Legal · Draft for counsel review
Privacy Policy
Last updated: August 2, 2026
This page describes how the GunSearchEngine / Betsy products handle data based on current product behavior. It is a product-accurate draft and should be reviewed by counsel before you rely on it as final legal terms. Operator: Coriolis Agency / Coriolis, LLC.
1. Who we are
We operate GunSearchEngine.com (multi-dealer product search with Betsy AI), related dealer embed experiences, shopper alerts (My Betsy), public demand insights, and Betsy Brand Intelligence (enterprise demand analytics). GunSearchAgent.com is a related dealer product that may send data to this platform via server APIs.
2. Data we collect
- Search & chat — messages you send Betsy, extracted search filters (caliber, brand, type, price, etc.), and product interaction signals used to run search and improve continuity.
- Email & alerts — email addresses you provide to receive result lists, restock / price alerts, or magic-link sign-in; watch/alert preferences.
- Session & technical — server-minted session ids, coarse geo from CDN headers (country / region / city when available), channel (web vs embed), timestamps, and rate-limit counters.
- Embed / host context — on dealer sites using our widget: page path, first-touch referrer host/path (not full referrer URL), landing UTM/click ids, and funnel stage hints (browse / cart / checkout / purchase) when detected. We do not store full host product page HTML scrapes.
- Enterprise portal — account email, name, password hash, API key metadata (hashed secrets), and audit events for Brand Intelligence clients.
- Seller / catalog — product feed data from participating retailers (titles, prices, stock, UPCs, links) and seller configuration for embeds.
3. How we use data
- Provide search, chat, product cards, email lists, and alerts
- Authenticate shoppers (magic link) and enterprise users
- Operate dealer embeds scoped to that seller's catalog
- Build anonymized or aggregated demand analytics (public Insights, seller intel, Brand Intelligence)
- Secure the service (rate limits, abuse prevention, audits)
- Send transactional email you request (results, alerts, resets)
4. AI processing
Chat and some intent extraction may be processed by our AI provider (xAI / Grok) to understand queries and generate replies. Do not submit sensitive personal data you do not want processed by subprocessors. Catalog search itself is constrained by our product database and policy layer.
5. Sharing
- Dealers (GSA / embed) — store-scoped leads and intel for that seller where product features enable it; not full multi-dealer market export for Free tiers.
- Brand Intelligence clients — anonymized demand packages and sanitized sessions. Never includes emails, session ids, seller hosts, or product URLs. May include free-text search slots (e.g.
q), referrer host/path, landing UTM, and public catalog fields on UPC boards. See Enterprise API docs. - Public Insights — aggregated demand and US-state map counts only (no session dump or order dollars).
- Vendors — infrastructure and email (e.g. hosting, database, SMTP, AI API) under their respective terms.
- We do not sell personal email lists as a standalone product.
6. Retention (product defaults)
- Search intent event trail: pruned on the order of ~14 days
- Feed sync logs: short retention (default ~24 hours)
- Demand daily rollups: retained longer for multi-day analytics
- Chat sessions / leads and shopper watches: retained while needed for product features unless deleted via request
7. Cookies & similar
We use HttpOnly session cookies for shopper magic-link identity (gse_shopper) and enterprise portal login (gse_enterprise). Embed UIs may use browser storage for conversation continuity on the host origin. Analytics may use Vercel Analytics.
8. Your choices & deletion
You can stop using the service, unsubscribe from daily seller insights where offered, pause/delete alerts in My Betsy, and revoke enterprise API keys in the portal. To request access, correction, or deletion of personal data associated with your email, contact devops@coriolisagency.com or use Coriolis contact. We may need to verify control of the email address.
9. Security
We use TLS in transit (hosting provider), hashed enterprise API keys and passwords, rate limits, and access controls on admin and partner APIs. No method of transmission or storage is 100% secure.
10. Children
The service is intended for adults engaged in lawful firearms and ammunition commerce. It is not directed at children under 13 (or under 16 where applicable).
11. Changes
We may update this policy as the product evolves. Material changes will be reflected by updating the date above and, where appropriate, additional notice in product UI.
12. Contact
Privacy requests: devops@coriolisagency.com. General: coriolisagency.com. See also Terms of Use.