Privacy Policy
Effective Date: August 29, 2026 · Last Updated: August 29, 2026
1. Introduction and Scope
This Privacy Policy ("Policy") describes how AuditMe ("we," "us," "our"), operated by Eduard Tymchenko, collects, uses, stores, shares, and protects personal information obtained through the website located at https://www.auditme.dev (the "Service") and any related websites, applications, APIs, or services.
By accessing or using the Service, you ("User," "you," "your") acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree, you must immediately cease all use of the Service.
This Policy applies to all Users worldwide, regardless of jurisdiction. Where applicable law provides additional protections, those protections supersede any less restrictive provisions herein.
This Policy is effective as of August 29, 2026 ("Effective Date") and supersedes all prior versions. We reserve the right to modify this Policy at any time. Material changes will be communicated via email to registered Users or through a prominent notice on the Service at least thirty (30) days before they take effect. Continued use after the effective date constitutes acceptance.
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection legislation including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and equivalent laws.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
"Service" means the AuditMe platform, including the website at auditme.dev, all subdomains, APIs, tools, dashboards, and any related applications or services.
"Data Controller" means the natural or legal person who determines the purposes and means of Processing Personal Data. For the purposes of this Policy, the Data Controller is Eduard Tymchenko.
"Data Processor" means a natural or legal person who Processes Personal Data on behalf of the Data Controller.
"Cookies" means small text files placed on your device by the Service, as described in Section 7 of this Policy.
3. Information We Collect
We collect only the minimum data necessary to provide and improve the Service. The categories of data collected are as follows:
3.1 Account Information
- Email address (required for account creation and authentication)
- Display name (optional, provided by you during registration)
- Password hash (managed exclusively by Supabase Auth; we never have access to your plaintext password)
- Profile photograph (optional, sourced from third-party OAuth providers such as Google or GitHub if you choose to link your account)
- Authentication tokens (managed by Supabase; stored as HttpOnly cookies and encrypted tokens)
3.2 Usage and Analytics Data
- Pages visited, tools used, features accessed, and session duration
- URLs submitted for analysis and the resulting audit outputs, scores, and recommendations
- Error logs, crash reports, and performance metrics
- Device type, browser type and version, operating system, and screen resolution
- Referring URL and general geographic location (city-level, derived from IP address)
- IP address (used for rate limiting, abuse prevention, and security; rotated and not stored long-term)
3.3 Payment Information
- We do not process, store, or transmit credit card numbers, bank details, or payment credentials directly.
- All payment processing is handled exclusively by third-party payment processors (currently Payoneer). We receive only a transaction confirmation and the amount paid. We do not receive or store your payment card details.
- For Pro subscriptions, we maintain a record of your subscription status, plan tier, start date, and expiration date.
3.4 Data You Provide Voluntarily
- Support inquiries submitted via email, Telegram, or the in-app support form
- Feedback, feature requests, bug reports, or survey responses
- Content you create using our content generation tools (blog posts, meta descriptions, schema markup, etc.)
- WordPress credentials (application passwords) provided for the WordPress Apply feature; these are encrypted at rest and used solely for the purpose of applying SEO changes to your WordPress site
3.5 Data We Do NOT Collect
- Your browsing history outside the Service
- Your search engine queries or search engine results pages (SERPs)
- Your contacts, social media profiles, or address books
- Precise geolocation data (GPS coordinates)
- Biometric data, health data, or data classified as "sensitive" under GDPR Article 9
- Information from third-party data brokers or advertising networks
4. Legal Basis for Processing (GDPR)
For Users in the European Economic Area (EEA), the United Kingdom, Switzerland, and other jurisdictions that require a lawful basis for Processing Personal Data, we rely on the following:
4.1 Consent (Article 6(1)(a) GDPR)
- When you create an account, you consent to the Processing of your email and name for the purpose of providing the Service.
- When you opt in to receive marketing communications, you consent to receiving emails about product updates, features, and promotions.
- You may withdraw consent at any time by contacting us at support@auditme.dev or by adjusting your preferences in account settings. Withdrawal does not affect the lawfulness of Processing prior to withdrawal.
4.2 Performance of Contract (Article 6(1)(b) GDPR)
- Processing of your submitted URLs, website content, and analysis parameters is necessary to perform the SEO analysis service you requested.
- Processing of your account data is necessary to provide account management, authentication, and Pro subscription features.
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
- Security monitoring, fraud prevention, and abuse detection (including rate limiting and SSRF protection)
- Service improvement through aggregated, anonymized usage analytics
- Compliance with legal obligations and responding to lawful requests from authorities
- Enforcement of our Terms of Service and protection of our legal rights
4.4 Legal Obligation (Article 6(1)(c) GDPR)
- We may Process data when required by applicable law, regulation, legal process, or enforceable governmental request.
5. How We Use Your Information
We use collected information exclusively for the following purposes:
5.1 Service Delivery
- Providing, operating, and maintaining the SEO analysis tools and features of the Service
- Processing URLs and generating SEO audit reports, recommendations, and insights
- Managing your account, authentication, subscriptions, and user preferences
- Delivering email notifications related to account security, service updates, and billing
5.2 Service Improvement
- Analyzing aggregate, anonymized usage patterns to identify trends and improve tool functionality
- Debugging, identifying and fixing errors, and optimizing performance
- Developing new features based on aggregate usage data and User feedback
- Conducting internal research and analytics to enhance User experience
5.3 Security and Compliance
- Detecting, preventing, and responding to fraud, abuse, unauthorized access, and other malicious activity
- Enforcing rate limits, API abuse protections, and Terms of Service
- Complying with applicable laws, regulations, legal processes, or enforceable governmental requests
- Protecting the rights, property, or safety of AuditMe, our Users, or the public
5.4 Communication
- Responding to support inquiries, feedback, and other communications
- Sending service-related notices (security alerts, policy changes, billing confirmations)
- Sending marketing communications only with your explicit opt-in consent; you may unsubscribe at any time
6. Data Storage and Retention
We retain your Personal Data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law.
6.1 Account Data
- Stored in Supabase-hosted PostgreSQL databases located in the European Union
- Encrypted at rest using AES-256 encryption; encrypted in transit using TLS 1.3
- Retained for the duration of your active account plus thirty (30) days after account deletion for recovery purposes
- Permanently deleted after the retention period expires
6.2 Analysis Data
- SEO audit results, recommendations, and reports are stored in your browser's localStorage by default
- We do not have access to your localStorage data unless you explicitly share it or save it to your account
- When saved to your account, analysis data is stored in Supabase and retained for the duration of your account
- You may delete your analysis history at any time via the "Clear History" button in the application
6.3 Server Logs
- Automatically collected server logs (including IP addresses, request paths, timestamps, and User-Agent strings) are retained for a maximum of thirty (30) days
- Logs are automatically rotated and permanently deleted after the retention period
- Aggregated, anonymized log data may be retained indefinitely for service improvement purposes
6.4 Payment Records
- Transaction confirmations and subscription records are retained for seven (7) years to comply with tax and accounting obligations
- We do not retain payment card numbers, CVV codes, or other sensitive payment credentials
7. Cookies and Tracking Technologies
The Service uses Cookies and similar technologies as described below. You may manage Cookie preferences through your browser settings or our Cookie Consent Banner.
7.1 Strictly Necessary Cookies
- Session authentication tokens (sb-*-auth-token): Required for maintaining your authenticated session
- CSRF protection tokens: Required to prevent cross-site request forgery attacks
- Load balancer affinity cookies: Required for routing your requests to the correct server
- These cookies cannot be disabled; the Service will not function without them
7.2 Preference Cookies
- Theme preference (dark/light mode): Stored in localStorage for your convenience
- Sidebar state and UI preferences: Stored in localStorage
- Locale/language preference: Stored as a Cookie to serve content in your preferred language
- These cookies are not required for the Service to function
7.3 Analytics
- We use Plausible Analytics, a privacy-friendly, self-hosted analytics solution
- Plausible does NOT use Cookies, does NOT collect personal data, and does NOT track Users across websites
- Plausible collects only aggregated, anonymized metrics: page views, referral sources, browser type, and country-level geographic data
- We do NOT use Google Analytics, Facebook Pixel, Hotjar, or any other third-party tracking scripts
- You may opt out of analytics collection via our Cookie Consent Banner
7.4 Do Not Track (DNT)
- We respect the Do Not Track (DNT) browser signal. When DNT is enabled, we disable all non-essential data collection, including analytics
8. Third-Party Service Providers
We share data with the following third-party service providers, each of which acts as a Data Processor under applicable data protection law:
8.1 Infrastructure and Hosting
- Vercel Inc. (hosting, edge functions, CDN): Processed data includes your IP address, User-Agent, request paths, and page content. Vercel maintains SOC 2 Type II compliance. Privacy Policy: https://vercel.com/legal/privacy-policy
- Supabase Inc. (authentication, database, real-time subscriptions): Processed data includes your email, name, password hash, and account metadata. Supabase hosts data in EU regions (Frankfurt). Privacy Policy: https://supabase.com/privacy
8.2 AI and Language Model Providers
- Groq Inc.: The submitted URL and analysis prompt are sent to Groq for content analysis. No account information, email, or personal identifiers are transmitted. Data is not used for model training. Privacy Policy: https://groq.com/privacy
- Google LLC (Gemini): The submitted URL and analysis prompt are sent to Google for content analysis. No account information, email, or personal identifiers are transmitted. Data is not used for model training. Privacy Policy: https://policies.google.com/privacy
- Mistral AI: The submitted URL and analysis prompt are sent to Mistral for content analysis. No account information, email, or personal identifiers are transmitted. Data is not used for model training. Privacy Policy: https://mistral.ai/privacy
8.3 Payment Processing
- Payoneer Inc. (payment processing): We do not share payment card details with Payoneer directly. Payoneer processes payments on behalf of the User and provides us with transaction confirmation only. Privacy Policy: https://www.payoneer.com/legal/privacy-policy
8.4 Authentication Providers
- Google LLC (OAuth): If you choose to sign in with Google, Google provides your name, email address, and profile photograph to us via OAuth 2.0. We do not receive your Google password. Privacy Policy: https://policies.google.com/privacy
- GitHub Inc. (OAuth): If you choose to sign in with GitHub, GitHub provides your username, email address, and profile photograph to us via OAuth 2.0. We do not receive your GitHub password. Privacy Policy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
8.5 Email Delivery
- We use Gmail SMTP (Google Workspace) for transactional email delivery (account verification, security notifications). Email content is limited to authentication links and service-related communications. We do not use email marketing services (Mailchimp, SendGrid, etc.).
9. Data Sharing and Disclosure
We do NOT sell, rent, lease, trade, or otherwise commercially distribute your Personal Data to third parties for their marketing purposes.
We may disclose your Personal Data only in the following limited circumstances:
- With your explicit consent: When you instruct us to share data with a third-party service or when you use features that require third-party integration (e.g., WordPress Apply).
- Service providers: As described in Section 8, to the extent necessary to provide and maintain the Service.
- Legal compliance: When required by applicable law, regulation, legal process, or enforceable governmental request. We will notify you unless legally prohibited from doing so.
- Protection of rights: When we believe in good faith that disclosure is necessary to protect the rights, property, or safety of AuditMe, our Users, or the public, including fraud prevention and security incident response.
- Business transfers: In connection with a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your data may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
- Aggregated, anonymized data: We may share aggregated, anonymized data that cannot reasonably be used to identify you. For example, we may publish reports on aggregate SEO trends, tool usage statistics, or industry benchmarks.
10. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- Right of Access (Article 15): You may request a copy of all Personal Data we hold about you, including the purposes of Processing, categories of data, recipients, and retention periods.
- Right to Rectification (Article 16): You may request correction of inaccurate or incomplete Personal Data.
- Right to Erasure / Right to be Forgotten (Article 17): You may request deletion of your Personal Data, subject to our legal obligations to retain certain data.
- Right to Restriction of Processing (Article 18): You may request that we limit how we Process your Personal Data in certain circumstances.
- Right to Data Portability (Article 20): You may request your Personal Data in a structured, commonly used, machine-readable format (e.g., JSON, CSV).
- Right to Object (Article 21): You may object to Processing based on legitimate interests, including direct marketing. We will cease Processing unless we demonstrate compelling legitimate grounds.
- Right to Withdraw Consent (Article 7(3)): Where Processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of Processing prior to withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your country of residence, workplace, or place of the alleged infringement.
- Automated Decision-Making: We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on Users.
To exercise any of these rights, contact us at support@auditme.dev. We will respond to all requests within thirty (30) days. We may request identity verification before processing your request.
11. Your Rights Under CCPA / CPRA
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of Personal Data we have collected, the sources of collection, the business or commercial purpose for collection, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your Personal Data, subject to certain legal exceptions (e.g., data required for legal compliance, security, or fraud prevention).
- Right to Correct: You may request correction of inaccurate Personal Data.
- Right to Opt-Out of Sale or Sharing: We do NOT sell or share (as defined under CCPA/CPRA) your Personal Data. We do not have a "Do Not Sell My Personal Information" link because we do not sell data.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights. You will not receive different pricing, quality of service, or be denied service for exercising your rights.
- Right to Limit Use of Sensitive Personal Information: We do not collect or process sensitive Personal Information (as defined under CPRA) for purposes other than those permitted by law.
To exercise your CCPA/CPRA rights, contact us at support@auditme.dev. We will respond within forty-five (45) days. You may also designate an authorized agent to make a request on your behalf.
12. International Data Transfers
Your data may be processed in countries other than your country of residence. When we transfer Personal Data internationally, we ensure appropriate safeguards are in place:
- European Economic Area (EEA) to United States: Data transfers to Vercel, Supabase, and AI providers in the United States are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, or by the provider's participation in the EU-U.S. Data Privacy Framework.
- Supabase data is hosted in EU regions (Frankfurt, Germany). Account data does not leave the EU unless you use features that require processing by US-based AI providers.
- We maintain Data Processing Agreements (DPAs) with all third-party processors that handle Personal Data originating from the EEA.
- You may request a copy of the applicable transfer mechanisms by contacting us at support@auditme.dev.
13. Data Security
We implement commercially reasonable technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit: All data is transmitted over HTTPS using TLS 1.3 with HSTS enforcement
- Encryption at rest: All stored data is encrypted using AES-256 encryption
- Authentication: Passwords are hashed using bcrypt with per-user salts (managed by Supabase Auth). We never have access to plaintext passwords
- Access controls: Administrative access to production systems is restricted to authorized personnel using multi-factor authentication (MFA)
- Rate limiting: All API endpoints are rate-limited to prevent abuse (10 requests per minute per IP for scan endpoints)
- SSRF protection: All user-submitted URLs are validated against internal IP ranges, metadata endpoints, and known attack vectors before processing
- Content Security Policy (CSP): Strict CSP headers are deployed on all pages to prevent cross-site scripting (XSS) attacks
- Dependency management: We use automated dependency scanning (Dependabot) and perform weekly dependency updates
- Incident response: We maintain an incident response plan and will notify affected Users within seventy-two (72) hours of discovering a data breach affecting their Personal Data
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your Personal Data, we cannot guarantee absolute security.
14. Children's Privacy
The Service is not directed to individuals under the age of sixteen (16) (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect Personal Data from children.
If we become aware that we have collected Personal Data from a child without verification of parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us immediately at support@auditme.dev.
For Users in the EEA, we comply with Article 8 of the GDPR regarding the conditions applicable to child's consent in relation to information society services.
15. Data Breach Notification
In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, as required by Article 33 of the GDPR
- Notify affected Users without undue delay when the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 of the GDPR
- Document the breach, its effects, and the remedial action taken, as required by Article 33(5) of the GDPR
- Take all reasonable steps to mitigate the impact of the breach and prevent recurrence
16. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated via email to registered Users or through a prominent notice on the Service at least thirty (30) days before they take effect.
The "Last Updated" date at the top of this page indicates when this Policy was last revised. Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated Policy.
We encourage you to review this Policy periodically. If you do not agree to the modified Policy, you must stop using the Service and delete your account.
17. Severability
If any provision of this Policy is found to be unlawful, void, or unenforceable by a court of competent jurisdiction, that provision shall be deemed severable and shall not affect the validity and enforceability of the remaining provisions.
18. Contact Information
For questions, concerns, data access requests, or complaints regarding this Privacy Policy or our data practices, contact us at:
- Data Controller: Eduard Tymchenko
- Email: support@auditme.dev
- Telegram: @Edzzy91 (https://t.me/Edzzy91)
- Website: https://www.auditme.dev
