DATA PROCESSING

Data processing agreement.

The substance of the processing relationship, written plainly. The executable document does not exist yet, and this page says so rather than implying otherwise.

No signable DPA exists today. Not built yet This page describes the processing accurately so you can assess it, but there is no counter-signed agreement to put in front of a procurement team. If your process requires one, that is a genuine blocker: see the enterprise page, which says the same thing.

Roles

For the site data you ask us to crawl, you are the controller and we are the processor. For your account and billing records, we are the controller.

What is processed

  • Public page content from the sites you submit: the text, markup and metadata a crawler retrieves.
  • Derived findings: the checks, their outcomes and the evidence supporting them.
  • Account data: the address you signed up with and your billing records.
  • Abuse-prevention metadata: the requesting address, stored only as a truncated keyed hash.

The scanner reads public HTML. It does not submit forms, does not authenticate, and does not reach anything a signed-out visitor could not. It is not designed to process personal data, though public pages sometimes contain it.

Sub-processors

ProcessorPurposeWhat it sees
Amazon Web ServicesHosting and object storageCrawl artifacts and uploaded files
PolarPayments and subscriptionsBilling identity and transaction records
ResendTransactional emailRecipient addresses and message contents
CloudflareVerification challenge and edge deliveryRequest metadata for abuse prevention
A large-language-model providerModel-judged checksContent from the pages you scan

The last row is the one that matters most for a data-classification review: running model-judged checks sends page content outside our infrastructure. We do not train models on it and contract for the same, but it does leave.

Retention and deletion

  • Free scan results and share links expire after 30 days.
  • Account crawl data and findings are kept while the account is open and deleted with it.
  • Repository or CMS access is limited to the scopes you grant; revoking access removes the associated data.

Security measures

TLS in transit, hashed verification tokens, keyed and truncated requester hashes, scoped access, and audit logging written out of band so the trail does not depend on the request succeeding. The security page lists the controls and, more usefully, what is absent: no SOC 2, no ISO 27001, no penetration-test report, no uptime guarantee.

Your rights

Export and deletion are available from the account. Statutory rights of access, correction, portability and erasure apply where the law grants them, and those are the mechanisms.

Privacy Security