Privacy policy
Effective 6 August 2026
In short
We collect the minimum needed to run audits and bill for them. We do not sell your data, we do not run advertising, and we do not store raw IP addresses. Audited pages are fetched, analysed and discarded — we keep the findings, not your page.
What we collect
| Data | Why | Kept for |
|---|---|---|
| Email address, name, profile image | To create your account and contact you about it | Until you delete your account |
| URLs you audit, and the resulting reports | To show you your reports and history | Your plan's retention window (90 days to 2 years) |
| Usage counts (audits run, exports taken) | To enforce your plan's monthly quota | Rolling 12 months |
| A salted hash of your IP address | Rate limiting and abuse prevention | Up to 1 hour |
| Browser user-agent string | Troubleshooting failed audits | With the audit record |
| Error logs | Diagnosing faults | 30 days |
On IP addresses
We never write your IP address to disk. It is hashed with a secret salt on arrival, and only the hash is stored. That is enough to count requests from the same source for rate limiting, and not enough to identify you or to reconstruct the original address.
On the sites you audit
When you audit a URL we fetch that page and analyse it in memory. We keep the findings and a summary of extracted facts — title, headings, response headers, link and image counts. We do not retain the full page source.
If a page contains something matching the shape of a private API key, it is redacted before it enters a report. A report should never become a second place a secret leaks.
Who else processes it
We use these services to operate the product. Each receives only what it needs.
| Service | Purpose | What it receives |
|---|---|---|
| Vercel | Application hosting | All request traffic |
| Neon | Database hosting | Account records and reports |
| Clerk | Authentication | Email, name, profile image, sign-in events |
| Google PageSpeed Insights | Core Web Vitals data | The URL being audited — nothing about you |
| Google AI Studio or Anthropic | Writing the report summary | Audit findings and the audited domain, only when an AI driver is enabled |
| Zoho Mail | Transactional email | Your email address and message content |
The AI step is optional. When no AI provider is configured, report summaries are generated by our own rules engine and nothing leaves our infrastructure.
Why we are allowed to (UK/EU)
- Contract. Account data and audit records — we cannot provide the service without them.
- Legitimate interests. Hashed IPs and error logs, for security and reliability. We considered the privacy impact and chose hashing and short retention to minimise it.
- Consent. Marketing email, if you opt in. Withdraw at any time.
Your rights
Depending on where you live you may have the right to access, correct, delete, export or restrict processing of your data, and to object to it. Email privacy@checkmysites.com and we will respond within 30 days.
Deleting your account soft-deletes your profile immediately and removes your reports at the end of your plan's retention window. To have everything erased immediately instead, say so in your request.
Cookies
We set a session cookie so you stay signed in, and a preference cookie remembering your light or dark theme. That is all. There are no advertising cookies and no third-party trackers.
Security
Traffic is encrypted in transit. Passwords are handled entirely by Clerk and never reach our servers. API keys are stored hashed. Access to production data is limited to the operator.
No system is perfectly secure. If we discover a breach affecting your data we will notify you and the relevant supervisory authority as required by law.
Children
This service is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
If we change this policy materially we will email account holders before it takes effect. The effective date above always reflects the current version.