Privacy policy
Last updated: 5 August 2026 · Applies to PageSpeedAudit (this website and its APIs)
1. Who is responsible
The controller for all processing described here is the operator named in our imprint. For any privacy question or request, email [email protected] — this is the fastest route and reaches the operator directly.
2. Visiting the site
Server logs. Like almost every website, our servers record technical logs of each request — IP address, requested path, browser identifier (user agent), and timestamp. We use them to keep the site secure, diagnose faults, and investigate abuse. Log files are deleted after 14 days.
Content delivery. The site is served through Cloudflare, which terminates TLS, filters malicious traffic, and caches static assets. Cloudflare necessarily sees the IP address of every request; it acts as our processor.
Visit counting without tracking. We do not use Google Analytics or any third-party analytics. To understand which pages are read and where checkouts start, we record page views with a pseudonym computed from a one-way hash whose key rotates every day. The raw IP address is never stored for this purpose, the same visitor produces a different pseudonym each day, and yesterday's pseudonyms cannot be linked to today's — so no browsing profile of you can be built.
3. Using the free tools
When you run one of our free tools (for example a URL check), we log the tool name, the URL you submitted, your IP address, your browser identifier, coarse information derived from the IP on our own server (country, city, network) — and, if you are signed in at the time, the link to your account, so support can see your tool history when you write in. We use this to prevent abuse of the free tools and to see which tools are worth improving. The IP address, browser identifier, network identifiers, and account link are erased from these records after 400 days; what remains is aggregate statistics — which tool ran on which URL, when, and coarse location and device type.
Some tools can send you results by email (for example CrUX Watch monitoring). Those subscriptions are covered in the email section below and always use double opt-in.
4. Buying an audit & your account
Payment. Checkout runs entirely on Stripe. Your card or payment details are entered on Stripe's pages and never touch our servers. From Stripe we receive and store: your email address, what you bought, the amount and currency, the payment status, any promotion code used, and Stripe's technical identifiers for the transaction. Stripe also processes refunds and disputes on our behalf.
Your account. To deliver your report we create an account keyed to your email address. Passwords are stored only as salted one-way hashes — we cannot read them. Sign-in is also possible via emailed magic links. Your reports remain available in your account.
Invoicing and tax. Purchase records are business records; tax law requires us to retain them for up to 10 years. This retention continues even if you delete your account.
5. How your audit is produced
An audit analyzes the publicly accessible URL you submit. To produce it we:
- request lab and field performance data for the URL from Google (PageSpeed Insights and the Chrome UX Report), and
- process the URL's page data with Anthropic's Claude models, which perform the expert analysis behind your report.
What these providers receive is data about the submitted website — the URL and its public page content — not data about you as a person beyond what the URL itself reveals. You may only submit URLs you own or are authorized to have audited. The finished report is stored on our servers and served from your account.
6. Email
All email is sent through Mailgun (a Sinch company). We use Mailgun's EU region, so sending is processed on EU infrastructure.
Transactional email — receipts, report-ready notifications, sign-in links, account and security messages — is sent because it is part of the service; it cannot be opted out of while you use the service.
Marketing email is strictly double opt-in. Newsletters, email courses, and update subscriptions start only after you confirm via a link we send you. Every marketing email contains a one-click unsubscribe link that works immediately. After a purchase we also send a short onboarding series that helps you use what you bought; it has the same one-click opt-out.
Proof of consent. When you sign up for marketing email (and when you confirm), we record the timestamp, the page the signup came from, your IP address, browser identifier, and the approximate location derived from the IP. We keep this so we can prove your consent existed — regulators and mailbox providers require it. Location is derived on our own server from a local database; your IP is not sent to any geolocation service. These consent records are visible to no one in day-to-day operation and are kept for as long as the subscription exists and afterwards for as long as legally necessary to evidence the consent. Unsubscribing therefore keeps a minimal record — that you were subscribed, when, and when you left — rather than erasing all trace of the subscription, precisely so your opt-out itself is provable and permanent.
Engagement measurement. Emails we send include standard delivery, open, and click measurement (a tracking pixel and redirect links, processed by Mailgun and stored by us per message). We use this to find and cut email nobody wants. These engagement events are deleted after 400 days. Spam complaints and permanent delivery failures additionally place your address on our internal do-not-send list — that list is kept, because its purpose is to make sure we never email you again.
7. Contacting us
When you use the contact form or email us, we process your message, your email address, and the technical data submitted with it in order to answer you. Incoming messages are screened for spam, and an AI model (Anthropic's Claude) helps categorize and prioritize them; the decision how to answer you is made by a human. Correspondence is kept as long as needed to handle your request and as required for business correspondence under applicable commercial law.
8. Affiliate & reseller programs
Applying. If you apply to the affiliate or reseller program we process your email address, the website you name, and your application details, plus the same proof-of-consent records as for email signups. For reseller applications, an AI model reviews the public website you named to check that it belongs to a genuine agency — see automated decisions.
If you arrive through an affiliate link. A referral cookie (psa_ref,
30 days) may credit the referring partner if you later buy. In the EU/EEA, UK, and Switzerland this
cookie is set only after you agree on the referral page — declining just means the
partner earns no commission; nothing else changes for you. Affiliates can also use direct checkout
links that set no cookie at all and carry the referral inside the single checkout
session instead. Click records include your IP address, the referring page, and coarse
location/device information for fraud prevention; the IP, location details, and referrer are
anonymized after 400 days.
Payouts. Affiliate commissions are paid via Stripe Connect; Stripe collects the payout account details directly and we store only the Stripe account reference and the commission ledger. Commission and payout records are business records retained like purchase records.
10. Legal bases (GDPR)
- Contract (Art. 6(1)(b)) — accounts, payments, producing and delivering your audit, transactional email, affiliate/reseller program administration.
- Legal obligation (Art. 6(1)(c)) — retention of purchase, invoice, commission, and payout records under tax and commercial law.
- Legitimate interests (Art. 6(1)(f)) — security and abuse prevention (server logs, tool logs, fraud checks), privacy-preserving visit counting, the do-not-send suppression list, defending legal claims (consent records). You may object at any time — see your rights.
- Consent (Art. 6(1)(a)) — marketing email including its engagement measurement, and the affiliate referral cookie where consent law applies. Consent can be withdrawn at any time with effect for the future (every email's unsubscribe link; [email protected] for everything else).
11. Service providers we use
These companies process personal data on our behalf under data processing agreements:
- Stripe — payments, refunds, disputes, and affiliate payouts (Stripe Connect). Stripe also acts as an independent controller for its own payment-processing obligations.
- Cloudflare — content delivery, TLS, and traffic filtering in front of the site.
- Sinch Mailgun (EU region) — sending email and reporting delivery/open/click/complaint events back to us.
- Anthropic — AI analysis: producing audit reports from submitted page data, categorizing contact messages, and checking reseller applicants' public websites.
- Google — PageSpeed Insights and Chrome UX Report data for the URL being audited.
- Hosting — the application and its database run on dedicated infrastructure under our control; access is restricted to the operator.
We never sell personal data, and we share it with no one beyond this list except where the law requires.
12. International transfers
Some providers above are US companies, so personal data can be transferred to the United States. Where a provider is certified under the EU–US Data Privacy Framework (and its UK and Swiss extensions), we rely on that adequacy decision; in all other cases transfers are covered by the European Commission's Standard Contractual Clauses in the provider's data processing agreement, with supplementary measures where appropriate. Email sending is pinned to Mailgun's EU region, and IP geolocation for consent records happens locally on our own server — your IP is not sent anywhere for that purpose.
13. How long we keep data
| Data | Kept for |
|---|---|
| Server logs (IP, path, browser) | 14 days |
| Visit counting | No raw identifiers stored; daily-rotating pseudonyms are unlinkable after each day |
| Free-tool logs — IP, browser, network identifiers & account link | Erased after 400 days (aggregate statistics remain) |
| Email engagement events (delivered/opened/clicked) | Deleted after 400 days |
| Affiliate click IP, location details & referrer | Anonymized after 400 days |
| Account, reports | Until you delete your account or ask us to |
| Purchase, invoice, commission & payout records | Up to 10 years (tax and commercial law) |
| Marketing consent & unsubscribe records | Life of the subscription, then as long as legally necessary to evidence consent |
| Do-not-send suppression list | Kept permanently — it exists to make sure we never email you again |
| Contact correspondence | As long as needed to handle the request, plus statutory business-correspondence retention |
14. Automated decisions
Two processes here run without a human in the first step. Both come with a human on request:
- Reseller applications. An AI model reviews the public website you named to check it belongs to a genuine agency or consultancy. Approval is only granted automatically when the check is highly confident; uncertain cases go to a human before any decision. If your application is declined, you can reply to the decision email and a human will review it.
- Refunds and chargebacks. A fully refunded or disputed purchase automatically blocks the associated account, because access to the paid report ends when the payment is returned. If you think this hit you in error, email [email protected] and a human will look at it.
Under Art. 22 GDPR you have the right not to be subject to a solely automated decision with legal or similarly significant effect, and to obtain human intervention, express your point of view, and contest the decision — both routes above exist for exactly that.
15. Your rights
Wherever you are, you can exercise these rights by emailing [email protected]. We answer within one month (GDPR) or the deadline your local law sets, and never charge for a first request:
- Access — a copy of the personal data we hold about you;
- Rectification — correction of inaccurate data;
- Erasure — deletion, except where retention is legally required (for example invoices, and the minimal record that keeps your unsubscribe permanent);
- Restriction and objection — including an absolute right to object to direct marketing, honored immediately;
- Portability — the data you gave us, in a machine-readable format;
- Withdraw consent — at any time, with effect for the future, as easily as it was given.
We will verify requests using the email address on file. You also have the right to complain to a data protection supervisory authority — either where you live or the authority responsible for us (see the EU list of authorities).
16. California & other US states
For residents of California and other US states with privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others): we do not sell personal information and do not share it for cross-context behavioral advertising — there is nothing to opt out of, and a Global Privacy Control signal changes nothing because the state it requests is already our default. We use no "dark patterns": subscribing takes a confirmed opt-in, unsubscribing takes one click. You have the rights to know, access, correct, and delete personal information and to not be discriminated against for exercising them — use [email protected], and an authorized agent may submit requests on your behalf. The categories we collect are exactly those in sections 2–8: identifiers (email, IP), commercial information (purchases), and internet activity (pages viewed, pseudonymized); we collect no sensitive personal information as defined by the CPRA.
17. Security
- All traffic is encrypted in transit: plain-HTTP requests are redirected to HTTPS, and HSTS instructs browsers to use only HTTPS for a full year afterwards.
- Session cookies use the strictest browser protections (
__Host-prefix: secure-only, single-origin). - Passwords are stored only as salted one-way hashes and API keys only as one-way hashes; neither we nor anyone who copied the database can read them back.
- Card data never reaches our systems (processed by Stripe, a PCI DSS Level 1 provider).
- Access to production data is restricted to the operator; consent-record details are excluded from day-to-day admin screens by design.
18. Children
This is a business service and is not directed at children. We do not knowingly process data of anyone under 16; if you believe a child has given us personal data, email us and we will delete it.
19. Changes to this policy
When we change what we collect or how, we update this page and its date first — the policy describes the system as it actually runs. Material changes to how already-collected data is used would be announced to affected users by email before they take effect.