Privacy policy.
SiteAssets fetches public web pages and renders images from the parameters you give us. This page explains exactly what that means for your data — no filler, no dark patterns.
The short version
- Anonymous checks need no account. The URL you submit is fetched, scored and cached in memory for 10 minutes, then discarded.
- We never sell data, and we do not run third-party advertising or analytics trackers on this site.
- If you sign in, we store the minimum needed to run your account: an email address, a plan flag and your check history.
- Card payments are handled by our merchant of record. Card numbers never reach our servers.
- You can delete a report, or your whole account, from the dashboard at any time.
What we collect
We collect three categories of data: the URLs and parameters you submit, the account data required to keep you signed in, and coarse operational counters used for rate limiting.
- Submitted URLs and generator parameters — the title, description, site name, logo URL, brand colour and template you provide.
- Fetched page content — held in memory only for the duration of a check, and never written to disk in anonymous mode.
- Account data — email address, hashed password (when you use password sign-in), plan tier, plan expiry and created/updated timestamps.
- API keys — stored as a hash plus the last four characters, so a key can be verified but never recovered from our database.
- Usage counters — how many checks, generator renders and API calls a day or month, used to enforce the published limits.
- Operational logs — timestamps, route, status code and an IP-derived rate-limit bucket. Logs are short-lived and contain no page content.
What we do not collect
- No advertising identifiers, no behavioural profiles, no data brokerage.
- No third-party analytics or session-recording scripts on any page.
- No content behind your login — the checker only reads publicly reachable URLs.
- No card details: payments are processed by the merchant of record and we receive only a subscription status.
Anonymous checks and caching
Anonymous checks are cached in memory for 10 minutes, keyed by the normalised URL, so a page you scan twice in a row is only fetched once. The cache holds at most a few hundred entries and is never persisted to disk. Signed-in checks bypass the cache and are stored as reports in your account.
Accounts and stored reports
When you are signed in, each check can be saved as a report: the scanned URL, its score, the extracted metadata and the list of issues. Reports are visible only to you, unless you explicitly create a shareable link. Shareable links are public to anyone holding the URL for the retention window shown on the report page.
Payments
Subscriptions are sold by a merchant of record that handles the transaction, tax and invoicing. We receive a subscription status and a customer reference — never a card number, never a bank detail. To cancel or change a plan you use the billing portal, and cancelling stops the next renewal rather than revoking access immediately.
Third-party processors
We keep the list short and each one is bound by a data processing agreement.
- Hosting and database — stores accounts, API key hashes, usage counters and saved reports.
- Authentication — optional OAuth sign-in providers you choose to connect.
- Payments — the merchant of record for subscriptions and invoices.
- Font delivery — typefaces are self-hosted and served from our own origin, not a third-party CDN.
When you submit a URL, our server fetches it directly. Your browser sends the request to us, not to the scanned site, so the operator of that site sees our bot user agent rather than your IP address.
Retention
- Anonymous cache — 10 minutes, memory only.
- Saved reports — 30 days by default; longer windows are configurable for Pro accounts.
- Shareable report links — expire at the end of the retention window.
- Usage counters — kept for the current billing period plus a short audit window.
- Operational logs — kept briefly and rotated; no page content is included.
Security
- All traffic is served over TLS.
- Passwords are hashed; API keys are stored as irreversible hashes.
- Authenticated forms use a double-submit CSRF token in addition to origin checks.
- Outbound fetches block loopback, link-local, private and metadata endpoints, and every redirect hop is re-validated to prevent server-side request forgery.
- Access to production data is limited to the operators who need it to run the service.
If you believe you have found a security issue, please report it privately. We will confirm receipt and keep you updated while we fix it.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete the personal data we hold, and to object to certain processing. In practice, most of this is self-service:
- Delete an individual report from your dashboard.
- Revoke an API key from the account page.
- Delete your account to remove the associated records.
- Export your check history as JSON from the dashboard.
For anything else — a legal request, a data export, a correction — contact us using the address on the contact page and we will respond within 30 days.
Children
SiteAssets is a developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 13, and we will delete such data if we become aware of it.
Changes to this policy
When this policy changes materially we update the revision date at the top of the page and note the change in the changelog. Continuing to use the service after a change means you accept the updated policy.
Questions about your data?
Ask us anything about what is stored, how long it lives and how to remove it. We answer data requests within 30 days.
Contact us