Effective date: October 6, 2026
Simplee Digital Marketing Inc. ("Simplee Digital", "we") runs doiexist.ai ("Do I Exist"), a free tool that checks whether AI assistants mention your business. This policy explains what personal information the site collects, why, who it is shared with, how long it is kept, and the choices you have.
What we collect
When you run an audit:
- The website address you enter. Anyone may audit any public website.
- Your IP address, stored with the audit, so we can limit audits to 3 a day per person or network.
- Your account, if you are signed in, so the audit appears in your history.
- To build the report, our system visits the public home page of that website and reads its title, description, headings, visible text and structured data. It stores the brand name and business category it detects, the questions it asked, and every answer the AI engines gave. This is mostly business information, not information about you.
When you ask for the full report:
- Your full name and email address. The report opens in your browser as soon as you enter them, and goes by email only to the address you entered. You can also enter them while the audit is still running: we email the report when it finishes, or one short note if the audit could not be completed.
- The page you were on and the campaign tags in the link (for example utm_source), and the time.
- A record of the link in your report email: your email, name, IP address, the time, and when and how many times the link was opened. We keep only a scrambled (hashed) copy of the link. It lasts 30 days.
- When you open the report from that link and then use the page (scroll, tap, type or move the pointer), we record your email address as confirmed for that report and create or link your account record. This does not sign you in.
- Until October 6, 2026, the form also offered a "Track my score" box (an updated score by email once a month). It is no longer offered. If you ticked it then, we recorded that choice. You can withdraw it at any time by unsubscribing.
When you sign in:
- There are no passwords. You enter your email (and your name, if you like) and we email you a sign-in link that works once and expires after 15 minutes.
- Signing in, or confirming a report as described above, creates your account record: email, name, when it was created and when you last signed in.
When you send us a message (signed-in users, with the message button):
- The subject, the message, its type (feedback, suggestion or help) and our reply.
To keep the service safe and working:
- Each request to send an email or sign-in link, with your email address, IP address, report ID or account ID and the time, so we can limit abuse.
- A copy of each email we send, whether it was delivered, and any bounce or spam complaint our email provider reports.
- Your email address and the reason, if you unsubscribe or an email to you bounces or is marked as spam.
When you browse the site:
- Google Analytics 4 and the Meta Pixel load only after you interact with the page: a scroll, a tap, a key press or a pointer movement. A one-line notice in the site footer says so. There is no banner.
- Once loaded, they record pages viewed and the full page address, your device and browser, the referring site and approximate location from your IP address. They also record when you start an audit and when you view a report. They set cookies or similar identifiers.
- Your browser's local storage keeps the ID of your last audit and whether you have seen the dashboard welcome and the beta notice. This stays on your device.
We do not collect passwords or payment information, and we do not knowingly collect information from children.
If you used doiexist.ai before October 3, 2026, your earlier audits and the name and email you gave were moved to the systems described here.
Why we use it
- To run your audit and show your report. We show the report in your browser, email you a copy with the PDF and a link to it, or send a short note if the audit could not be completed.
- To sign you in and show your dashboard and audit history, and to answer your messages.
- To prevent abuse. Daily audit limits and limits on emails and sign-in links.
- To follow up, within the law.
- Your name, email, company, website, the page and campaign tags and a summary of your audit (score, competitors, missed questions and suggested actions) go to our Command Center when you enter your email, and again when you confirm it from the emailed link.
- Asking for a report is an inquiry. It gives us implied consent under CASL to email you about our services for 6 months from your latest inquiry. A new report request, a booking or a call with us starts the 6 months again.
- Follow-up emails come from a Simplee Digital mailbox. They may be written with the help of AI, using your first name, company and audit results. A person at Simplee Digital reads every reply.
- Every email lets you stop. Emails from doiexist.ai have an unsubscribe link. Follow-up emails from Simplee Digital tell you to reply "unsubscribe". Either way, we stop.
- An unsubscribe on doiexist.ai is passed to our Command Center, so Simplee Digital stops too.
- If an email to you bounces permanently or is marked as spam, our email provider tells us and we stop emailing that address. We also do not send a new report to an address that has unsubscribed.
- To improve the site. We use analytics and advertising measurement to see which pages and campaigns work.
Who we share it with
We do not sell personal information. We share it only with service providers that help us run the site and our business:
| Provider | Purpose | What they receive |
|---|---|---|
| Railway | Hosting for the site, its database (shared with our Command Center) and stored PDF reports | Everything described in this policy |
| Cloudflare | Domain name service for doiexist.ai, and a proxy and content delivery network that every visit passes through | Your IP address and request data (the page requested, browser details and the time) |
| Resend | Sending doiexist.ai email, and reporting bounces and complaints | Your email address, name and the email content, including the PDF |
| OpenAI (ChatGPT) | Answering the audit questions | The questions only (some name the brand) |
| Anthropic (Claude) | Answering the audit questions; AI processing in the Command Center to prepare follow-up drafts | For the audit: the questions only. For follow-up: your first name, company and audit summary, not your email address |
| Gemini answers the audit questions and helps build the report; Workspace email for our follow-up; Google Analytics 4, loaded only after you interact with the page | Gemini: the website address, text from its public home page, the brand name and category, the questions, AI answers about the brand and competitor names. Workspace: your email address and the emails exchanged. Analytics: browsing data described above | |
| Meta | Meta Pixel, for advertising measurement, loaded only after you interact with the page | Browsing data described above |
| Calendly | Scheduling a call, if you click a booking link in a follow-up email. The scheduler opens with your name and email filled in, and Calendly's own privacy policy applies to what you enter there | Your name and email |
None of the AI engines receives your name, email address or IP address from an audit. Links to book a call go to simplee.digital, which has its own privacy policy.
The Command Center. It is our internal customer relationship system. Report requests from this site go into it, and only Simplee Digital staff can sign in to it.
We may also disclose information if the law requires it, or to a buyer if the business is sold, under this policy.
Where it is stored
Our database and some providers are in the United States: Railway hosts in the US West region, and Resend, OpenAI, Anthropic, Google and Meta process data in the US. Information stored outside Canada is subject to the laws of that country, and authorities there may be able to access it.
How long we keep it
- Audits, reports and PDFs: 24 months, then deleted, unless you ask us to delete them sooner.
- Your name, email address, report requests, account and our Command Center record: 24 months after your last contact with us, then deleted or made anonymous, unless you ask us to delete them sooner.
- Security records and copies of emails we sent: no longer than the 24 months above.
- Unsubscribes: if you unsubscribe, your email address stays on our unsubscribe list so we never email you again.
- Analytics data: kept by Google and Meta under their own retention settings.
Who can see your report
- The report goes only to the email address entered, and opens in the browser of the person who entered it. Anyone who types a name and email into the report form sees the report in their own browser.
- The link in your report email lasts 30 days, can be used more than once and opens only that report and its PDF. Anyone who has the email, for example if you forward it, can open the report. Opening it does not sign anyone in.
- The report page address is long and unguessable. Once an email address has been confirmed through the emailed link, anyone who has the page address can view the full report, including the AI answers. The Share button copies this address. Before that, anyone with the page address sees only the website, brand name and score.
- When the address is shared on social media, the preview image shows the brand name and score. We ask search engines not to index report pages.
- Agencies may share reports with their clients. Share links only with people you want to see the report. To have a report removed, write to [email protected].
Your choices and rights
- You can ask to see the personal information we hold about you, ask us to correct it, withdraw your consent, or ask us to delete it, subject to legal limits. If you ask us to delete it, we keep your email address on our unsubscribe list so we never email you again.
- To make a request, write to [email protected] or to the address below. Tell us the email address you used; we may ask you to confirm it is yours. We reply within 30 days.
- You can unsubscribe from any email with the link in it, or by replying "unsubscribe" to a follow-up email.
- Cookies. The site sets two cookies of its own, both needed for it to work, both signed so they cannot be changed, and neither readable by page scripts:
dx_reports: set when you enter your email in the report form or open the link in your report email. It lasts 30 days and lists the reports this browser may open, with the email address for each and whether it has been confirmed. It does not sign you in.dx_session: set when you sign in with a sign-in link. It keeps you signed in for 30 days and holds your account ID and email address. Signing out removes it.
- Analytics and advertising cookies. Google Analytics and the Meta Pixel set their own cookies once they load, which happens only after you interact with the page. You can block or delete cookies in your browser and opt out of Google Analytics with Google's opt-out tool. The audit works without them; opening a report needs
dx_reportsand signing in needsdx_session. - If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada.
Security
- Data travels over encrypted connections (HTTPS).
- There are no passwords to steal. Sign-in links work once and expire after 15 minutes. Report links last 30 days and open only one report. Both are stored only in scrambled (hashed) form.
- No database table can be read from the browser. Reports are served only through checks on who may view them.
- Forms that start an audit or send email accept requests only from doiexist.ai's own pages.
- A site-wide hourly limit applies to new audits, and we refuse website addresses that do not exist.
- Our audit browser refuses to visit private or internal network addresses.
- Only staff who need it can access the Command Center.
- No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify you and the Privacy Commissioner as the law requires.
Contact
Simplee Digital Marketing Inc., 171 East Liberty Street, Suite 305, Toronto, ON
Privacy requests and our privacy officer: [email protected] or the address above.
Changes
If we change this policy, we post the new version here with a new date. If a change is significant, we say so on the site before it takes effect.