Privacy Policy
Last updated: March 22, 2026
1. Information We Collect
Account data: Email address and password (hashed) when you create an account.
Scan data: URLs you scan, audit results, scores, screenshots, and issue reports. This data is associated with your account.
Pulse RUM data: When you install the Pulse SDK on your site, we collect anonymized metrics from your visitors: Core Web Vitals (LCP, CLS, INP, FCP, TTFB), click positions, page paths, and JavaScript errors. No personal data, cookies, or IP addresses are stored.
2. How We Use Your Data
- To provide scan results and monitoring dashboards
- To detect score regressions and send alerts
- To generate reports and trend analysis
- To render click heatmaps from Pulse data
- To improve the Service (aggregated, anonymized usage patterns)
3. Data Storage
All data is stored in Supabase (PostgreSQL) with row-level security. Data is encrypted in transit (TLS) and at rest. Servers are hosted in the United States.
4. Data Sharing
We do not sell, rent, or share your personal data with third parties. Scan results are private to your account unless you explicitly share them via a share link.
5. Cookies
We use essential cookies for authentication (Supabase auth tokens). We do not use tracking cookies, advertising cookies, or third-party analytics on the dashboard.
6. Your Rights
You have the right to:
- Access your data via the dashboard and API
- Export your scan results (JSON, Markdown, CSV, PDF)
- Delete your account and all associated data from Settings
- Withdraw consent for Pulse data collection by removing the SDK
7. Pulse SDK and Your Visitors
If you install Pulse on your website, you are the data controller for the metrics collected from your visitors. We act as a data processor. The Pulse SDK:
- Does not collect personal information
- Does not use cookies
- Does not track users across sites
- Is 3.7KB gzipped — minimal performance impact
We recommend you disclose Pulse data collection in your own privacy policy.
8. Data Retention
Scan results are retained for as long as your account is active. When you delete your account, all associated data is permanently removed within 30 days. Pulse RUM data is retained for 90 days.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or dashboard notification.
10. Contact
Questions about privacy? Contact us at nastasadanandrei@gmail.com.