.
Provider:TypeSafe AI
Role:Request classification for the editor assistant
Data:Editor assistant chat messages with emails, phone numbers, URLs and quoted wording masked, plus page control labels and section names
Purpose:Classify what an editing request asks for so the right editing step runs
Location:United States
Transfers / Notes:
EU Standard Contractual Clauses and UK Addendum under TypeSafe's Data Processing Addendum
Receives no page text, media or account identifiers; inputs are not used to train TypeSafe models.
Provider:Runware
Role:AI image generation
Data:Image briefs derived from site content and the resulting generated images
Purpose:Generate hero, portrait and gallery images on request
Location:United States and other Runware-operated regions
Transfers / Notes:
Contractual safeguards as applicable
Receives the generation brief only, not account or contact details.
Provider:Bright Data
Role:Public web and social profile retrieval
Data:Public profile and website URLs supplied for site generation and the public content retrieved from them
Purpose:Collect public business information used as site-generation input
Location:United States, Israel and other Bright Data-operated regions
Transfers / Notes:
Contractual safeguards as applicable
Only public pages named by the customer are retrieved.
Provider:Parallel Web Systems
Role:Web research for site generation
Data:Business name, website URL and research queries derived from the site-generation brief
Purpose:Research public information about the business being described
Location:United States
Transfers / Notes:
Contractual safeguards as applicable
Used during site generation; receives no account or payment data.
Provider:Jina AI
Role:Web page reading for site generation
Data:Public website URLs supplied for site generation and the page text retrieved from them
Purpose:Read public pages named by the customer as site-generation input
Location:Germany and United States
Transfers / Notes:
Contractual safeguards as applicable
Receives URLs only, not account or contact details.

Retention

Account profile and workspace settings

Retention: For the life of the account and up to 24 months after closure

Kept to provide the service, resolve disputes, and maintain security records.

Billing and transaction records

Retention: Up to 7 years or longer if tax or accounting rules require it

Payment card details are handled directly by Stripe, not stored in full by GenLP.

Support messages and abuse reports

Retention: Up to 24 months after the issue is closed

May be retained longer when needed for investigations, disputes, or legal obligations.

Operational logs and security events

Retention: Typically up to 24 months

Shorter or longer windows may apply when incident response or legal obligations require it.

Analytics and consent records

Retention: Analytics cookies up to 13 months; consent preference records up to 24 months

Analytics remains off until the visitor enables it on this surface.

Cookies, analytics, and browser signals

We use analytics cookies and similar technologies (Google Analytics and the Meta Pixel) to measure how our sites are used. Whether analytics is on by default depends on where you are visiting from:

  • In the European Economic Area, the United Kingdom, Switzerland, and Quebec (Canada) — and anywhere we cannot determine your location — analytics stays off until you enable it through the cookie banner or the preferences controls.
  • Everywhere else, analytics is on by default and you can turn it off at any time using the "Your Privacy Choices" link in the site footer or the controls on our Cookie Policy page. Opting out takes effect immediately.

If your browser sends a Global Privacy Control (GPC) signal, we treat it as an opt-out of default-on analytics. An explicit choice you save always takes precedence over these regional defaults, in both directions. For manual privacy-rights requests, contact privacy@genlp.ai.

Your rights and requests

Depending on your location, you may have rights to access, delete, correct, export, or object to certain processing. We currently review rights requests manually. Use the privacy request page or email privacy@genlp.ai.

International transfers and security

We use infrastructure and vendors that may process data in the United States and other regions where they operate. When transfer law applies, we rely on contractual safeguards and technical measures as appropriate. We also use access controls, logging, encryption in transit, and vendor security controls to protect the service.