Privacy policy
OpenAEO collects the minimum it needs to audit your site and show you the result: the domain you ask us to audit, plus your email address if you choose to give it. We do not sell your data, we do not run advertising trackers, and we do not build profiles on you. This page lists exactly what is stored, who it is shared with, and how to have it deleted. Last updated 7 August 2026.
What we collect
When you run an audit: the domain or URL you submit, and the results our crawler computed from that page. If you are not logged in, this is not attached to any identity.
When you give us your email for the full audit: your email address, the domain you audited, and that audit's result, so we can send you the report and know what you asked about. We also record the date you gave it and which form it came from, so that if you ask us later what you agreed to, there is an answer rather than an assurance.
When you create an account: your email address and a salted, hashed password (we never store the password itself). We also store the audits, citation tests, target prompts, competitor domains, and server-log excerpts you choose to save.
If you connect Google Search Console or Analytics: a refresh token that lets us read your search-performance and referral data. It is read-only, we never write to your Google account, and you can revoke it at any time from your Google account permissions.
Automatically: your IP address is used transiently for rate limiting (to stop abuse) and, as described below, to count visitors. It is never written down in either case. We do not use advertising or analytics cookies. The only cookie we set is a session cookie that keeps you logged in.
How far you scrolled: when you leave a page we add one count to that day's total for that page: which page it was, the furthest depth you reached rounded to the nearest tenth, which sections came into view, whether your screen was narrow, and the domain name of the site that linked you to us. We record the referring domain only, never the full address of the page you came from, because those routinely carry search terms and session tokens in the query string and a bare domain cannot. It exists because we were making decisions about page length from guesswork, and we would rather measure. If your browser sends Do Not Track or Global Privacy Control, nothing is counted: the browser declines to send it, and our server declines to record it even if something else does.
How we count visitors, and why it cannot identify you: to report visitors rather than page views, something has to decide that two views came from the same person. We do that without keeping any record of a person. When a view arrives we combine your IP address, your browser's user-agent string, and a random secret that exists for that day only, and hash the three together. That hash is never stored. It is used once, to nudge one of 1024 small counters, and then discarded. At the end of the day the secret is overwritten by the next day's and ceases to exist, so the same visitor on two different days produces two unrelated hashes that nothing can connect.
What remains is 1024 numbers. From them, statistics can estimate how many distinct people there were, to within a few percent. They cannot say who, and they cannot be meaningfully asked whether a particular person is among them, because thousands of visitors collapse into the same 1024 numbers and the calculation does not run backwards. There is no per-visitor row to look anyone up in, at any point, which is a stronger promise than a privacy policy alone: it is not that we choose not to look, it is that there is nothing there to look at.
The trade is real and we accept it deliberately. Because no per-person record exists, we cannot produce bounce rates, entry and exit pages, funnels, or anything else that needs one visitor's sequence of pages, and our visitor numbers are estimates rather than exact counts. We would rather report an approximate number honestly than an exact one built on a record of you. We can learn that about 300 people read half way down the homepage; we cannot learn that you did.
Who we share it with
We share data only with the service providers needed to run the product, never with data brokers or advertisers:
- Netlify. Hosting and data storage.
- Stripe. Payments. Card details are entered on Stripe's own page and never touch our servers; we store only the last four digits and your plan.
- AI providers (OpenAI, Anthropic, Perplexity, Google). When you run a citation test, your target prompts are sent to these assistants to check whether you are cited. Do not put confidential information in your prompts.
- Resend: sending transactional email (your report, password resets).
- Google. Only if you connect Search Console or Analytics, to read your own data.
How long we keep it
Account data is kept while your account exists. Audit history is capped at the most recent 200 runs per account and citation runs at the most recent 52. Lead emails are kept until you ask us to remove them. Traffic totals and visitor registers are kept for 120 days and contain nothing that identifies anyone. The daily secret behind the visitor count is not kept at all: it is overwritten when the day turns, which is what stops the day's hashes from ever being recomputed. Delete your account or email us and it goes.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it, including the email address you gave for a report. If you are in the UK, EU, or a similar jurisdiction, these are your rights under the GDPR: access, rectification, erasure, restriction, portability, and objection. Email [email protected] and we will action it within 30 days. You can also complain to your local data-protection authority.
Our lawful basis is: performing the service you asked for (running audits, your account), and our legitimate interest in product updates to people who gave us their email, which you can stop at any time.
Unsubscribing
Every product update we send carries a one-click unsubscribe link, and the standard List-Unsubscribe header so your mail client can offer the option itself. Acting on it takes effect immediately: we record the opt-out against your address and check it at the moment of sending, not when a list was drawn up, so a stale export cannot put you back on. Running another audit later does not opt you back in. If a link ever fails, email [email protected] and we will remove you by hand the same day; you do not need to give a reason.
Unsubscribing stops product updates. It does not delete your audit history, close your account, or stop the transactional messages you asked for, such as the fix files from a report you just requested or a password reset. To have everything deleted, say so and we will do that instead.
Children
OpenAEO is a business tool and is not directed at anyone under 16. We do not knowingly collect their data.
Changes
If this policy changes materially, we will update the date at the top and, for account holders, say so by email. Questions go to [email protected].
Updated