Privacy Policy
Last updated: June 2026
We don't sell your data. We don't track you across the web. We collect the minimum needed to run the service, and your analysis history stays in your browser unless you explicitly share it.
If you want the legal details, keep reading. If you just wanted to know the bottom line, there it is.
Here's everything we gather, broken down by category:
- Account info: Name, email, password hash (handled by Supabase, we never see your actual password).
- Usage data: Which tools you use, how often, what errors occur. This helps us fix bugs and prioritize features.
- Analysis results: The SEO data you generate β keywords, URLs, scores, recommendations. This lives in your browser's localStorage by default. We only see it if you click "Share" or save it to your account.
- Technical basics: IP address, browser type, rough location (city-level). Standard server logs. We use this for security and abuse prevention.
We don't collect: your browsing history outside our site, your search queries on Google, your competitors' data, or anything from third-party trackers.
- Run the service: You can't get an SEO audit without us processing your URL.
- Keep things working: Error logs, performance metrics, abuse detection.
- Improve the product: We look at aggregate usage patterns β "80% of users run the Schema Validator" tells us to invest there.
- Communicate: Security updates, major feature launches, billing receipts. No marketing spam unless you opt in.
- Legal compliance: If a court orders us to hand over data, we comply. We'll notify you unless legally prohibited.
Analysis history: Stored locally in your browser (localStorage). We can't see it. You can clear it anytime from your browser settings or our "Clear History" button.
Account data: Hosted on Supabase (PostgreSQL) in the EU. Encrypted at rest, TLS in transit. We don't run our own database servers.
Retention: Account data stays until you delete your account. Analysis history in localStorage stays until you clear it. Server logs rotate every 30 days.
You can:
- Download everything we have on you (Settings β Export Data)
- Delete your account and all associated data (Settings β Delete Account)
- Object to processing β email us and we'll stop
- Request a copy in a portable format
We respond to all requests within 30 days. Usually faster.
We use exactly three types of cookies:
- Essential: Session auth, CSRF protection. The site breaks without these.
- Preferences: Theme choice (dark/light), sidebar state. Purely for your convenience.
- Analytics: We use a self-hosted Plausible instance. No Google Analytics. No Facebook pixel. No cross-site tracking.
You can reject analytics cookies in the cookie banner. The site works fine without them.
We share data with exactly these services:
- Supabase: Auth + database. EU-hosted. DPA in place.
- Vercel: Hosting + edge functions. Logs include IPs.
- AI providers (Groq, Google Gemini, Mistral): Only the URL and analysis prompt you submit. No account info. We don't train on your data.
- Plausible: Privacy-friendly analytics. EU-hosted. No cookies by default.
We don't sell data to data brokers, ad networks, or "partners." If that ever changes, you'll know before it happens.
- All traffic over HTTPS (HSTS enabled)
- Passwords hashed with bcrypt (Supabase handles this)
- Rate limiting on all API endpoints (5 requests/minute for scans)
- SSRF protection β we block internal IPs and metadata endpoints
- Content Security Policy headers on every page
- Dependabot alerts + weekly dependency updates
No system is 100% secure. If we discover a breach affecting your data, we'll notify you within 72 hours.
Questions, concerns, or data requests:
- Email: ffedzzy@gmail.com
- Telegram: @Edzzy91
