Legal

Privacy Policy

Effective:

1. Overview

This policy explains what AutoAudit AI (“we”, “us”) does with the information you give us when you submit a URL for an audit, sign in, or contact us. We try to be specific rather than vague wherever possible, and we would rather say “we don’t collect that” than gesture at possibilities.

We are a small service. We do not run advertising, sell your data, or build advertising profiles. The data we hold exists to run the audit you asked for and to let you come back to it.

Local consumer-protection and privacy laws may give you additional rights regardless of what this page says. If you believe a right in your jurisdiction applies to you, email us at the address in Section 11 and we will work with you in good faith.

2. What we collect

We collect three categories of data:

  1. URLs and audit inputs. The website URL you submit, plus any options you set (crawl depth, pages to skip). We fetch the pages of that URL as part of the audit.
  2. Account information, if you create an account. Email address, hashed password (we never store passwords in plain text), and basic profile fields such as display name. If you sign in with a third-party provider (for example, a social login), we receive the verified identifier that provider returns.
  3. Basic server logs. IP address, user-agent string, approximate timestamp, and the route requested. We keep these as long as needed to operate the service and investigate abuse; they are not used to build profiles of you.

We do not collect: precise geolocation, device fingerprinting signals, advertising IDs, or information from third-party trackers on the sites you audit. We do not knowingly collect data from sites we audit beyond what the audit itself requires (the contents of each audited page are processed to produce the report and are not used to build a separate database of scanned sites).

3. Why we collect it

We use the data above for three reasons, and only these three:

  • To run the audit. Fetching your URL, scoring it, identifying technical issues (broken links, redirect chains, missing meta tags, performance and accessibility findings), and producing the report.
  • To generate fix suggestions. Our system drafts concrete remediation snippets (redirect maps, meta edits, content rewrites). All suggestions require your explicit approval before they are stored against your account.
  • To deliver the report, if you ask us to. If you request an emailed copy, we send the report to the address you provided. You can unsubscribe from these emails at any time using the link in every message.

We do not use your audit data to train any general-purpose AI model. We may use it, in aggregate and irreversibly de-identified form, to improve the audit scoring rules themselves (for example, learning that a particular check produces too many false positives). We will tell you here if that ever changes.

4. How long we keep it

Retention is the part of privacy most policies dodge, so here is ours in plain terms:

  • Audit results and submitted URLs: 30 days from the audit run. After that, audit data is automatically deleted from our production database. We may keep shorter, irreversibly aggregated statistics (for example, “audits-per-day”) indefinitely.
  • Account information: While your account is active. When you delete your account, account data is removed within 7 days, except where we must keep records to comply with a legal obligation (such as tax records for paid plans, if and when they exist).
  • Server logs: 90 days, in line with common practice.
  • Backups: Encrypted nightly backups of the database are retained for up to 30 days, after which they are overwritten. Backups are not restored on demand; they exist for disaster recovery.

5. Who we share it with

We share data only with the processors required to run the service. As of the effective date above, those processors are:

  • Render — application hosting and database. Your audit data lives on servers operated by Render. (Render privacy policy)
  • Transactional email delivery. When you opt to receive reports by email, we send them through our hosting platform’s authenticated outbound email service. The service receives only the address you provided, the sender identity, and the report contents. We will name the underlying email vendor in this section once that decision is final.

[Other processors will be listed here as they are added.]

We do not sell your data. We do not share it with advertising networks. We will disclose information only when (a) you ask us to, (b) required by a valid legal process, or (c) necessary to investigate suspected abuse of the service.

6. Your rights

You have four rights that operate across every section above. To exercise any of them, email us at Section 11.

  • Access. Ask what we hold about you and we will provide a copy.
  • Deletion. Ask us to delete your account and your audit data. We will confirm when the deletion has completed.
  • Export. Ask for a machine-readable copy (JSON) of your audit history at any time during the retention window.
  • Opt out of email. Use the unsubscribe link in any report email, or email us directly, to stop receiving report emails.

Other rights may apply under local law (for example, the right to correct inaccurate data, the right to lodge a complaint with a data-protection authority). We will respect any right a competent authority confirms applies to you, regardless of whether it is listed here.

7. Security

We take reasonable steps to protect your data:

  • All traffic is served over HTTPS.
  • Account passwords are hashed (we cannot read your password).
  • Access to production data is limited to a small set of operators with audit trails.
  • The database is encrypted at rest by our hosting provider.
  • Backups are encrypted.

No system is perfectly secure. If we ever discover a breach that affects your data, we will tell you at the email address on your account and describe what was affected.

8. Children

The service is not directed to children under the age where consent is required in your jurisdiction (commonly 13 or 16). We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

9. International transfers

Our hosting is in the United States. If you submit data from outside the United States, you understand that the data will be transferred to and processed in the United States. Where required (for example, for users in the European Economic Area or United Kingdom), we rely on standard contractual clauses or equivalent safeguards for these transfers.

10. Changes to this policy

When we make a material change we will update the effective date at the top of this page and, if the change affects existing customers, notify you by email or by a prominent notice on the service before the change takes effect. Non-material changes (typos, format improvements, clarifications) do not require notice.

11. Contact

For any privacy question — access, deletion, export, complaints, anything else — contact:

Email: hello@autoaudit-ai.com

Looking for the user agreement?Read the Terms of Service