Legal

Privacy Policy

This policy describes what LandCrawler collects, who processes it, how long we keep it, and how you can get a copy or have it deleted.

Last updated:

Pending final legal review.This policy reflects our engineering team's accurate description of current data practices. It has not yet been reviewed or approved by counsel, and the retention periods below are our proposed baseline rather than executed legal commitments. We will update this page when review completes.

What we collect

Account data — the email address and display name you provide at signup, your approval status, and your plan and role.

AI chat content— the messages you send to the LandCrawler assistant, the assistant's replies, and the memory it derives from them. This is stored in Firestore under your account and is processed by Google Vertex AI to generate responses.

Product analytics and session replay — we record page views and feature interactions, and we record sessions of your use of the app (session replay is enabled by default). Replays capture what was on screen and how you moved through the interface. Analytics and replay traffic is routed through our own first-party /ingest endpoint before reaching PostHog.

Security telemetry — we record sign-in attempts, security profiles, and account-recovery events keyed to your email address, so we can detect credential stuffing and account takeover.

Usage metering — counts of AI and API usage, used to enforce plan limits.

Workspace data — the projects, saved artifacts, shares, and API keys you create.

Billing data — your subscription and invoice records. Card details are entered with Stripe directly; we never see or store them.

Technical logs — server and infrastructure logs and traces, which include IP address and request metadata.

The well, operator, permit, and production records LandCrawler serves are public regulatory data. They are not personal information about you.

Why we use it

We use account, chat, workspace, and billing data to deliver the service you signed up for — this is contractual necessity. We use analytics, session replay, and error telemetry to improve and debug the product, and security telemetry and infrastructure logs to protect accounts and the platform — these rest on our legitimate interest in running a working, secure service. Billing records are additionally kept to satisfy tax and accounting legal obligations.

We do not sell your personal data, and we do not use your chat content to train third-party models.

Who processes it

We use the following service providers. Each receives only what its function needs.

Service providers that process LandCrawler data
ProviderFunctionData received
Google / FirebaseAuthentication, Firestore database, Vertex AI (chat model inference), Cloud Logging and TraceEmail, account identity, chat content, app and infrastructure logs
StripeSubscription billing and payment processingBilling email, subscription and invoice records. Card details go to Stripe directly — we never see or store them.
PostHogProduct analytics and session replay, routed through our own first-party /ingest proxyPage views, feature interactions, and recorded browsing sessions of the LandCrawler app, keyed to your account id
SentryError and crash trackingStack traces, browser/runtime context, and the account id attached to an error
ResendTransactional email deliveryEmail address and message metadata for verification, approval, and billing email
GitHubFeedback intake — feedback you submit is filed as an issue in our private trackerThe feedback text you write and the account it came from
Stadia MapsMap tile servingYour browser requests tiles directly, so your IP address is visible to Stadia Maps

How long we keep it

The periods below mirror our machine-readable retention schedule (config/retention-schedule.yaml), which our deletion tooling and scheduled purge jobs read directly. Data under an active legal, security-incident, or billing-dispute hold is retained until the hold clears.

LandCrawler data retention schedule
DataWherePurposeRetention
Account identityFirebase Auth, FirestoreProvide the serviceLife of account (+30 days after a deletion request)
Access requests and onboarding stateFirestoreAccess gating and onboarding365 days
Security telemetry (keyed to your email)FirestoreFraud and abuse prevention90 days
AI chat contentFirestoreDeliver the chat featureLife of account
Product analytics eventsPostHogProduct improvement365 days
Session replayPostHogUX research and debugging90 days
Error and crash telemetrySentryReliability90 days
Billing and payment recordsStripe, FirestoreBilling and statutory record-keeping2555 days
Transactional email logsResendDeliverability90 days
Usage meteringFirestoreQuota and tier enforcement395 days
Audit logFirestore, PostgresSecurity and compliance audit730 days
Product feedbackFirestore, GitHubProduct improvement730 days
Projects, artifacts, shares, API keysPostgres, FirestoreCollaboration featuresLife of account
Infrastructure logs and tracesGoogle Cloud Logging and TraceOperations and security30 days

Two categories survive a deletion request: billing records, which we must keep for tax and accounting purposes, and the audit log, which is the security record of account activity — including the deletion itself. Feedback you submitted is kept but disassociated from your account.

Your rights

Access and export — you can request a copy of the personal data we hold about you.

Deletion — you can request deletion of your account and associated data, subject to the two exceptions above. We action deletion requests within 30 days.

Correction — you can ask us to correct inaccurate account details.

Objection and opt-out — you can ask us to stop analytics collection and session replay for your account, and you can opt out of non-transactional email. Transactional email (verification, billing, security) is part of the service and cannot be disabled while your account is active.

Self-serve export and deletion tooling is in development. Until it ships, email support@landcrawler.ai from the address on your account and we will verify and action the request.

Contact

Questions about this policy or about your data: support@landcrawler.ai.

We'd like to use product analytics, session replay, and account-linked error diagnostics to improve LandCrawler. None of it runs until you choose. Strictly necessary cookies (sign-in, security) always apply.