ByDefault
How it worksFAQPricing
Sign in
Legal

Privacy Policy

Last updated July 30, 2026

1. Who we are

ByDefault is run by Joscha Neske ("ByDefault", "we", or "us"), who is the controller under the EU General Data Protection Regulation (GDPR) for the personal data described in this policy, except where we act as a processor on behalf of our customers (see section 6). Full provider details are in the Imprint. You can reach us at hello@joshtriedcoding.com.

This policy covers bydefault.so, the ByDefault application, and the visibility analytics we provide. By using the service you agree to our Terms of Service.

2. Data we collect about you

Account data

When you sign up we collect your email address, your name, and, depending on how you sign in, a profile picture. Sign-in works via an email magic link or your Google or GitHub account. During onboarding we also store the answers you give us, such as your goals and how often you want to publish.

Session and log data

When you sign in we store a session record that includes your IP address and browser user agent. Our hosting provider processes request logs, including IP addresses, to operate and defend the service.

Workspace content

Everything you create in a workspace is stored so we can provide the service: your organization name and website, the prompts and topics you track, competitors, articles and drafts, author profiles, categories, chat conversations with our agents, uploaded files and images, and the answers, citations, and mention analytics our monitoring produces.

Connected services

If you connect GitHub for publishing, we store installation and repository metadata and use short-lived access tokens scoped to repository contents and pull requests. If you store environment variables for the coding agents, their values are encrypted at rest (AES-256-GCM), are decrypted only at the moment an agent run needs them, and are redacted from agent output. They are never shown to the AI models themselves.

Billing data

Payments are handled by our billing providers, Autumn and Stripe. Your card details go directly to Stripe and never touch our servers. We share your name and email with the billing provider and store your plan and usage counters.

3. How we use your data

  • To provide the service: run your tracked prompts, analyze answers, generate content, and publish where you tell us to.
  • To operate accounts, workspaces, and team invitations (invitation emails are stored until the invite is accepted or expires).
  • To bill you for your subscription.
  • To send transactional email such as sign-in links and invitations (via Resend).
  • To understand product usage and fix errors, using the analytics tools listed below.
  • To protect the service against abuse.

We do not sell personal data, and we do not send you marketing email without your consent.

4. AI providers

ByDefault runs your tracked prompts against AI assistants and uses AI models to analyze answers and write content. To do this, prompt text, article drafts, chat messages, and related workspace context are sent to AI providers, currently: Anthropic, OpenAI, OpenRouter (routing to Google and Anthropic models), Cursor, OpenCode, and Browserbase (which operates the cloud browser sessions used to query assistants the way a real user would). Each provider processes this data under its own API terms. We only send what is needed for the specific run, and we do not send your stored environment variable values to any model.

5. Analytics and cookies

We use cookies that are strictly necessary to keep you signed in. These are httpOnly session cookies set by our authentication system.

In production we additionally use:

  • PostHog (EU cloud, hosted in the European Union) for product analytics and error tracking. After sign-in, usage is associated with your account.
  • Vercel Analytics for aggregate page view statistics.

6. Visitor analytics we run for customers

Customers can install our tracking integration on their own websites to measure AI crawler and AI-referred traffic. Through it we receive server request logs from the customer's site, including visitor IP address, user agent, referrer, and the page requested. The IP address is used in memory to verify claimed crawler identities against the operator's published IP ranges and is discarded immediately after that check; it is never written to storage. Only requests recognized as AI assistant traffic are retained at all: records of ordinary visitor traffic are discarded at ingest, and of the location data we retain only the country. We use this data solely to provide visibility analytics to that customer.

For this data the customer is the controller and ByDefault is a processor under Art. 28 GDPR. Customers are responsible for disclosing this processing to their own visitors. A data processing agreement is available on request at hello@joshtriedcoding.com.

7. Subprocessors and service providers

We use the following providers to run ByDefault:

  • Vercel (hosting, Frankfurt region)
  • Neon (Postgres database)
  • Upstash (Redis, background workflows, realtime updates, and the isolated sandboxes that run coding-agent prompts)
  • ClickHouse (analytics warehouse for crawler and visibility data)
  • Amazon Web Services (S3 file storage behind our CDN)
  • Resend (transactional email)
  • Autumn and Stripe (billing and payments)
  • PostHog, Vercel Analytics (analytics, see section 5)
  • Anthropic, OpenAI, OpenRouter, Cursor, OpenCode, Browserbase (AI providers, see section 4)
  • Firecrawl (fetching and reading public web pages, including your own site, for research and onboarding)

8. Legal bases

We process your data to perform our contract with you (Art. 6(1)(b) GDPR), based on our legitimate interests in operating, improving, and protecting the service (Art. 6(1)(f) GDPR), to comply with legal obligations (Art. 6(1)(c) GDPR), and, where we ask for it, based on your consent (Art. 6(1)(a) GDPR).

9. International transfers

Our primary infrastructure runs in the European Union. Some providers, including the AI providers, process data in the United States or other countries outside the EEA. Where that happens we rely on the EU Standard Contractual Clauses or an adequacy decision such as the EU-U.S. Data Privacy Framework.

10. Retention

We keep your data for as long as your account exists, so your answer history and analytics stay available to you. If you delete a workspace, its data is deleted. To delete your account and associated personal data, email hello@joshtriedcoding.com and we will complete the deletion within 30 days, except where we must retain records to meet legal obligations (for example, invoicing).

11. Your rights

Under the GDPR you have the right to access, rectify, and erase your personal data, the right to restrict or object to processing, and the right to data portability. You can exercise these rights by emailing hello@joshtriedcoding.com. You also have the right to lodge a complaint with a supervisory authority. Our competent authority is the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit).

12. Changes to this policy

We may update this policy as the product evolves. We will post the updated version on this page and adjust the date above. For material changes we will notify you by email or inside the product.

13. Contact

Questions about privacy or this policy: hello@joshtriedcoding.com.

Your competitors are already in the answers. See where you stand.

Check AI visibility →
ByDefault

ByDefault tracks who ChatGPT and Claude recommend in your category, and shows you exactly what to publish to change the answer.

Quick Links

  • Pricing
  • FAQ
  • Sign in

Company

  • Twitter / X
  • Privacy Policy
  • Terms of Service
  • Imprint