This policy explains what we store, why, and how to have it deleted.
We never store card data, and we don't keep raw page bodies beyond what a finding needs. We authenticate with Google or a one-time email link — there are no passwords in this system.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to your records is locked to your account. Security detail about a domain is gated to verified domain owners.
Scan results are keyed to the domain. We retain anonymized domain-level records (scores and findings, with no link to your personal account) as a benchmark dataset. This survives account deletion by design — it is not personal data.
We use Supabase (database, auth, storage), Stripe (payments), Resend (email), Cloudflare Turnstile (bot protection), and cloud APIs (Browserless, Google PageSpeed, Anthropic, DataForSEO) to run scans. We share only what each needs to do its job, and we scrub email and secrets from our error monitoring.
The “AI visibility” section shows a third-party AI model's answer about a business, labeled and timestamped. It is that model's output, not our factual claim about any business.
You can permanently delete your account and personal data at any time from your account settings. This removes your email, scans, fix plans, screenshots, and Stripe linkage. The anonymized domain-level benchmark record (which contains no personal data) is retained.
Questions about your data? Contact us through the site.