Geode Privacy Policy
Last updated: 2026-08-26
1. Who We Are
Geode is a service of Brady White, a sole proprietor doing business as Geode ("Geode," "we," "us"), based in Edmond, Oklahoma. We help local small businesses understand and improve how AI assistants describe them: we run AI visibility audits, ongoing monitoring, and done-for-you remediation of business listings and websites. Our website and client portal live at geode.whitebirds.net (the "Site").
This policy explains, in plain English, what information we actually collect, why we collect it, who we share it with, and the choices you have. Geode is a business-to-business service: nearly everything we handle is information about businesses — names, addresses, categories, websites, reviews-related settings — plus the ordinary contact details of the people who run them. We do not run advertising, we do not sell data, and we keep this policy limited to what we really do.
2. What This Policy Covers
This policy covers the Site (including the public landing page, the client portal, and one-page prospect "snapshot" preview pages), our audit, monitoring, and remediation services, and our communications with clients and prospective clients. If you sign a service agreement with us, that agreement controls the services themselves; this policy controls how we handle information.
3. Information We Collect
(a) From clients
When a business becomes a client (or starts onboarding), we collect:
- Business profile information — business name, address, phone, website, service categories, service area, hours, competitors you ask us to track, and your logo and brand colors.
- Contact information — the name, email address, and phone number of the owner or staff we work with.
- Onboarding answers — what you tell us about your services, customers, and goals, which we use to write the customer-style questions we test.
- Portal account data — your portal login email, a hashed password or invite token, and session records. Portal accounts are created by invitation only.
- Delegated access — if you purchase remediation, you grant us access to accounts like your Google Business Profile or website. How that access is granted, stored, and returned is governed by the Platform Access & Authorization Exhibit to our service agreement (summarized in Section 8 below).
(b) From prospective clients
Before we ever talk to a business, we may build a prospect record so we can prepare a free snapshot report. A prospect record contains business-directory information gathered from public sources and the Google Places API — business name, address, phone number, category, website, and rating/review counts — and may also include a contact name, contact email address, and Facebook page URL, but only where the business itself publishes them on its own website or public pages. We add our own internal notes about outreach status (for example, "delivered a snapshot," "asked us not to contact them"). That is the whole record: we do not collect consumer information about a prospect's customers, and we do not buy personal-data lists.
(c) From visitors to the Site
We keep this deliberately minimal:
- No advertising trackers. No analytics cookies. No third-party tracking scripts. The Site sets a cookie only when someone signs in (to the client portal or our own dashboard) — a sign-in cookie that keeps you logged in for up to 30 days and is renewed while you stay active. Anonymous visitors browsing the landing page, the sample report, or a snapshot page receive no cookies from us.
- Server logs. Like almost every website, our hosting provider (Cloudflare) processes standard technical data to deliver pages and block abuse — IP address, browser type, requested page, and timestamps. We do not use this data to profile visitors.
(d) Payments
Payments are processed by Stripe. When you buy an audit or subscribe to monitoring, you enter your card details directly with Stripe on Stripe's checkout pages. Card numbers never touch Geode's systems. We keep the records Stripe returns to us: who you are, what you purchased, subscription status, invoice and payment history, and any promo code you used.
(e) Scan data sent to AI providers
Our core service works by asking the same customer-style questions — for example, "who's a good plumber near downtown Edmond?" — repeatedly of the AI assistants we cover through their official APIs. We currently query OpenAI (ChatGPT), Anthropic (Claude), and Google (Gemini); the providers actually used for your scan are named on your report. We update this policy before adding any new AI provider. The questions describe your business's market, and may include your business name, city, and services. We collect and store the providers' responses and score them for mention rate, position, share of voice, and factual accuracy. This data is about your business's visibility, not about individual people, and we never automate or scrape consumer chat apps — API access only. See Section 6 for how the providers handle these inputs.
(f) Website research
To prepare your audit or snapshot, our automated research tool reads your own public website to find your logo, brand color, services, and basic business facts. It fetches only publicly available pages, the same way a browser would. Excerpts of those public pages — together with your onboarding answers and the competitors you ask us to track — are then sent to an AI provider to help draft the tailored customer-style questions we test. See Section 6.
4. How We Use Information
We use the information above to:
- Provide the service — run scans, score responses, generate reports and snapshot pages, and perform remediation work you have purchased;
- Bill you — process payments through Stripe and maintain subscription and invoice records;
- Communicate with you — Stripe emails your payment receipts; we deliver reports, portal invite links, and follow-ups personally (in person, by email, or by message); and we use Resend to send internal operator notifications to ourselves (signup alerts, payment alerts, follow-up reminders), which can include a buyer's email address or a prospect's contact details;
- Improve our methodology — refine how we ask questions and score answers, using scan results and aggregate patterns, not personal information;
- Protect the Site and comply with law — prevent abuse, enforce our terms, and meet legal obligations.
We do not use your information for third-party advertising, and we do not build profiles of individuals.
5. Who We Share Information With
We share information only with the service providers ("processors") we need to run Geode, each for a specific role:
| Provider | Role |
|---|---|
| Cloudflare (Workers and D1 database) | Hosts the Site on its global network; primary data storage in the United States |
| Stripe | Payment processing and subscription billing |
| Resend | Sends our internal operator-notification email (messages that can include client and prospect contact details) |
| OpenAI, Anthropic, Google | May receive scan questions and scan-related content via API and return the AI responses we score; the providers used for a given scan are named on the report |
| Google Places API | Source of public business-directory data for prospect records |
Each provider handles data under its own terms and privacy policy for the service it performs for us.
Beyond that list, we disclose information only: (i) with your direction — for example, when remediation work requires updating your public listings; (ii) for legal reasons — if required by law, subpoena, or court order, or to protect the rights, safety, or property of Geode or others; or (iii) in a business transfer — if Geode is ever sold or merged, information may transfer to the successor under this policy's protections.
We do not sell personal information, and we do not share personal information with anyone for cross-context behavioral advertising. We have not done so in the preceding 12 months.
6. How AI Providers Handle Scan Content
Scan questions and your business details are submitted to AI providers through their commercial APIs, and are therefore handled under each provider's API terms — not under the terms of their consumer chat apps. As of the date of this policy, each provider's published API terms state that API inputs and outputs are not used to train their models by default. Those are the providers' policies, not ours; they may change them, and we do not control how the providers operate their systems. We disclose this honestly rather than promising it — and we disclose exactly what we send. To prepare your scan, we send an AI provider excerpts of your public website pages, your onboarding answers, and the competitors you name, so it can draft tailored customer-style questions. To score your scan, we send an AI provider the captured answers together with your business's profile facts — name, address, phone, website, and competitor list — so it can grade mentions and factual accuracy. What we can promise is that we never send providers your credentials, customer lists, or payment information.
For the same reason of honesty: AI answers retrieved through APIs can differ from what the same assistant says in its consumer app, and answers vary between runs. As our public disclaimer states: "Results reflect AI API responses captured at scan time. AI outputs vary between runs and change as the underlying models are updated. No ranking, placement, or revenue outcome is expressed or implied."
7. Data Retention
- Client data (business profile, scan history, reports, billing records): kept while your account is active, and for a reasonable period afterward — our default is 24 months after the account closes — so you can retrieve past reports, and so we can meet tax, accounting, and legal obligations. Billing records may be kept longer where the law requires.
- Prospect records: kept while we are actively working an outreach pipeline. If a prospect asks us to stop contacting them, we mark the record "do not contact" the same day, with a note — that marker is our suppression list, and it works only because we keep it. If a prospect asks us to delete their record entirely, we honor that too, and we will explain the one honest trade-off at the time: full deletion also erases our memory that they asked not to be contacted.
- Sign-in sessions and logs: sessions expire 30 days after your last activity; operational logs are kept for short windows and then expire automatically.
8. Security
We take reasonable, proportionate measures to protect the information we hold:
- Encryption in transit — all Site traffic is served over HTTPS/TLS; data stored with our hosting provider is encrypted at rest.
- Access controls — the client portal is invitation-only; sessions expire; administrative access is limited to the people who operate Geode.
- Client credentials — for remediation work we strongly prefer delegated, least-privilege access (for example, a "Manager" invite on your Google Business Profile) over shared passwords. Where a platform offers no delegation and you choose to share a password, it is stored only in a password manager, protected with multi-factor authentication where available, and rotated when our engagement ends. We never accept credentials for financial accounts, bank or payment logins, or personal email. The full rules are in the Platform Access & Authorization Exhibit to our service agreement.
No security program is perfect, and we cannot guarantee absolute security — but we keep our footprint small on purpose: no trackers, no data resale, card data never on our systems.
9. Your Choices and Rights
We extend these choices to everyone we hold information about — clients, prospects, and visitors — regardless of what state you live in or whether any privacy statute technically applies:
- Email opt-out. Every marketing or outreach email includes a working unsubscribe method. Opt-outs are honored within 10 business days, and usually much faster. You may also opt out by emailing geode@whitebirds.net. We will still send necessary transactional email (receipts, report deliveries) while you remain a client.
- Access, correction, and deletion. Email geode@whitebirds.net to ask what information we hold about you or your business, to correct it, or to have it deleted. We will verify you are who you say you are, respond within 30 days, and honor deletion except where we must keep records for billing, legal, or suppression purposes.
- Prospects. If we gathered your business's public listing data and you want no part of it, one email removes you from our pipeline.
We will never discriminate against you — in pricing, service, or otherwise — for exercising any of these choices.
10. Children
Geode is a business service for business owners. The Site and our services are not directed to anyone under 18, and we do not knowingly collect information from minors. If you believe a minor has provided us information, email geode@whitebirds.net and we will delete it.
11. United States Only
Geode serves United States businesses. The Site is hosted on Cloudflare's global network, with primary data storage in the United States. If you access the Site from outside the US, you understand your information will be processed in the US.
12. A Note on State Privacy Laws
Several states (California, Texas, Colorado, and others) have comprehensive privacy laws that apply to companies above certain revenue or data-volume thresholds. Geode is a small business that does not currently meet those thresholds — including the California Consumer Privacy Act's — and does not sell or share personal information for advertising in any case. Rather than track thresholds, we simply extend the core rights those laws provide (access, correction, deletion, opt-out) to everyone, as described in Section 9.
13. Changes to This Policy
If we change this policy, we will post the updated version at geode.whitebirds.net with a new "Last updated" date. For material changes — anything that would genuinely change what we collect or who we share it with — we will email active clients before the change takes effect.
14. Contact Us
Brady White, a sole proprietor doing business as Geode
1812 Council Bluff Dr.
Edmond, OK 73013
Email: geode@whitebirds.net
Web: geode.whitebirds.net
We read every message, and privacy questions get answered by the owner, not a bot.