Privacy Policy
This page explains what AIWebAudit (we, us) collects when you use aiwebaudit.com, why, and what rights you have. It's plain English on purpose. If anything is unclear, email hello@aiwebaudit.com.
01Who we are
AIWebAudit is operated from New Zealand and is the data controller for personal information you submit to the service. Our address is available on request via the contact email above.
02What we collect
- The domain(s) you audit. When you enter a URL, we fetch that site as a normal visitor would and store the resulting report.
- Your email address. To unlock the full report as an anonymous visitor, or to create an account. Stored to send you the report and (if you sign up) to sign you in.
- Account data. If you register, we store your email, hashed password (managed by Supabase Auth), account creation date, and any subscription tier.
- Payment data. Handled entirely by Paddle.com Market Limited, our merchant of record. Paddle receives and stores your billing details; we only receive a customer ID and subscription status.
- Basic technical data. A short-lived, hashed record of your IP address for abuse and rate-limit protection, and anonymous product analytics (event names such as
audit_runand the domain audited — no personal identifiers).
03Why we use it
- Run the audit you asked for and deliver the report.
- Save your reports and re-audit history if you have an account.
- Send you the report, product updates, and — only if you subscribe — receipts and account emails.
- Prevent abuse: an audit is expensive to run, so we rate-limit anonymous traffic per IP.
- Measure funnel numbers (how many audits are run, how many unlocks) so we can improve the product.
04What we don't do
- We do not sell your data to anyone.
- We do not share your email with third parties for their marketing.
- We do not run advertising trackers or third-party ad networks.
05Who processes your data on our behalf
- Supabase — database, authentication, and file storage.
- Cloudflare / Lovable Cloud — application hosting and edge network.
- Paddle — payments, subscription billing, VAT/sales tax, and receipts. Paddle acts as merchant of record.
- Google PageSpeed Insights — public API we query to measure Core Web Vitals for the domain you audit.
- Large-language-model providers accessed via a managed AI gateway, for the AI-generated parts of the report. We do not send them your email or account details.
06How long we keep it
- Anonymous reports: up to 7 days.
- Account reports: for the life of your account.
- Rate-limit records: deleted after 48 hours.
- Analytics events: aggregated and retained indefinitely; they contain no personal identifiers.
- Account data: until you delete your account, then within 30 days.
07Cookies and similar technology
We use a small number of first-party, functional cookies to keep you signed in and remember your session. We do not use advertising or cross-site tracking cookies.
08Your rights
You can request a copy of your data, correct it, or delete it at any time by emailing hello@aiwebaudit.com. Signed-in users can delete their own saved reports from the "My reports" page. If you're in the EU/UK, you have rights under the GDPR/UK-GDPR; you can also lodge a complaint with a supervisory authority.
09Governing law
This policy and your use of AIWebAudit are governed by the laws of New Zealand.
10Changes to this policy
When we materially change this policy, we'll update the date at the top and — for account holders — notify you by email.