Arrow AI
Free See how AI engines talk about your brand Run the GEO audit ->

Trust Center

Security & privacy, in plain language

How Arrow’s public pages and audit tools use data, what stays in your browser, and when a request reaches a service provider. Review the workflow before sharing business or personal information.

Security posture

Public pages and server-side tools

01 — Architecture

Pages, APIs, and browser storage

  • Public pages are served on Vercel; audit and form features also call server-side APIs.
  • The internal GEO workspace uses access-code verification and a signed session cookie when configured.
  • The browser stores scan history, prompts, consent choices, and some form data locally. Audit requests also leave the device.
02 — Transport & headers

Configured delivery controls

  • Hosting configuration includes HTTPS-related HSTS and browser security headers.
  • Configured headers include Content-Security-Policy, X-Frame-Options, nosniff, Referrer-Policy, and Permissions-Policy.
  • The configured GEO session cookie uses Secure, HttpOnly, and SameSite controls; these controls are not a security certification.
03 — Before sharing

Choose the appropriate workflow

  • Use public domains and non-confidential prompts for public-source visibility analysis.
  • Do not submit passwords, private client records, health information, or unpublished documents to a public audit.
  • Report abuse or spoofing via the contact form

Privacy & data use

Analytics choices and submitted data

Consent

Optional analytics consent

  • The shared consent banner offers Accept and Reject and stores your choice in the browser.
  • The shared loader enables Google Analytics, Vercel Insights, and HubSpot tracking after acceptance.
  • Submitting a form, requesting an audit, or booking still sends the data needed for that action when analytics is rejected.
Minimal data

What an action sends

  • Opening the booking widget connects to Cal.com; booking sends the scheduling details you provide.
  • Contact and audit forms send submitted details to server-side handling and HubSpot; configured lead storage or fallback form services may also be used.
  • Provider-backed answer tests send the submitted domain or brand context and prompts to configured AI APIs. API tests are distinct from consumer search tests.
Your rights

Access, correction, deletion

  • Request access or deletion via the contact form
  • We review the request, verify what data and services it concerns, and respond under the applicable process described in our policies.
  • Details in the privacy policy and data processing pages

Services and data flows

Who touches data, and why

ServicePurposeData involved
VercelPublic hosting and server-side request handling; optional InsightsRequest metadata and data sent to the feature; Insights through the shared consent loader
Browser storageLocal workspace and form stateScan history, saved prompts, consent choice, and some submitted form data on this browser
Cal.comBooking widget and schedulingConnection metadata when opened and booking details when submitted
Google Analytics / HubSpot trackingOptional usage and CRM-related trackingEnabled by the shared loader after analytics consent
HubSpotContact and audit request handlingSubmitted contact, company, website, and request information
Configured Redis/KV storageServer-side lead storage when enabledSubmitted lead records; configuration determines whether this path is active
Google form fallback / WorkspaceFallback form handling and correspondence where usedSubmitted request data or email correspondence for that workflow
Configured AI providersOptional answer tests through OpenAI, Google Gemini, Anthropic, Perplexity, or Groq APIsDomain or brand context and prompts; only configured providers receive requests. Provider terms and account settings apply.

Questions?

Security or privacy question we didn't answer?

Read how we separate website scores from observed answers in the measurement method, then explore the GEO authority library.

For a client project, confirm the data sources, provider settings, access, retention, and review responsibilities in the agreed scope. This page is not a certification of a deployment or a blanket compliance guarantee.

Company · Terms · Privacy · Cookies · Data processing · Legal notice