What we hold
accountemail, nameYour email address, an optional name, and a hash of your password (argon2id — we never see the password itself). Lawful basis: performance of the contract.while active
sitesurls, settingsThe addresses you asked us to monitor and how you configured the crawl.while active
resultsscan dataScores, failing rules, page URLs, CSS selectors and truncated markup snippets of failing elements. Kept for your plan's retention window, then deleted automatically.per plan
operationslogsRequest logs and error traces, for keeping the service up.30 days
anonymouspublic scansA free check stores the URL and its results against a random slug, plus a per-IP counter for the rate limit. Deleted after fourteen days.14 days
What we do not do
noad trackingNo advertising pixels, no third-party analytics that follow you across sites.none
noselling dataWe do not sell or share your data with data brokers.ever
nocard detailsPayment is handled by Paddle as merchant of record. Card details never reach our servers.never stored
nopage contentWe do not keep copies of your pages — only the small snippets of markup that failed a check.not archived
Who else touches it
hostingVercel, RailwayApplication hosting and managed Postgres/Redis.EU/US
paymentsPaddleMerchant of record. Handles the transaction, tax and invoice, and holds the billing details.MoR
emailResendSends alerts and account email. No marketing lists.transactional
Your rights
Under the GDPR you can ask for a copy of your data, correction, deletion, or export. Write to [email protected]. We answer within thirty days, usually the same week. Deleting your workspace deletes the sites, scans and issues with it.
Cookies
One: an httpOnly session cookie once you sign in. It is strictly necessary, so there is no consent banner to click through. Nothing tracks you before you have an account.