Privacy Policy
Who They Name measures how AI assistants answer questions about businesses, then writes the pages a business can publish in reply. Doing that means handling a small amount of personal data and a larger amount of business data. This page says what, why, for how long, and how to get it back or removed.
01Who is responsible
Who They Name is operated by MMM Studio, a sole proprietorship established in Switzerland (the “operator”, “we”). We are the controller for the data described on this page.
Email: contact@mmmstudio.ch
Postal address: available on request at the address above.
We have not appointed a data protection officer; the size of the business does not require one. Data protection questions go to the email address above.
02What this policy covers
This policy applies to the public site at the root of this domain, the application under /app, free scan reports under /r/, hosted Answer Profiles and question pages under /p/, the public API, and the emails we send. It applies whether you use Who They Name for your own business or, on the Agency plan, on behalf of your clients.
It is written under the Swiss Federal Act on Data Protection (FADP). Where the EU or UK General Data Protection Regulation also applies to you, the same commitments hold and the rights in section 8 are the rights those laws give you.
03Data we collect
Account data
Your email address, a password (stored only as a hash by our authentication provider) or sign-in links sent by email, your name if you give one, the name of your organisation, the team members you invite and their roles, and the timestamps of sign-ins. On the Agency plan, the brand name, logo and colours you set for white-labelled reports.
Business facts
What you tell us about the business you manage: name, website, category, addresses, phone numbers, opening hours, services, prices, credentials, area served, languages. Most of this is public by nature and, on plans that publish, is meant to be published. Where a fact identifies a person (a practitioner’s name, for example) you are responsible for being allowed to publish it.
Prompts and configuration
The questions we put to the engines, the prompt sets they belong to, the engines and languages you enable, the locations you track, and the rivals you name.
Scan results
For every prompt and engine we store the answer text the engine returned, the businesses it named and in what order, the sources it cited, and the scores, trends, alerts and suggested fixes we derive from that. Answers are produced by third-party engines and may name businesses other than yours; that is public information those engines give to anyone who asks.
Free scans
When you run a free scan from the public site we store the website you enter, the email address you give, the business name, city and category we infer from the site or that you confirm, and a salted hash of your IP address used only to limit abuse. The raw IP address is not stored with the scan.
Billing
Payments are handled by Stripe. We store your Stripe customer identifier, the plan, billing period, subscription status and renewal dates, and references to invoices. Card numbers never reach our systems; Stripe holds them under its own security certifications.
Usage and technical data
Counts of scans, prompts, engine calls and their cost per organisation and month, so plan limits and spending caps can be enforced. An audit log of significant actions inside an organisation (who invited whom, who changed billing, who created an API key). Server and function logs kept by our hosting provider, which include IP addresses, user agents and request timestamps, used for security and debugging.
Correspondence
Emails you send us, and the transactional emails we send you: reports, alerts when a position moves, invitations, sign-in links, billing notices.
Prospecting
We may run a free public scan of a business using only public information, and send one message to an address that business itself publishes for enquiries, to share the resulting report. The message carries our full identity. There is no follow-up unless you reply, and we never write again to an address that has asked us to stop: reply, or write to contact@mmmstudio.ch.
Bulk prospect scans run by our customers
Customers on the Agency plan can scan businesses in bulk. We find those businesses through a search results provider (SerpApi) from a category and a city, then scan them from public information. For each one we store the same public facts we would store for any free scan: name, website, city, category, and the answers the engines gave. The customer, not us, decides whether to contact the business. If a report about your business was made this way and you want it gone, reply to the message that brought you to it or write to contact@mmmstudio.ch, and it is deleted the same working day.
04Why we use it
- To provide the service you asked for: run scans, compute scores, publish profiles and question pages, send reports and alerts, bill subscriptions, support you. Basis: performance of a contract.
- To keep the service safe and fair: rate limiting, abuse prevention, enforcing plan limits and spending caps, security logging. Basis: our legitimate interest in operating a reliable service.
- To improve the product: understanding which prompts and engines produce useful signals, fixing extraction errors. We do this on aggregated data and never train third-party models on your data. Basis: legitimate interest.
- To contact businesses about their visibility (prospecting, section 3). Basis: legitimate interest in business-to-business marketing, always with an easy way to say no.
- To meet legal obligations: accounting and tax records, responding to lawful requests. Basis: legal obligation.
We do not sell personal data, do not show advertising, and do not use your data for automated decisions with legal effects on you.
One exception to deletion, so it is not a surprise: when a subscription is cancelled we keep a single accounting record of that cancellation, with no personal data beyond the organisation’s identifier, because it is the only proof the subscription ended. Everything else goes.
05Processors and transfers
We rely on the following providers. Each receives only what its purpose requires and is bound by a data processing agreement or by terms that commit it to confidentiality and appropriate security.
| Provider | Purpose | What it receives | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account, business, configuration and scan data | European Union |
| Netlify | Hosting, serverless functions, scheduled jobs, logs | Requests to the site, app and API; function logs | United States, global edge network |
| Stripe | Payments, invoices, billing portal | Email, organisation name, payment details you enter on Stripe’s pages | United States, with EU entities |
| Resend | Transactional email delivery | Recipient email address and the content of each email | United States |
| OpenAI | ChatGPT answers; structured extraction of answers | Prompts (category, city, question wording, sometimes business and rival names) and answer text | United States |
| Anthropic | Claude answers; structured extraction of answers | Same as above | United States |
| Gemini answers with search grounding | Same as above | United States | |
| Perplexity | Perplexity answers and cited sources | Same as above | United States |
| SerpApi | Google AI Overviews results; finding businesses for a bulk prospect scan | Search queries (question wording and location; a category and a city) | United States |
| IndexNow | Telling participating search engines that a page you published is new or changed | The web addresses of your published Answer Profile and question pages, and nothing else | Redistributed to Microsoft Bing, Yandex and other participating engines |
A scan sends the question itself, which may include the business name, the city and the names of rivals you asked us to track. It never sends your account email, your password, your billing details or the email address given for a free scan.
Drafting is a second, separate call, and it sends more, because it writes from your facts. When you press the button that drafts your Answer Profile or an answer page, we send the business facts you have entered (name, category, street address, town, phone, opening hours, services and their prices, your description) and the questions you are currently losing to Anthropic or to OpenAI, with the instruction to use only those facts. Nothing is sent until you press it, and it is never sent as part of a scan.
Some of these providers process data outside Switzerland and the European Economic Area, mainly in the United States. For those transfers we rely on the provider’s certification under the Swiss-U.S. and EU-U.S. Data Privacy Framework where it holds one, and otherwise on the standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner and the European Commission.
06Public pages
Free scan reports (/r/<token>) are readable by anyone who has the link. The link contains a long random token and is not listed anywhere, but we treat the report as public information: it is built from answers the engines give to anyone, about a business whose name and website are public.
Answer Profiles and question pages (/p/<slug>) are public by design. They are meant to be readable by any crawler that comes looking, and by anyone you send the link to. They are only served while you have marked them as published and while your plan includes publishing; otherwise they return a not-found page.
Nothing else about your organisation is public. The application, its exports and the read API are available only to signed-in members of an organisation or to holders of that organisation’s API keys. A few endpoints answer without a sign-in because they have to: the free scan and its report, the hosted profile and question pages you published, and a health check that says whether the service is up.
07Retention
- Account and configuration data: for as long as your account exists.
- Scan history (answers, citations, snapshots): on the free tier, 30 days from each scan, after which older answers and snapshots are deleted automatically; on Starter, Growth and Agency, for the life of the subscription. When a paid subscription ends, the organisation moves to the free tier and its 30-day rule applies from then on, so export what you want to keep first (see section 8).
- Free public reports: 90 days, then the report and the email address given with it are deleted, unless you created an account and attached the report to it.
- Hosted profiles and question pages: while published; unpublished content stays in your workspace until you delete it.
- Rate-limit hashes: for the length of the limiting window, at most a few days. The hash of the address that ran a free scan lives with that scan, up to 90 days.
- Server and function logs: for the short retention period of our hosting provider, currently measured in days rather than months.
- Billing records: ten years after the end of the financial year concerned, as Swiss accounting law requires (Code of Obligations, art. 958f).
- After account deletion: everything else is deleted within 30 days from live systems and within a further 30 days from backups.
08Your rights
You can, at any time and free of charge:
- Access and export your data. The answers and citations of any scan export from the application as CSV, the latest visibility report prints to PDF, and the facts, prompts and configuration of a workspace are visible and editable in its settings.
- Correct anything inaccurate, directly in the application.
- Delete your account from the Account page. If you own an organisation this cancels its subscription and deletes the organisation, its workspaces, scan history, published pages and API keys. Deletion starts at once and cannot be undone; live systems are clear within 30 days and backups within a further 30 (section 7).
- Object to processing based on our legitimate interests, including prospecting emails, by writing to us.
- Withdraw consent where processing relies on it, without affecting what was done before.
- Complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to the supervisory authority of your own country if the GDPR applies to you.
Requests that cannot be handled inside the application go to contact@mmmstudio.ch. We answer within 30 days and may ask you to confirm that you control the account concerned.
10Security
- All traffic is encrypted in transit (TLS with HTTP Strict Transport Security). Data is encrypted at rest by our database provider.
- Every database table is protected by row-level security: a member of one organisation cannot read or change another organisation’s data, even through the API.
- Entitlements and limits are enforced in the database and on the server, never in the browser.
- Passwords are hashed by our authentication provider; we never see them. API keys are shown once and stored hashed. Webhook deliveries are signed.
- IP addresses used for rate limiting are stored as salted hashes. Secrets are kept out of the browser and out of logs.
- Payment data never touches our systems.
No system is perfectly secure. If we learn of a breach that is likely to put you at high risk we will tell you and the competent authority without undue delay, as the law requires.
11Children
Who They Name is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
12Changes
We will update this page when the service or the law changes. The date at the top is the date of the current version. For changes that reduce your rights or add new uses of your data, account holders receive an email at least 30 days before the change takes effect.
13Contact
MMM Studio
Switzerland
contact@mmmstudio.ch
See also the Terms & Conditions.