Skip to content
CheckMySites

Privacy policy

Effective 6 August 2026

In short

We collect the minimum needed to run audits and bill for them. We do not sell your data, we do not run advertising, and we do not store raw IP addresses. Audited pages are fetched, analysed and discarded — we keep the findings, not your page.

What we collect

DataWhyKept for
Email address, name, profile imageTo create your account and contact you about itUntil you delete your account
URLs you audit, and the resulting reportsTo show you your reports and historyYour plan's retention window (90 days to 2 years)
Usage counts (audits run, exports taken)To enforce your plan's monthly quotaRolling 12 months
A salted hash of your IP addressRate limiting and abuse preventionUp to 1 hour
Browser user-agent stringTroubleshooting failed auditsWith the audit record
Error logsDiagnosing faults30 days

On IP addresses

We never write your IP address to disk. It is hashed with a secret salt on arrival, and only the hash is stored. That is enough to count requests from the same source for rate limiting, and not enough to identify you or to reconstruct the original address.

On the sites you audit

When you audit a URL we fetch that page and analyse it in memory. We keep the findings and a summary of extracted facts — title, headings, response headers, link and image counts. We do not retain the full page source.

If a page contains something matching the shape of a private API key, it is redacted before it enters a report. A report should never become a second place a secret leaks.

Who else processes it

We use these services to operate the product. Each receives only what it needs.

ServicePurposeWhat it receives
VercelApplication hostingAll request traffic
NeonDatabase hostingAccount records and reports
ClerkAuthenticationEmail, name, profile image, sign-in events
Google PageSpeed InsightsCore Web Vitals dataThe URL being audited — nothing about you
Google AI Studio or AnthropicWriting the report summaryAudit findings and the audited domain, only when an AI driver is enabled
Zoho MailTransactional emailYour email address and message content

The AI step is optional. When no AI provider is configured, report summaries are generated by our own rules engine and nothing leaves our infrastructure.

  • Contract. Account data and audit records — we cannot provide the service without them.
  • Legitimate interests. Hashed IPs and error logs, for security and reliability. We considered the privacy impact and chose hashing and short retention to minimise it.
  • Consent. Marketing email, if you opt in. Withdraw at any time.

Your rights

Depending on where you live you may have the right to access, correct, delete, export or restrict processing of your data, and to object to it. Email privacy@checkmysites.com and we will respond within 30 days.

Deleting your account soft-deletes your profile immediately and removes your reports at the end of your plan's retention window. To have everything erased immediately instead, say so in your request.

Cookies

We set a session cookie so you stay signed in, and a preference cookie remembering your light or dark theme. That is all. There are no advertising cookies and no third-party trackers.

Security

Traffic is encrypted in transit. Passwords are handled entirely by Clerk and never reach our servers. API keys are stored hashed. Access to production data is limited to the operator.

No system is perfectly secure. If we discover a breach affecting your data we will notify you and the relevant supervisory authority as required by law.

Children

This service is not intended for anyone under 16, and we do not knowingly collect their data.

Changes

If we change this policy materially we will email account holders before it takes effect. The effective date above always reflects the current version.

Contact

privacy@checkmysites.com