What we actually do with data
Plain English, not legal boilerplate — the same standard we hold every site we scan to. Last updated August 29, 2026.
The short version
We collect the account info you give us, the site URLs you ask us to monitor, and the results of scanning those sites. We don't sell data, we don't run ads, and we don't use any third-party analytics or tracking scripts on this site — there's nothing here to track you with beyond what's described below.
What we collect
When you create an account: your username, email address, and password. Your password is never stored in readable form — like any real system, we store a one-way hash of it, not the password itself.
When you add a site to monitor: the site's URL, and whatever's needed to verify you actually control it (a DNS record or a file you place on your own server — see our ownership-verification step before any scan ever runs). We never scan a site until that's proven.
When a scan runs: the accessibility, security, performance, link, and SEO findings that scan produces. This is data about the site you asked us to check — not personal data about you — but it lives in your account and is visible only to you (or anyone you choose to give your login to).
Cookies
This site sets two cookies, both required for it to function at all: sessionid
(keeps you logged in) and csrftoken (a security cookie that
protects forms from being submitted from somewhere else without your knowledge). Neither
is used for tracking or advertising, and we don't set any others — no analytics cookies,
no ad-network cookies, no third-party trackers of any kind.
Payment
Pro subscriptions are billed through Stripe. When you upgrade, we share your email address with Stripe to create your billing record — your card details go directly to Stripe and never touch our own servers at all. Managing or canceling your subscription happens through Stripe's own billing portal, linked from your account.
We send transactional email only: password resets, scan-completion notices, and (for Pro accounts with uptime monitoring on) down/recovery alerts. We don't send marketing email, and we don't share your address with anyone for that purpose.
IP addresses
Login and signup attempts are rate-limited by IP address to stop automated abuse — this uses a short-lived cache, not a permanent database record, and exists purely to keep the service available, not to build any kind of profile.
Data retention and deletion
Deleting a site from your account permanently deletes its full scan history and findings along with it — there's no soft-delete or recovery window once you confirm. Your account page has a real "Delete my account" button that does the same thing to your whole account: every site, scan, and finding you have is permanently deleted, and any active Pro subscription is canceled immediately. We keep one small record after deletion — your username, email, and Stripe billing IDs if you were ever a paying customer — for financial and legal recordkeeping. Nothing about what sites you scanned or what was found is kept. You can also always reach privacy@getsitehealth.com directly if you'd rather we handle it by hand.
Security
API keys are stored the same way passwords are — only a one-way hash, never the real key. Every scan is guarded against being pointed at internal/private network addresses before it ever runs. The site itself is served over HTTPS with modern browser security headers enabled.
Your rights
Wherever you're located, you can ask us what data we hold about you, ask us to correct it, or ask us to delete it — email privacy@getsitehealth.com and we'll act on it. Specific legal rights vary by where you live; reach out and we'll sort out what applies rather than making you guess.
Changes to this policy
If what we actually do with data changes, this page will change with it, and we'll update the date at the top — no silent rewrites of what we've told you.
Contact
Questions about any of this: privacy@getsitehealth.com.