# Privacy Policy · Terradium

Last updated: 21 June 2026

This Privacy Policy explains how Terradium, a GEO/AEO content and AI visibility platform created by [Kugie](https://kugie.app) and operated by PT Semesta Solusi Digital ("Terradium", "we", "us"), collects, uses, and shares personal information when you use our website and service at terradium.io and app.terradium.io, and when our Embed SDK runs on a customer's website (together, the "Service").

## 1. Who we are

Terradium is created by Kugie and operated by PT Semesta Solusi Digital. Terradium helps you write content built to be cited by AI engines, measures where you appear across AI answers (ChatGPT, Perplexity, Google AI Overviews, and Gemini), and (through the Embed SDK) helps you understand which of your visitors arrived from an AI answer.

For personal information about your own account, Terradium acts as a **data controller**. For data we process on your behalf, including the visitor events collected by the Embed SDK that you install on your website, you are the controller and Terradium acts as a **data processor**. The Data Processing Addendum at /dpa governs that relationship.

## 2. Information we collect

- **Account identity.** When you sign in, our authentication provider (Clerk) supplies your name and email address. We keep a mirrored copy to scope your data to your account. If you choose Sign in with Google, Google shares your name, email address, and profile picture with Clerk so we can create and secure your account. We use this only to sign you in. We do not access your Gmail, Calendar, Drive, contacts, or any other Google data.
- **Search Console data.** If you connect Google Search Console, we read your performance data (queries, pages, clicks, impressions, CTR, position, and AI-surface impressions) for the properties you authorize. You can disconnect at any time.
- **Project content and AI-visibility data.** The projects, articles, keywords, and prompt-sampling runs you create, and the resulting metrics (appearance rate, citation share, share-of-voice, average position).
- **Embed SDK visitor events.** When you install our embed on your site, it sends us visitor events on your behalf. By default this is non-PII traffic-source data.
- **Audit events and usage data.** A timeline of actions taken in your account, plus standard server logs used to operate and secure the Service. Source IP addresses seen by the embed endpoint are anonymized server-side and not stored in raw form.

## 3. The Embed SDK

When you add the Terradium embed to a website you operate, it collects a small set of non-PII signals about how a visitor arrived, so you can attribute traffic to AI answers. By default it collects referrer and traffic source (including an AI-referral classification), UTM parameters and gclid present on the landing URL, the entry path, and optional survey responses only if you enable the visitor survey.

No PII by default. The embed does not set advertising cookies, does not fingerprint visitors, and does not collect names, emails, or precise location. The visitor's IP address is used only transiently to derive coarse signals and is anonymized server-side.

Consent mode: the embed respects a consent posture you configure. When consent is required and has not been granted, the embed stays in a no-op / minimal mode. You are responsible for obtaining any consent your jurisdiction requires.

For embed visitor events, you are the controller and Terradium is the processor. See the [DPA](/dpa).

## 4. How we use information

- To generate, plan, and publish your content, and to serve it through the public content API.
- To sample AI engines and report where and how often your content is cited.
- To attribute, in aggregate, which visitors to your site arrived from an AI answer.
- To authenticate you, secure the Service, prevent abuse, and provide support.

We do not sell your personal information, and we do not use the content or visitor data you load into the Service for advertising.

## 5. Sub-processors

Clerk (authentication), OpenRouter and underlying model providers (generation and sampling), Google (Search Console for properties you connect), Cloudflare R2 (featured images), Polar (billing), Resend (email), Slack (optional notifications). A current list also appears in the DPA. We may also disclose information if required by law.

## 6. How we protect information

Every record is scoped to your account. Sensitive credentials are encrypted at rest using AES-256-GCM. The embed ingestion endpoint anonymizes source IPs. API and embed requests are authenticated, and the embed endpoint is rate-limited.

## 7. Data retention

We retain your account and content data for as long as your account is active. Embed visitor events are retained for a limited window, then deleted or aggregated (see the DPA). When you close your account, or on a valid deletion request, we delete or anonymize the associated personal information within a reasonable period, except where we must retain it to comply with legal obligations or resolve disputes.

## 8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Contact us to make a request. If your data was collected by a customer using Terradium's embed, we will refer your request to that customer as the controller.

## 9. International transfers

Terradium and its sub-processors may process information in countries other than your own. We take steps to ensure such transfers are subject to appropriate safeguards.

## 10. Cookies and analytics

The dashboard uses cookies necessary to keep you signed in and to operate the Service, and product analytics to improve it. The Embed SDK does not set advertising cookies on your visitors.

## 11. Changes

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you.

## 12. Contact us

Privacy questions: [legal@kugie.app](mailto:legal@kugie.app). Company support: [company@kugie.app](mailto:company@kugie.app). See also [/contact](/contact).
