Last updated 7 October 2026
Privacy Policy
CredibleAI keeps a contractor’s content, search presence and directory listings current. This page says what information we collect to do that, what we do with it, and how you can have it removed.
1. Who this covers
This policy applies to the CredibleAI website and the CredibleAI app (together, the “Service”). CredibleAI is built and operated by RipeSeed. “We” and “us” mean RipeSeed, as the operator of CredibleAI. “You” means a person who visits the site, joins the waitlist, or uses an account.
2. Information we collect
Information you give us
- Waitlist. Your email address and, if you add it, your company name.
- Account. Your name, email address and password. Passwords are stored as a one-way hash, never as the password itself.
- Your business. Your business name, website, address, phone number, service areas, logo, brand colours, photos, job details and anything else you enter or upload so we can produce content and check listings for you.
- Billing. Payments are taken by Stripe. We receive your plan, payment status and a customer reference from Stripe. We do not receive or store your card number.
Information we gather for you
- Your public website. We read the public pages of the website you give us to learn your services, locations, photos and brand.
- Public business listings. We look up your business on public directories (such as Google Maps, Yelp and Foursquare) to see whether your name, address, phone number and website are correct there.
- Local signals. We collect public weather, news and seasonal information for the areas you serve. This is about places, not about you.
Information collected automatically
- Sign-in cookie. One cookie that keeps you signed in. We do not use advertising cookies or third-party tracking cookies.
- Server logs. Standard request records such as IP address, browser type, the page requested and the time, kept to run and secure the Service.
3. Google user data
Connecting a Google account is optional. If you choose to connect one, Google asks for your permission first and this section describes exactly what happens after you agree. One sign-in can cover both permissions below, and Google lets you allow one and not the other.
What we access
Your Google Business Profile. We request permission to manage it (https://www.googleapis.com/auth/business.manage). With it we access:
- the list of Business Profile accounts and locations your Google account manages;
- for the location you connect: its name, address, phone number, website and business description.
Your Google Search Console. We request permission to read it (https://www.googleapis.com/auth/webmasters.readonly). This permission is read-only: we cannot change anything in your Search Console. With it we access:
- the list of websites your Google account can see in Search Console;
- for the website you connect: its weekly search results. That is the searches people typed, the page of yours Google showed, how many times it was shown, how many times it was clicked, and its average place in the results.
We do not access your Gmail, Calendar, Drive, contacts or any other Google product.
How we use it
- to show you your Business Profile details inside CredibleAI;
- to compare those details with your other directory listings and point out where they disagree;
- to update your Business Profile name, phone number, website or description, and only when you have reviewed and approved that specific change;
- to show you how your website appears in Google search, week by week;
- to suggest which pages of your website to write or improve. To write those suggestions we send some of your search terms and their numbers to the AI providers named in section 6, who process them on our behalf to return the suggestion. We do not send them your Google account details or tokens.
How we store it
We store the Google account and location identifiers, the listing details above, the name of the website you connect, its weekly search results, and the access and refresh tokens Google issues. Tokens are encrypted at rest (AES-256-GCM) and are only used from our servers to make the requests described here.
Who we share it with
We do not sell Google user data. We do not share it with anyone except service providers that host and run the Service on our behalf under confidentiality obligations (including the AI providers in section 6, only for the page suggestions described above), or where the law requires it. We do not use Google user data for advertising, and we do not use it to develop, improve or train generalised AI or machine-learning models.
Limited Use
CredibleAI’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deletion
You can disconnect your Business Profile at any time from the Listings page, and your Search Console from the Search Insights page. Disconnecting deletes the stored tokens for that connection and we stop reading from it. Disconnecting your Business Profile also deletes its Google account identifiers. Search results we have already read stay in your account so your history is not lost, until you ask us to delete them. You can also remove CredibleAI’s access from your Google Account settings. To have all Google data we hold about you deleted, email support@credibley.com.
4. Facebook and Instagram
Connecting Facebook or Instagram is optional. If you choose to connect, Facebook (or Instagram) asks for your permission first and you choose which account we may post to. This section says exactly what we read, what we store and what we do with it.
What we read
- the list of Facebook Pages your login manages (their names and ids), so you can pick the one for your business;
- for the Page you connect: its name and id, and the username and id of the Instagram Business or Creator account linked to it, if there is one;
- which of the permissions we asked for you allowed;
- your Facebook user id for our app (a number). We need it to cancel our access when you disconnect.
You can also connect an Instagram Business or Creator account by itself, with Instagram’s own sign-in and no Facebook Page. Then we read only that account’s id, its username, whether it is a Business or Creator account, and which of the two permissions we asked for you allowed.
What we store
- the Page’s name and id;
- the Instagram account’s username and id;
- the access token Facebook issues for that Page, encrypted at rest (AES-256-GCM). If your login manages several Pages, we also hold the token for your login (encrypted the same way) and the names and ids of those Pages while you choose. Both are deleted as soon as you pick a Page or disconnect;
- your Facebook user id for our app and the list of permissions you allowed;
- for an Instagram account connected by itself: its id and username, the list of permissions you allowed, the access token Instagram issues for it, encrypted at rest (AES-256-GCM), and the date that token runs out. Instagram’s token lasts about 60 days, so we renew it with Instagram from time to time and keep only the newest one;
- a record of each post we publish for you: which post, where it went, when, and its link on Facebook or Instagram.
What we do with it
One thing. We publish the posts you have approved in CredibleAI to the Page you connected and to your Instagram account (the one linked to that Page, or the one you connected by itself), at the time you scheduled or when you press Publish now. To do that we send Facebook and Instagram the post’s picture and caption.
What we never do
We never read your messages, your followers, your comments, your insights, your ads or anything else on your accounts. We never post anything you have not approved. We do not sell this data, we do not use it for advertising, and we do not use it to train AI models. We share it with nobody except the provider that hosts the Service for us.
Disconnecting and deletion
You can disconnect at any time: open the Planner in the app and choose Disconnect under “Where your posts go”. Facebook and an Instagram account connected by itself each have their own Disconnect, and ending one does not end the other. Disconnecting Facebook deletes the tokens, the Page and Instagram details and your Facebook user id from our systems, and we ask Facebook to cancel the permission you gave us (unless the same Facebook login is still connected to another CredibleAI account). Disconnecting an Instagram account you connected by itself deletes its token, id and username from our systems; to also take CredibleAI off the list in Instagram, open Instagram’s Settings, then Apps and websites. Posts already published stay on your Page and your Instagram account, where you can delete them yourself. The record of what we published stays in your CredibleAI account until you ask us to delete it. You can also remove CredibleAI in your Facebook settings under Business integrations or Apps and websites. When you remove CredibleAI there, or in Instagram’s settings, Facebook or Instagram tells us and we delete the stored connection by ourselves. If you ask them to have us delete your data, we do the same and keep only a code for that request, with its date and whether anything was deleted, so you can check what happened; the code does not identify you. Our data deletion page has the steps, and how to ask us to delete everything we hold.
5. How we use information
- to provide the Service: produce content, audit search presence and check listings;
- to create and secure your account and keep you signed in;
- to take payment and manage your subscription;
- to answer you when you write to us, and to tell you about changes to the Service;
- to email you when a seat opens, if you joined the waitlist;
- to find and fix faults, prevent abuse and meet our legal obligations.
6. AI processing
The Service uses AI models from Anthropic, OpenAI and Google (Gemini) to write and design content. To do that we send those providers the business information needed for the task, such as your services, town, brand details and photos, and, for page suggestions, search terms and numbers from a Search Console you have connected. They process it on our behalf to return a result. We do not train AI models on your information.
7. Who we share information with
We do not sell personal information. We share it only with:
- Stripe, to take payments;
- Anthropic, OpenAI and Google, to generate content as described above;
- Google, Yelp and Foursquare, to look up business listings. We send them your business name and location to find the right one. Changes you approve to a connected Google Business Profile are sent to Google;
- Meta (Facebook and Instagram), to publish the posts you approve to the Page and Instagram account you connected. We send the post’s picture and caption;
- Pexels, to find stock photos. We send search terms, not personal information;
- our hosting provider, which stores the Service’s data;
- authorities or other parties where the law requires it, or as part of a merger or sale of the business, in which case this policy continues to apply to your information.
8. How long we keep it
We keep account and business information for as long as your account is open. When you ask us to delete your account we delete or anonymise it within 30 days, except records we must keep for tax, accounting or legal reasons. Waitlist entries are kept until a seat is offered or you ask to be removed.
9. Security
Data is sent over HTTPS. Passwords are hashed and connected-account tokens are encrypted. Access to production systems is limited to the people who need it. No system is perfectly secure, so we cannot promise absolute security, and we will tell you if a breach affects your information where the law requires it.
10. Your choices and rights
You can ask us for a copy of your information, to correct it, to delete it, or to stop using it. Depending on where you live you may have further rights under laws such as the GDPR or the CCPA, including the right to complain to your local data-protection authority. To use any of these, email support@credibley.com. We will not treat you differently for doing so.
11. Children
The Service is for businesses. It is not directed at anyone under 18 and we do not knowingly collect information from children.
12. Changes to this policy
If we change this policy we will post the new version here and change the date at the top. If a change materially affects how we use your information, we will tell account holders by email before it takes effect.
13. Contact
Questions or requests about this policy or your information: support@credibley.com. Our Terms of Service cover the rules for using the Service.