Privacy & Data

Privacy Policy

We collect only what we need, we don’t sell your data, and you can delete it yourself. If AI is involved, we say so. Here’s the detail.

Last updated July 23, 2026
On this page

1. Who we are

Icarus Works (“we,” “us”), operated by Dominion Studios, provides AI-search visibility audits and ongoing optimization for businesses. This policy explains what personal information we process and your choices. It applies to icarusworks.ai and our application.

2. Notice at collection — what we collect and why

In short: Email + the domain you want analyzed for the free check; account and purchase details when you buy; onboarding/support content you send; limited technical data automatically.

You provide

  • Free AI-visibility check: your email, the website/domain to analyze, and optionally industry and city. Used to deliver results and — until you unsubscribe — a short series of related follow-ups.
  • Account & audit purchase: email, business name, website. Payment is processed by Stripe — we never see or store full card numbers.
  • Onboarding & support: details you submit (CMS, access notes, brand info, priorities) and messages to our AI strategist/concierge or support.
  • Team invites: email addresses you invite to your workspace.

Collected automatically

  • Technical / usage: IP address (rate-limiting, fraud/abuse prevention, security), request metadata, error diagnostics.
  • Bot protection: Cloudflare Turnstile challenge data to tell humans from bots on our forms.

Businesses we analyze

Our audits use publicly available information about a domain, and we retain a record of each check (subject domain, industry, cited sources) to improve analysis. This is business, not consumer, information.

Purpose categories. Deliver the service; authenticate and secure accounts; prevent abuse; send transactional and (opt-out-able) marketing messages; improve our models and analysis; run our B2B outreach; comply with law.

3. Business-outreach (cold email) data

In short: We run business-to-business outreach. We hold basic business-contact information for prospects, and anyone can opt out instantly.

We conduct B2B outreach to businesses (primarily U.S. small businesses and trades). For those prospects we process business-contact data — such as business name, business email address, website/domain, city, and trade/industry.

Source of this data. We obtain business-contact data from third-party business-data providers and publicly available business sources (such as business listings and directories). We do not knowingly source or target personal, non-business email addresses for cold outreach, and we exclude recipients outside the United States.

Your choices as a recipient.Every outreach message includes a way to opt out (an unsubscribe link and/or a “reply STOP” instruction), which we honor immediately and permanently across our sending systems. To access or delete the data we hold about you, email privacy@icarusworks.aiand we’ll remove you.

4. How we use data

  • Deliver the visibility check, audit, and optimization you request.
  • Authenticate you (passwordless codes / magic links) and secure your account.
  • Prevent abuse, rate-limit, and protect the platform (uses IP + bot protection).
  • Send transactional email (audit ready, sign-in links, billing/account notices).
  • Send service follow-ups and B2B outreach. Marketing/nurture emails always include one-click unsubscribe that stops them immediately; transactional/account messages are unaffected. We honor opt-outs right away.
  • Improve our models and analysis quality.

We do not sell your personal information.

5. Legal bases (GDPR/EU/UK, where applicable)

  • Contract: to provide the service you requested.
  • Legitimate interests: security, abuse prevention, B2B outreach to business contacts, service improvement.
  • Consent: marketing emails and any non-essential cookies/analytics.
  • Legal obligation: where we must retain records.

6. Sharing & sub-processors

In short: We share data only with vendors that process it for us, under contract. We do not sell personal information or share it for cross-context behavioral advertising.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, and hosting of your account recordsUnited States
VercelApplication hosting and global content deliveryUnited States
StripePayment processing (we never see or store full card numbers)United States
ResendTransactional and sign-in email deliveryUnited States
SmartleadBusiness-to-business outreach (cold email) sending and reply handlingUnited States
Cloudflare (Turnstile)Bot and abuse protection on our formsGlobal
Upstash (Redis)Rate-limiting and cachingUnited States
AnthropicAI processing for audits, recommendations, and the AI concierge/strategistUnited States
OpenAIAI processing for audits, recommendations, and supportUnited States
PerplexityAI answer-engine querying for visibility analysisUnited States
PineconeSemantic memory for your workspace's AI assistantUnited States
SentryError monitoring and diagnostics (when configured)United States

We may also disclose data if required by law or to protect rights and safety.

7. AI processing & disclosures

In short: We use AI for audits, recommendations, and chat/support, and we tell you when you’re dealing with AI.

Icarus Works uses artificial intelligence to generate audits and recommendations, power the in-app AI concierge/strategist, help resolve support requests, and compose some outreach replies. We disclose when you’re interacting with an AI system, and if you ask whether you’re dealing with a human or AI, we’ll tell you plainly. AI output can contain errors and is not professional advice. We do not use your private workspace content to train third-party foundation models beyond what is necessary to process your request. See our AI & Automation Disclosure and Responsible AI principles.

8. Retention

We keep personal data while your account is active or as needed to provide the service, then delete or anonymize it, except where longer retention is required by law. Lead/outreach records are kept only as long as needed for the outreach purpose or until you opt out / request deletion. You can request deletion anytime (see below).

9. Your rights (CCPA/CPRA, other U.S. state laws & GDPR/UK)

Depending on where you live, you may have the right to:

  • Access / know the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data.
  • Opt out of marketing and of any “sale” or “sharing” of personal information (we do not sell or share for cross-context behavioral advertising).
  • Data portability and to restrict/object to certain processing (GDPR).
  • Not be discriminated against for exercising these rights.

How to exercise. Email privacy@icarusworks.ai or use the in-app control (below). We verify and respond within the timeframes required by law. You may use an authorized agent where the law allows. If we ever deny a request, you may appeal by replying to our response. See also Your Privacy Choices.

10. Delete your data (self-serve)

Signed-in users can request deletion from your account privacy settings. If you ran a free check without an account, email privacy@icarusworks.aifrom the address you used and we’ll erase your records. Deletion removes your account, workspace, reports, messages, and lead records, subject to limited legal retention.

11. Global Privacy Control & recognized opt-out signals

In short: We honor browser “Do Not Sell/Share” signals.

We honor the Global Privacy Control (GPC) and other recognized opt-out preference signals as a valid request to opt out of sale/sharing for the browser or device that sends them. Because we do not sell or share personal information for cross-context behavioral advertising, this mainly confirms that stance — but we treat a GPC signal as a binding opt-out.

12. Cookies & tracking

In short: Essential cookies only right now.

We use strictly necessarycookies for authentication and security. Our cookie banner is informational because we don’t currently set non-essential/analytics/advertising cookies. If we add analytics or advertising pixels later, we’ll update this policy and, where required (e.g., for EU/UK visitors), request consent first via the banner. See our full Cookie Notice.

13. Security

We protect data with row-level security (each customer accesses only their own records), encrypted transport (HTTPS), restricted server-side access to secrets, rate limiting, bot protection, and continuous error monitoring. No system is perfectly secure, but we work to protect your information. If a breach affecting your personal data occurs, we’ll notify you and regulators as required by applicable law. More detail is on our Security & Trust page.

14. Children

The service is for businesses and is not directed to anyone under 16. We do not knowingly collect data from children. COPPA does not apply — we do not target or knowingly collect from children under 13.

15. International users

We operate in the United States and our outreach targets U.S. businesses. If you access the service from outside the U.S., you understand your data is processed in the U.S. We do not knowingly send cold outreach to recipients outside the United States.

16. Changes

We’ll post changes here and update the effective date. Material changes will be notified where required.

17. Contact

Terms of Service →  ·  All policies →