Data Policy
What This Page Covers
This Data Policy is a companion to our Privacy Policy and sets out, specifically, what data we hold, how long we keep it, and how you can exercise your data rights.
Data We Store and How Long
- Account data (name, email, hashed password): kept for as long as your account exists, deleted on request.
- Site Audit reports: kept in your dashboard until you delete them individually or delete your account.
- Support tickets: kept for as long as needed to resolve your request and for a reasonable period afterward for support-quality purposes.
- Server/access logs (IP address, request metadata): kept for a limited period for security and abuse-prevention purposes, then rotated out.
- AI provider API keys (if you use a BYOK AI feature): stored encrypted, deletable at any time from your account settings.
Your Rights
Wherever you are, you can ask us to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data (e.g. update your name/email from your profile page directly).
- Delete your account and associated data.
- Withdraw consent for optional cookies at any time.
To exercise any of these, contact us via our Contact page or an in-app support ticket. We aim to respond within a reasonable time and will verify your identity before acting on a request.
No Sale of Data
We do not sell, rent, or trade your personal data to third parties.
Sub-processors
To provide certain tool results, data you submit (the URL/domain you're checking, not your account details) may be sent to: Google (Custom Search, PageSpeed Insights, Safe Browsing), crt.sh, and the Internet Archive's Wayback Machine. If you use an AI-powered feature with your own key, your request is sent to the AI provider you selected (OpenAI, Anthropic, Google, or DeepSeek).
Security Measures
HTTPS everywhere, hashed passwords, encrypted storage for sensitive credentials like AI API keys, and role-based access to our admin systems.