Legal
Privacy Policy
This policy describes what LandCrawler collects, who processes it, how long we keep it, and how you can get a copy or have it deleted.
Last updated:
What we collect
Account data — the email address and display name you provide at signup, your approval status, and your plan and role.
AI chat content— the messages you send to the LandCrawler assistant, the assistant's replies, and the memory it derives from them. This is stored in Firestore under your account and is processed by Google Vertex AI to generate responses.
Product analytics and session replay — we record page views and feature interactions, and we record sessions of your use of the app (session replay is enabled by default). Replays capture what was on screen and how you moved through the interface. Analytics and replay traffic is routed through our own first-party /ingest endpoint before reaching PostHog.
Security telemetry — we record sign-in attempts, security profiles, and account-recovery events keyed to your email address, so we can detect credential stuffing and account takeover.
Usage metering — counts of AI and API usage, used to enforce plan limits.
Workspace data — the projects, saved artifacts, shares, and API keys you create.
Billing data — your subscription and invoice records. Card details are entered with Stripe directly; we never see or store them.
Technical logs — server and infrastructure logs and traces, which include IP address and request metadata.
The well, operator, permit, and production records LandCrawler serves are public regulatory data. They are not personal information about you.
Why we use it
We use account, chat, workspace, and billing data to deliver the service you signed up for — this is contractual necessity. We use analytics, session replay, and error telemetry to improve and debug the product, and security telemetry and infrastructure logs to protect accounts and the platform — these rest on our legitimate interest in running a working, secure service. Billing records are additionally kept to satisfy tax and accounting legal obligations.
We do not sell your personal data, and we do not use your chat content to train third-party models.
Who processes it
We use the following service providers. Each receives only what its function needs.
| Provider | Function | Data received |
|---|---|---|
| Google / Firebase | Authentication, Firestore database, Vertex AI (chat model inference), Cloud Logging and Trace | Email, account identity, chat content, app and infrastructure logs |
| Stripe | Subscription billing and payment processing | Billing email, subscription and invoice records. Card details go to Stripe directly — we never see or store them. |
| PostHog | Product analytics and session replay, routed through our own first-party /ingest proxy | Page views, feature interactions, and recorded browsing sessions of the LandCrawler app, keyed to your account id |
| Sentry | Error and crash tracking | Stack traces, browser/runtime context, and the account id attached to an error |
| Resend | Transactional email delivery | Email address and message metadata for verification, approval, and billing email |
| GitHub | Feedback intake — feedback you submit is filed as an issue in our private tracker | The feedback text you write and the account it came from |
| Stadia Maps | Map tile serving | Your browser requests tiles directly, so your IP address is visible to Stadia Maps |
How long we keep it
The periods below mirror our machine-readable retention schedule (config/retention-schedule.yaml), which our deletion tooling and scheduled purge jobs read directly. Data under an active legal, security-incident, or billing-dispute hold is retained until the hold clears.
| Data | Where | Purpose | Retention |
|---|---|---|---|
| Account identity | Firebase Auth, Firestore | Provide the service | Life of account (+30 days after a deletion request) |
| Access requests and onboarding state | Firestore | Access gating and onboarding | 365 days |
| Security telemetry (keyed to your email) | Firestore | Fraud and abuse prevention | 90 days |
| AI chat content | Firestore | Deliver the chat feature | Life of account |
| Product analytics events | PostHog | Product improvement | 365 days |
| Session replay | PostHog | UX research and debugging | 90 days |
| Error and crash telemetry | Sentry | Reliability | 90 days |
| Billing and payment records | Stripe, Firestore | Billing and statutory record-keeping | 2555 days |
| Transactional email logs | Resend | Deliverability | 90 days |
| Usage metering | Firestore | Quota and tier enforcement | 395 days |
| Audit log | Firestore, Postgres | Security and compliance audit | 730 days |
| Product feedback | Firestore, GitHub | Product improvement | 730 days |
| Projects, artifacts, shares, API keys | Postgres, Firestore | Collaboration features | Life of account |
| Infrastructure logs and traces | Google Cloud Logging and Trace | Operations and security | 30 days |
Two categories survive a deletion request: billing records, which we must keep for tax and accounting purposes, and the audit log, which is the security record of account activity — including the deletion itself. Feedback you submitted is kept but disassociated from your account.
Your rights
Access and export — you can request a copy of the personal data we hold about you.
Deletion — you can request deletion of your account and associated data, subject to the two exceptions above. We action deletion requests within 30 days.
Correction — you can ask us to correct inaccurate account details.
Objection and opt-out — you can ask us to stop analytics collection and session replay for your account, and you can opt out of non-transactional email. Transactional email (verification, billing, security) is part of the service and cannot be disabled while your account is active.
Self-serve export and deletion tooling is in development. Until it ships, email support@landcrawler.ai from the address on your account and we will verify and action the request.
Contact
Questions about this policy or about your data: support@landcrawler.ai.