1. Controller details
For personal data covered by this policy, the data controller is BoostLLMs, operated from Tallinn, Estonia.
Contact: contact@boostllms.com
Last updated: February 23, 2026
This Privacy Policy explains how BoostLLMs (https://boostllms.com) processes personal data under the GDPR and applicable Estonian law.
For personal data covered by this policy, the data controller is BoostLLMs, operated from Tallinn, Estonia.
Contact: contact@boostllms.com
When acting as processor, the customer submitting the URL is typically the controller (or another processor with authority), and BoostLLMs processes data on documented instruction.
| Data category | Examples | Purpose | Lawful basis |
|---|---|---|---|
| Account and identity data (Clerk) | Name, email, account identifiers, login metadata | Authentication, account management | Art. 6(1)(b), Art. 6(1)(f) |
| Billing and transaction data (Stripe) | Transaction IDs, billing data, credit events | Payments, invoicing, compliance, fraud prevention | Art. 6(1)(b), Art. 6(1)(c), Art. 6(1)(f) |
| Service usage and technical data | IP, device/browser info, timestamps, error logs | Operation, reliability, abuse prevention | Art. 6(1)(b), Art. 6(1)(f) |
| Audit request data | Submitted URLs, run settings, request parameters | Execute requested audits | Art. 6(1)(b) |
| Scraped website data (Firecrawl and pipeline) | Publicly accessible page content and metadata | Analyze requested URLs and generate reports | Art. 6(1)(b); Art. 28 framework where applicable |
| AI analysis and report data | Scores, recommendations, generated snippets, report history | Deliver requested outputs and improve quality | Art. 6(1)(b), Art. 6(1)(f) |
| Marketing communications | Preferences, interaction data | Product updates and marketing | Art. 6(1)(a) or Art. 6(1)(f) where legally permitted |
BoostLLMs does not sell personal data.
| Provider | Function |
|---|---|
| Clerk | Authentication and identity management |
| Stripe | Payments, subscriptions, credits, billing |
| Supabase | Database and storage |
| Vercel | Hosting and infrastructure |
| Firecrawl | URL fetching and web scraping at user request |
| Resend | Transactional email delivery |
| OpenAI | AI analysis and report generation |
| Anthropic | AI analysis and report generation |
| Google (AI APIs) | AI analysis and report generation |
| xAI | AI analysis and report generation |
Some providers process data outside the EEA, including in the United States. Where transfers occur, BoostLLMs uses GDPR-compliant safeguards, including:
BoostLLMs retains personal data only for as long as necessary for the purposes described in this policy.
| Data type | Retention approach |
|---|---|
| Account profile and identity data | Retained while account is active, then deleted or anonymized unless legally required longer |
| Audit reports and URL processing records | Retained while account is active and for a limited post-closure period, then deleted or anonymized |
| Security and operational logs | Retained for limited periods needed for security, abuse prevention, and reliability |
| Billing and accounting records | Retained as legally required, including Estonian accounting and tax obligations |
We may retain data longer where required by law or for establishment, exercise, or defense of legal claims.
Subject to GDPR conditions, you may request:
To exercise your rights, contact contact@boostllms.com. We may verify your identity before responding. Where BoostLLMs acts as processor, we may direct your request to the relevant controller and assist as required by Article 28 GDPR.
You may lodge a complaint with your local supervisory authority. In Estonia, the competent authority is:
Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Phone: +372 627 4135
Website: https://www.aki.ee/en
BoostLLMs uses necessary technologies for authentication, security, and core service functionality. Where non-essential analytics or marketing technologies are used, we request consent where legally required and provide controls to withdraw consent.
We implement appropriate technical and organizational measures to protect personal data, including access controls, encryption in transit where applicable, and security logging and monitoring.
BoostLLMs is not directed to children, and we do not knowingly collect personal data from children in violation of applicable law.
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised "Last updated" date. Material changes may also be communicated by email or in-app notice.
For privacy questions and rights requests, contact: contact@boostllms.com