We use cookies for analytics and advertising measurement. Your data is never sold. Privacy Policy

Cookie Preferences

Essential Cookies
Required for forms, security, and basic site function.
Always on
Analytics (Google Analytics 4)
Anonymized page view data. Helps us understand how visitors use this site.
Marketing (Meta Pixel, Kit)
Conversion tracking and email attribution. No data is sold.

Privacy Policy

Last updated: April 2, 2026

This privacy policy explains how Anthony Spitaleri LLC ("we," "us") collects, uses, stores, and protects your information when you use anthonyspitaleri.com, including the AI Visibility Audit, AEO Fix Pack, AEO Monitoring, coaching services, and all related digital products.

We do not sell your data. We do not share your personal information with data brokers, advertisers, or any third party for their own marketing purposes.

This policy is incorporated into our Terms of Service. Together they govern your use of all our products and services.

What We Collect

Data TypeWhen CollectedPurpose
Name and emailAudit results, Phase Check, Fix Pack intake, coaching inquiryDelivering results, follow up communication, email marketing
Business URLAudit scan, Fix Pack intakeRunning the AI Visibility Audit and generating fix files
Business details (name, category, description, address, phone, social profiles, keywords)Fix Pack intake formGenerating schema markup, llms.txt, and other technical fixes
Website credentials (WordPress Application Password)Fix Pack intake formDeploying technical fixes to your website
Audit scores and pillar dataEvery audit scanDelivering results, monitoring trends, generating aggregate statistics
Coaching session contentDuring coaching engagementsDelivering coaching, generating anonymized insights for training
Payment informationAt purchaseProcessing payment (handled by Stripe; we do not store card numbers)

How We Store Your Data

Server side storage. Lead records and intake form data are stored in encrypted, non-public directories on our web server (hosted by Kinsta, a SOC 2 compliant WordPress hosting provider). These files are not accessible via any public URL.

Credentials. Website credentials submitted through the Fix Pack intake form are stored temporarily for deployment purposes only. Credentials are automatically purged within 24 hours of service delivery by an automated retention script. We never store your WordPress login password. We use Application Passwords with limited scope.

Email marketing. Your name and email are stored in Kit (formerly ConvertKit) for the purpose of sending audit results, service updates, and educational email content. You can unsubscribe from any email with one click.

Payment processing. All payments are processed through Stripe. We do not store, see, or have access to your full credit card number. Stripe's privacy policy governs payment data: stripe.com/privacy

Data Retention

Data TypeRetention PeriodEnforcement
Website credentials24 hours after service deliveryAutomated (data_retention script)
Fix Pack intake records30 days after service deliveryAutomated (data_retention script)
Audit lead records (email, name)90 days from submissionAutomated (data_retention script)
Audit scan data (domain, score, pillar breakdown)Indefinite (anonymized, no PII)Used for aggregate analysis only
Kit email subscriber dataUntil you unsubscribeManaged through Kit
Coaching session recordsDuration of engagement plus 12 monthsManual review, anonymized for AI coaching system improvement (all identifying details removed)

Retention periods are enforced by an automated script that runs daily. When a retention window expires, the data is permanently deleted from our server.

Third Party Services

Our systems interact with the following third party services in the course of delivering our products. Each interaction is limited to the minimum data required for the specific function.

ServiceWhat We SendPurposeTraining Exclusion
Anthropic (Claude API)Business name and URLAI citation testing during auditNot used for model training per Anthropic API terms
OpenAI (ChatGPT API)Business name and URLAI citation testing during auditAPI data not used for training per OpenAI API terms
Google (Gemini API)Business name and URLAI citation testing during auditAPI data not used for training per Google API terms
Perplexity APIBusiness name and URLAI citation testing during auditSubject to Perplexity API terms
Kit (ConvertKit)Name, email, tagsEmail marketing and automationN/A
StripePayment details (direct to Stripe)Payment processingN/A
Google Analytics 4Page views, anonymized usage dataWebsite analyticsN/A
Meta (Facebook Pixel)Page views, conversion eventsAdvertising measurementN/A

Queries sent to AI services (Anthropic, OpenAI, Google, Perplexity) are transient. They are used to test whether your business is cited by AI search engines. These queries contain your business name and URL only. They are not stored by us beyond the audit cache period (24 to 72 hours).

AI vendor training exclusions. All AI queries are made through API endpoints, not consumer interfaces. Under current API terms: Anthropic does not use API inputs or outputs to train models. OpenAI does not use API data for training unless you opt in. Google Gemini API data is not used for model improvement per their API terms. We review these vendor policies quarterly and will update this disclosure if any vendor changes their terms.

Cookies and Tracking

This website uses the following cookies and tracking technologies:

You can opt out of tracking by clicking "Manage Preferences" on the cookie consent banner displayed when you first visit the site. You can also disable cookies in your browser settings at any time.

Your Rights (CCPA)

If you are a California resident, you have the right to:

To exercise any of these rights, email anthony@anthonyspitaleri.com with the subject line "Privacy Request." We will respond within 45 days.

Your Rights (GDPR)

If you are located in the European Union or European Economic Area, you have the right to:

Our legal basis for processing your data is consent (you provide your information voluntarily) and legitimate interest (delivering the service you requested). To exercise any GDPR right, email anthony@anthonyspitaleri.com with the subject line "GDPR Request." You will receive an acknowledgment within 48 hours confirming we have received your request. We will complete your request within 30 days.

Data Security

We implement the following measures to protect your data:

Aggregate Data and Content

We use anonymized, aggregate audit data to create educational content. Examples: "The average small business scores 42 out of 100 on AI visibility" or "73% of sites tested have no llms.txt file." Anonymization means we change a minimum of three identifying details (industry, location, business size, revenue range) so that no published data can be traced to a specific business. We never publish your business name, URL, score, or any identifiable details without your explicit written consent.

Children

Our services are designed for business owners and professionals. We do not knowingly collect information from anyone under the age of 18. If you believe we have collected information from a minor, contact us immediately and we will delete it.

Changes to This Policy

We may update this policy as our services evolve. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated via email to active clients and subscribers.

Contact

For any privacy related questions, data requests, or concerns:

anthony@anthonyspitaleri.com
Anthony Spitaleri LLC
Davie, Florida