Skip to content

Privacy

This describes what the software does, not what a template says it might. Where a sentence makes a claim about storage or sharing, the code that does it is named in the repository and checked by a test.

Not in force yet

This document is complete except for the name of the operating entity and the governing jurisdiction, which are not part of the software and have to be supplied by whoever operates this service. Until they are, this page is not published in the sitemap, is not indexed, and does not bind anyone. Everything below describes what the system actually does today.

The free check stores no report

You can run a check without an account. We fetch the address you give us, apply the rules, and return the result to your browser. The finding, the page and its bytes are not written to any database — the result exists for the length of that one request. One thing is written: a one-way fingerprint of your address, an HMAC rather than the address itself, in a single row that counts your checks against the per-visitor hourly limit. That row holds a count and a clock, every copy of this site shares it so the published limit is the real one, and it is deleted when your hour closes.

What we store when you have an account

Your email address and your chosen language. The domains you add and whether they are verified. Each audit you request, including the address you asked us to audit and when it ran. The pages we fetched, the findings we produced, and the evidence behind them — which includes the served HTML, the rendered DOM and the response headers of the site you asked us to crawl. Any share links you create, the ledger of credits bought, spent and refunded, and any finding you contest along with what you wrote.

Why we keep the bytes

Because a finding without the material it rests on is an assertion. Each stored artefact is addressed by a hash of its own content and can be downloaded from your report, so any claim we make can be traced back to the exact bytes it came from. That is the product; it is also the largest thing we hold about you, and it is deleted with the rest when you delete your account.

Sites that are not yours

When you ask us to audit an address, we make requests to that site. We identify ourselves in every request with a published user-agent token, we read and obey robots.txt before fetching anything, and we honour any crawl delay it declares. A site owner can have their domain blocked permanently by writing to us. We do not audit private or internal addresses, and we refuse a redirect that leads to one.

Cookies and tracking

One cookie, set only when you sign in, holding a signed session identifier and nothing else. No analytics, no advertising, no third-party trackers, no fingerprinting, no cross-site anything. There is no cookie banner because there is nothing to consent to.

Who else receives it

Only the processors below, each for the one job named. A processor that is not configured on this deployment receives nothing at all, and the list says which those are.

How long we keep it

Until you delete it. There is no automatic expiry, because a report you paid for should still be there when you come back. You can delete everything from your account at any time and it is removed immediately and permanently, including the stored bytes. The one exception is the record of payments, which we keep for as long as tax and accounting law requires — that record contains the amount, the date and the payment reference, and no audit data.

Your rights

You can export everything we hold about your account as a single file, and you can delete all of it, both from your account settings and without asking us. You can also correct your details, object to processing, or complain to your data protection authority. If you would rather we did any of it for you, write to privacy@seomasterize.com and we will answer within one business day.

How it is protected

Every customer read is checked against the signed-in account before a row is fetched, and row-level security in the database refuses cross-tenant reads independently of that. Findings, pages and credits can only be written by the server, never by a browser — a client that could write a finding could fabricate evidence, which would make the product meaningless. Stored artefacts live in a private bucket and are served only to the account that owns them, over a URL addressed by content hash.

Children

This is a tool for people who operate websites. It is not directed at children and we do not knowingly hold data about them.

Changes

The date at the top moves when this document changes in substance. If a change affects what we do with data we already hold, we will say so by email before it takes effect.

Processors

Cloudflare
Serves this site and runs the application
Supabase
Stores your account, audits and evidence
Stripe
Takes payment; receives your email and the amount, never your card details from usnot configured on this deployment — receives nothing
Resend
Sends sign-in links and the copy of anything you contestnot configured on this deployment — receives nothing
the configured model provider
Writes the explanation on a finding the rules have already decidednot configured on this deployment — receives nothing