Privacy Policy
This policy describes exactly what the tool records. It is short because the tool collects little: there are no accounts, no advertising cookies and no third-party trackers beyond the analytics described below.
Audits you run
When you audit a URL we store that URL, the final URL after redirects, the score and grade, the HTTP status code, the response time, the pass/warning/failure counts and the full report. The report holds the evidence each rule found — at most ten items per rule — taken from the audited page and its response: the title tag, meta description, headings, canonical URL, image and link URLs including any query string, sitemap URLs, any author name the page declares, and security headers such as Strict-Transport-Security and the first 200 characters of Content-Security-Policy. The page's full HTML is not retained.
Audits that fail
If an audit cannot complete — the site refuses the connection, returns an error, or times out — we record the error code, the hostname and the HTTP status so we can see which failures are common. Only the hostname is kept in that case, never the path or query string.
Who can see your audits
Stored audits are not published anywhere on this site and are not readable by other visitors — only the operator can read them. Audits are recorded at all only when the deployment has Supabase configured.
Rate limiting and your IP address
Audits and contact messages are rate limited. To count requests we store your IP address with a timestamp. It is not linked to an audit record and is used for nothing else. Entries older than a day are cleared as later requests arrive, so on a quiet site an entry can linger past that.
How long we keep things
Audit records are deleted from our database within 90 days by a nightly job; encrypted database backups roll off on our provider's own schedule, and hosting and CDN request logs are retained by those providers. Rate-limiting entries are short-lived as described above. Messages you send through the contact form are kept until you ask us to delete them, because they are correspondence we may need to refer back to. Ask us and we will delete a specific audit record or contact message.
Analytics and consent
We use Google Analytics to count visits and see which features get used. It runs under Google Consent Mode with analytics_storage denied by default, so no analytics cookie is written and no measurement data is sent until you accept the cookie banner. Declining leaves analytics off; you can change your mind by clearing this site's data in your browser. Running an audit does not put the audited URL in the address bar, so it is not sent to Analytics — but if you use the share buttons, or open a shared link, the URL is in the address bar and is then sent to Analytics and to whichever network you shared it on.
Cookies and local storage
Your consent choice, your light/dark theme preference and the recent-audit list described below are kept in your browser's local storage, not sent to us. If you accept analytics, Google Analytics sets its own cookies to distinguish sessions. There are no advertising or profiling cookies.
The audit list in your browser
The audits listed on /history are held in your browser's local storage and are never sent to us: for each one, the final URL, the score and grade, the pass/warning/failure counts and the time you ran it, for up to twenty audits. Entries older than 24 hours are discarded the next time you open that page — if you never go back, they stay in your browser until you clear this site's data, which is worth knowing on a shared computer. The Clear history button on that page removes them all immediately. This list is separate from the audit record on our server, which follows the 90-day rule above.
Messages you send us
If you use the contact form, the name, email address and message you type are stored so we can reply. They are used for nothing else and are not shared.
Processors we rely on
Vercel hosts the application and processes request logs, Cloudflare sits in front of it as a CDN, Supabase stores audit records, rate-limiting entries and contact messages, and Google provides Analytics. Each receives only what its role requires.
Your rights
You can ask us to delete an audit record or a contact message, or ask what we hold about you. Use the contact form and tell us the URL or message concerned. Because audits are not tied to an identity, please give us enough detail to find the record.
Changes
If this policy changes materially we will update the date at the top of this page. Continuing to use the tool after a change means the updated policy applies.