GDPR covers EU citizens. I don't think it says anything about non-EU citizens.
GDPR also applies to EU based companies for all of their activities - so in addition to limiting US business in the EU, it limits EU businesses in the US.
So I guess you need to assume this applies for all visitors.
I strongly disapprove of extraterritorial legislation (a US specialty). But in the case of the GDPR, if you want to regulate internet activity, then you more-or-less have to go extraterritorial.