Legal
Privacy policy
Last updated: 30 June 2026
Who we are
Osoro GEO is operated by Osoro Solutions, a sole trader based in the United Kingdom. We are the data controller of the personal data described below. You can reach us at hello@osorosolutions.com.
What we collect
- URLs you scan. The website address you enter in the scan form, the resulting score, the issues detected, and the audit report.
- Email (optional). If you choose to unlock the full report or create a workspace account, we store the email you provide.
- Account data. If you sign in with Google or email/password, we store your auth provider's user ID, your email, and any workspace data you save (queries, citation logs, audits).
- Basic usage data. Standard server logs (IP, user agent, request paths) for security and debugging.
How we use it
- To deliver the GEO scan you requested.
- To send you your report when you ask for it.
- To follow up with relevant guidance (and only if you've given us your email).
- To improve the product based on aggregate scan trends.
We do not sell your data to third parties. We do not use your data to train third-party AI models.
Where we store it
Data is stored with Supabase (EU region) and Vercel. Both are GDPR-compliant processors. The scan engine calls Firecrawl and an AI gateway hosted by Lovable Cloud. Only the page content of the URL you scanned is sent to these services.
Your rights
Under UK GDPR you can ask us to access, correct, or delete your personal data, or to stop processing it. Email hello@osorosolutions.com with your request and we'll action it within 30 days.
Browser extension
The Osoro GEO browser extension is an optional companion to the web app. It adds two capabilities: a quick-audit overlay for any webpage, and a citation observer that logs when AI search engines mention your brand. If you do not install the extension, none of the data described in this section is collected.
What the extension stores locally
- Project API token. The
gvs_…token you paste during setup is saved in your browser's local extension storage. It is never sent to any service other than the Osoro API. - Cached project configuration. Your brand names, tracked domains, and competitor list are cached locally for up to one hour so the extension can filter observations without a network call.
- Recent citation log. The last few observed citations (query snippet, engine, timestamp, cited/not-cited) are stored locally so the popup can show recent activity. This data stays on your device and is cleared when you sign out.
Citation observer: what is collected
When you browse ChatGPT or Perplexity while signed in to the extension, it reads completed AI responses that are already visible on your screen. The extension does not make any requests to ChatGPT or Perplexity on your behalf, does not inject queries, and does not access any data that is not already rendered in the page you are viewing.
For each completed AI response the extension sends to Osoro:
- The AI engine name (e.g. "chatgpt" or "perplexity").
- The query you asked.
- The response text (truncated to 60,000 characters), used solely to detect whether your brand or a tracked competitor was cited.
- Source URLs listed in the AI response, if any.
- The page URL where the response appeared.
- A timestamp.
The extension applies a local pre-filter: if neither your brand nor any tracked competitor is mentioned in the response, the data is not sent to our servers. Only responses containing a relevant citation are transmitted.
Quick-audit overlay: what is collected
When you right-click a page and choose "Audit this page with Osoro", or type a URL into the extension's side panel, the URL is sent to the Osoro scan API. This works exactly the same way as using the scan form on the Osoro website. No authentication is required for the public scan. The audit overlay works without connecting a project token.
What the extension does NOT do
- It does not track your general browsing history.
- It does not run on pages other than ChatGPT and Perplexity (citation observer) or the specific page you choose to audit (overlay).
- It does not send data to any third party, only to the Osoro API.
- It does not automate queries or interact with AI engines on your behalf.
- It does not read passwords, form inputs, or cookies from any site.
Disabling or removing the extension
You can disable the citation observer at any time by signing out in the extension popup (which clears your token and cached config). Uninstalling the extension removes all locally stored data. To delete observed citations stored on the server, email hello@osorosolutions.com.
Cookies
We use a small number of essential cookies for authentication and session state. We do not use third-party advertising or tracking cookies.
Complaints
If you believe we've mishandled your data you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.