Privacy Policy

Last updated: 19 May 2026 · Effective immediately
The short version We collect the minimum information needed to run your account, generate your AI visibility reports, take payment, and pay our affiliates. We do not sell your data. We host on UK / EU / US infrastructure and rely on UK GDPR-compliant Standard Contractual Clauses for any international transfers. You have full rights to see, correct, delete, or port your data — contact us at support@toplevelapp.com and we'll action it within 30 days.

Contents

  1. Who we are
  2. What information we collect
  3. Why we collect it (lawful bases)
  4. How we use it
  5. Third-party processors and sub-processors
  6. International transfers
  7. How long we keep your data
  8. Your rights under UK GDPR
  9. Cookies and similar technologies
  10. Security
  11. Children
  12. Changes to this policy
  13. Contact and complaints

1. Who we are

Top Level App is operated by Future Build Cov Ltd, a company registered in England and Wales, with its registered office in Coventry, United Kingdom. For the purposes of UK data protection law (the UK GDPR and Data Protection Act 2018), Future Build Cov Ltd is the data controller for personal information collected through the Top Level App service.

You can reach our data protection contact at support@toplevelapp.com or via WhatsApp on +44 7463 537535.

2. What information we collect

We collect only what we need to deliver the service. Specifically:

2.1 Account and billing data

2.2 Data you submit

2.3 Affiliate program data (only if you apply)

2.4 Technical and usage data

3. Why we collect it (lawful bases)

PurposeLawful basis (UK GDPR Art. 6)
Creating and managing your accountPerformance of a contract
Taking payment via Stripe and recording subscription statePerformance of a contract
Running the AI visibility checks you requestPerformance of a contract
Sending you transactional emails (sign-in links, invoices, account notifications)Performance of a contract
Affiliate program administration and commission payoutsPerformance of a contract
Security, fraud prevention, abuse detection, rate-limitingLegitimate interests (keeping the service safe and reliable)
Complying with our UK accounting, tax, and legal obligationsLegal obligation
Sending you marketing emails (if any are ever sent)Consent — and you can withdraw it at any time

4. How we use it

We use your data to:

We do not sell your personal data. We do not use it to train AI models. We do not share it for third-party advertising.

5. Third-party processors and sub-processors

We rely on a small number of reputable third-party services to run Top Level App. Each is bound by a written data processing agreement (DPA) and only handles data necessary for its specific function.

ServiceWhat it doesWhere data is processed
Stripe Payments Europe LtdSubscription billing, card processing, customer portalIreland / USA
Google Firebase & Google Cloud PlatformAuthentication, database, serverless functionsUSA (multi-region)
Resend Inc.Transactional email deliveryUSA
OpenAI, L.L.C.AI visibility and citation analysisUSA
Serper.devGoogle Search results lookup for keyword rankingUSA
Netlify, Inc.Static site hosting + content deliveryUSA / global edge

If you'd like a current list of sub-processors at any time, email support@toplevelapp.com.

6. International transfers

Several of our processors are based in the United States. Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR — specifically the UK International Data Transfer Agreement (IDTA), Standard Contractual Clauses (SCCs), or equivalent — to ensure your data remains protected to UK standards.

7. How long we keep your data

8. Your rights under UK GDPR

You have the following rights regarding your personal data. We will respond within 30 days of receiving a verified request.

To exercise any of these rights, email support@toplevelapp.com with the subject line "Data subject request". We may ask you to verify your identity before fulfilling the request.

9. Cookies and similar technologies

Top Level App uses a small, strictly necessary set of cookies. We do not use third-party advertising cookies or cross-site tracking.

CookiePurposeExpiry
tla_refStores an affiliate referral code so we can attribute commission to the affiliate who referred you90 days
Firebase Auth cookies (firebaseLocalStorageDb etc.)Keeps you signed in across visitsUntil sign-out
Stripe Checkout cookiesSet by Stripe on their hosted checkout page only — governed by Stripe's own privacy policyPer Stripe's policy
tla_url (session storage, not a cookie)Remembers the URL you typed on the homepage so the checkout flow can prefill itUntil you close the tab

10. Security

We take security seriously. Specifically:

11. Children

Top Level App is a B2B tool intended for business owners, marketers, and agencies. It is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

If we make material changes to this policy we will notify you by email (where we have one) and update the "Last updated" date at the top. Continued use of the service after a change constitutes acceptance of the updated policy.

13. Contact and complaints

For any data protection question or request, contact us at support@toplevelapp.com.

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):