Privacy Policy
Last updated August 26, 2026.
1. Introduction
This Privacy Policy explains how PageInspection ("PageInspection," "we," "our," or "us") collects, uses, stores, and protects information when you visit pageinspection.com (the "Site"), use the application at app.pageinspection.com, or use our website auditing and crawling services (collectively, the "Services").
PageInspection is a technical audit tool. You give us a URL or a domain, our crawler requests the pages, and we run automated checks covering classic SEO, answer engine optimization (AEO), and generative engine optimization (GEO). We return findings, metrics, and suggested fixes.
Two things about our design are worth stating up front, because they shape everything below:
We do not retain copies of the pages we crawl. Our crawler fetches a page, evaluates it in memory, records the findings and metrics, and discards the page. We do not keep HTML snapshots, page archives, or screenshots of the pages you audit.
Full-site crawls require proof that you control the domain. Before we will crawl a site, you must verify ownership by publishing a verification tag we generate for you. This is described in Section 4.
By using the Services, you acknowledge that you have read and understood this Privacy Policy. Your use of the Services is also governed by our Terms of Service.
2. Information We Collect
2a. Anonymous Use Without an Account
You can run a limited number of single-page audits from our home page without creating an account. For these audits we collect:
- The URL you submit
- A cryptographic hash of your IP address, used solely to enforce the rate limit on free searches
- Basic request metadata such as timestamp and user agent
We do not store your raw IP address for anonymous searches. We store only an irreversible hash of it, which cannot be used to recover the original address. Audit results generated in this mode are transient: they exist to render your preview and are not retained in a durable account history.
2b. Account Information
When you create an account, we collect:
- Name
- Email address
- A hashed password, or an identifier from a third-party sign-in provider if you register that way
- Optional profile details you choose to supply, such as company or website name
- Billing and contact details, where you arrange a paid allowance with us
2c. Domain Verification Data
To enable full-site crawls, we generate a unique verification token for each domain you wish to audit and record:
- The domain or hostname you are claiming
- The verification token we issued
- The verification method you used and the result of each verification attempt
- Timestamps of issuance, successful verification, re-verification, and revocation
- What our request to the checked page returned, limited to what is needed to confirm the token matches and to show you why a check did not pass
We may re-check verification at any time. If the tag is removed, the domain fails the check and crawling for it stops.
2d. Audit and Crawl Data
When you run an audit or crawl, we collect and retain:
- The URLs requested, the HTTP status and response headers returned, response timings, and redirect chains
- The internal link graph of the site, including which pages link to which
- The results of each of our automated checks: pass, fail, or warning, with the evidence needed to explain the finding
- Technical metrics and extracted technical elements, such as page titles, meta descriptions, heading structure, canonical tags, hreflang declarations, structured data markup, image alt attributes, robots directives, sitemap and llms.txt contents, and similar
- Performance metrics, including Core Web Vitals data retrieved from Google PageSpeed Insights
- The fix prompts and briefs generated from your findings
- Crawl configuration and history, including depth, concurrency, page counts, and timestamps
Important limitation on scope. We record findings and the specific technical elements a check evaluates. We do not retain the full body content of your pages. However, some technical elements we extract can themselves contain personal data if you have placed it there: an author byline in a meta tag, a person's name in a page title, an email address in structured data markup, or a name in an image alt attribute. Section 5 explains how we treat that.
2e. Usage and Technical Data
For all users, we automatically collect:
- Pages and features used within the Site and application, and actions taken
- IP address (for authenticated sessions), browser type and version, device and operating system identifiers, and language preferences
- Session timestamps and duration
- Referring URLs
- Error logs, stack traces, and diagnostic data
2f. Communications
If you contact us, request a larger allowance, or respond to us by email, we retain the correspondence and any information in it.
2g. Cookies and Similar Technologies
We use the following categories:
Strictly necessary. Required for the Site and application to function: authentication, session management, security, and rate limiting. These cannot be disabled.
Analytics and performance. Help us understand which features are used and where the product fails. You may decline these.
We do not use advertising or cross-site tracking cookies, and we do not permit third parties to use our Site to build advertising profiles.
You can manage non-essential cookies through your browser settings or any cookie control we provide. Disabling strictly necessary cookies will prevent you from signing in.
3. How We Use Information
We process information to:
- Operate the Services: run audits and crawls, evaluate checks, generate reports, produce fix prompts, and maintain your crawl history
- Verify that you control a domain before crawling it
- Enforce free-tier allowances and rate limits, and prevent circumvention
- Authenticate you and secure your account
- Retrieve performance data for the URLs you audit from third-party performance APIs
- Provide support, respond to your inquiries, and arrange larger allowances
- Send transactional messages: account confirmation, password reset, security notices, crawl completion or failure notifications
- Send product updates and marketing where you have opted in or where we have a legitimate interest; you can opt out at any time
- Monitor, debug, and improve the Services, and develop new checks, using aggregated and de-identified data
- Detect and prevent abuse of the crawler, fraud, and security incidents
- Comply with legal obligations and enforce our Terms of Service
We do not sell or rent personal data. We do not use crawl data for advertising.
4. Domain Ownership Verification
Full-site crawling is gated behind proof of control. The process works as follows:
- You tell us the domain you want to audit.
- We generate a verification token unique to your account and that domain.
- You publish that token on the domain, currently as a meta tag in the head of its home page.
- Our system fetches that page and confirms the tag matches.
- Only after a successful match will we crawl the site.
We treat this as a security and abuse-prevention control, not a formality. It exists so that our crawler cannot be pointed at a site by someone with no relationship to it, and so that a site owner retains a way to stop us: remove the tag and the domain will not pass a further check, and write to us and we will revoke the verification held against it.
Verification does not grant us any right to your site beyond running the audits you request. We may re-check verification at any time, including when a crawl is initiated. If the tag is missing or no longer matches, we treat the domain as unverified and decline to crawl it.
Single-page audits of a URL do not require verification, because they fetch one page in the same manner as any ordinary visitor or as a search engine crawler, following any applicable robots directives. You remain responsible for using that feature lawfully, as set out in our Terms of Service.
5. Personal Data Appearing in Audited Pages
Websites contain information about people. A team page lists staff. A blog post carries an author name. Structured data markup may include a contact email.
Our position on this is:
- We do not seek out, isolate, index, or enrich personal data found on the pages we audit, and we do not build any dataset, contact list, or profile from it.
- We retain only the technical elements a check needs to explain its finding. Where such an element happens to contain personal data because it is published on your page, we hold it incidentally and only in that context.
- We do not retain page bodies, so the great majority of any personal data on an audited page is never stored by us at all.
- We do not attempt to crawl content behind authentication. If a page is not publicly reachable, we do not audit it.
Where the data in question is published on a site you have verified, you are the controller of that data and we act as a processor, handling it only to deliver your audit. You are responsible for the lawfulness of what you publish and for responding to requests from the individuals concerned.
Where you run a single-page audit of a site you do not control, you are responsible for ensuring that doing so is lawful in your circumstances.
If you believe personal data about you is being held by us in connection with an audit, contact us at pageinspections@gmail.com and we will investigate and, where appropriate, delete it.
6. How We Share Information
We do not sell, rent, or trade personal data. We share it only as follows.
6a. Service Providers
We rely on third parties to operate the Services. Each receives only what it needs and is bound by contractual confidentiality and data protection obligations. Categories include:
- Cloud hosting, compute, storage, and database providers
- Google PageSpeed Insights, which receives the URLs you audit in order to return performance and Core Web Vitals data
- Transactional email delivery
- Error monitoring, logging, and application performance tooling
- Product analytics
- Payment processing, where you arrange a paid allowance
- Customer support tooling
6b. Legal Requirements
We may disclose information where required by applicable law, court order, subpoena, or regulatory demand, or where we believe in good faith that disclosure is necessary to protect our rights, our users, or the public, or to investigate abuse of the crawler.
6c. Business Transfers
If PageInspection is involved in a merger, acquisition, reorganization, or sale of assets, information may transfer to the successor entity. We will give reasonable notice before your personal data becomes subject to a materially different privacy policy.
6d. With Your Consent
We share information with third parties where you have explicitly asked us to or agreed to it.
7. Artificial Intelligence and Machine Learning
PageInspection generates fix prompts and briefs from your audit findings. These are assembled from the findings themselves (the failing check, the affected URLs, the evidence, and acceptance criteria) and are delivered to you as plain text for you to use with whatever tool you choose.
Our commitments:
- We do not use your audit data, crawl results, or the technical content extracted from your pages to train, fine-tune, or improve generalized or non-personalized AI or machine learning models.
- We do not transfer your audit or crawl data to any third party for the purpose of training their models.
- Where a feature sends your data to a third-party AI provider to generate output for you, we will disclose that, and we will use providers under terms that prohibit retention beyond serving the request and prohibit training on the content.
8. Legal Basis for Processing (GDPR and UK GDPR)
Where the GDPR or UK GDPR applies to you, we rely on the following bases:
- Contractual necessity. Creating and maintaining your account, running the audits you request, verifying domains, enforcing allowances, and providing support.
- Legitimate interests. Securing the Services, preventing abuse of the crawler, debugging, improving the product, and communicating with existing users about the product. We balance these against your rights.
- Legal obligation. Where processing is required by law, including tax, accounting, and data protection obligations.
- Consent. Non-essential cookies and analytics, and marketing to people who are not existing users. You may withdraw consent at any time, without affecting processing already carried out.
9. Data Retention
We keep information only as long as we need it:
- Anonymous free-search data: hashed IP records are retained only as long as needed to enforce the rate-limit window. Results are transient and are not stored in a durable history.
- Account data: retained while your account is active. Following deletion, we retain minimal records for up to 2 years where needed for legal, tax, security, or dispute purposes.
- Domain verification records: retained while the domain remains verified on your account, and for a limited period afterward as an audit trail of who was authorized to crawl what. Deleted with your account.
- Audit and crawl results: retained while your account is active so your history and comparisons remain available, and deleted within 30 days of account closure or sooner on request. You may delete an individual audit or crawl from your dashboard at any time.
- Support correspondence: up to 2 years from the interaction.
- Logs and diagnostic data: typically 90 days, longer where needed to investigate a security incident.
- Backups: residual encrypted copies may persist for a limited period after deletion due to technical constraints.
You may request deletion of your data at any time by contacting pageinspections@gmail.com.
10. Security
We maintain technical and organizational measures appropriate to the data we hold, including:
- TLS encryption for data in transit
- Encryption at rest for sensitive data, and hashing of passwords and of IP addresses used for anonymous rate limiting
- Logical separation between accounts, so one account cannot reach another's audits or verified domains
- Ownership verification as a control on what the crawler may be pointed at
- Internal access limited to what personnel need to operate and support the Services, with access logged
- Dependency monitoring, vulnerability review, and use of reputable infrastructure providers
No system is perfectly secure and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify affected users and any relevant supervisory authority as required by applicable law, without undue delay.
11. Your Rights
11a. If You Are in the EEA, UK, or Switzerland
You have the right to: access your personal data and receive a copy; have inaccurate data corrected; request erasure; request restriction of processing; receive your data in a portable, machine-readable format; object to processing based on legitimate interests or to direct marketing; withdraw consent where processing is based on it; not be subject to solely automated decisions with legal or similarly significant effects; and lodge a complaint with your local supervisory authority.
11b. If You Are a California Resident
Under the CCPA and CPRA you have the right to know what personal information we have collected and its sources and purposes; to request deletion; to request correction; to opt out of sale or sharing for cross-context behavioral advertising (we do neither); to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.
11c. Exercising Your Rights
Contact pageinspections@gmail.com. We will respond within the period required by applicable law, generally 30 days under the GDPR and 45 days under the CCPA and CPRA, with extension where permitted. We may need to verify your identity first. There is no fee unless a request is manifestly unfounded or excessive.
Much of this you can do yourself: your dashboard lets you delete individual audits and crawls, remove verified domains, and close your account.
12. International Transfers
The Services are operated from, and information is processed and stored on infrastructure located in, the jurisdictions of our hosting providers. Where we transfer personal data from the EEA, UK, or Switzerland to a country not recognized as providing adequate protection, we rely on appropriate safeguards, which may include Standard Contractual Clauses or another mechanism recognized under applicable law.
If you access the Services from outside the country where our infrastructure is located, your information will be transferred there. Contact pageinspections@gmail.com for details of where your data is held and the safeguards applied.
13. Children
The Services are not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact pageinspections@gmail.com and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Services, our practices, or the law. The "Last Updated" date above reflects the most recent revision. Where changes are material, we will notify you by email or through a prominent notice in the application. Continuing to use the Services after the effective date constitutes acceptance.
15. Contact
Questions, requests, or complaints about this Privacy Policy or our handling of data:
PageInspection
Email: pageinspections@gmail.com
EEA and UK users may also lodge a complaint with their supervisory authority. EEA authorities are listed at https://edpb.europa.eu; the UK authority is the Information Commissioner's Office at https://ico.org.uk.
© 2026 PageInspection. All rights reserved.