Legal

Privacy Policy

Last updated 20 August 2026

This policy explains what SiteQuiet does with personal data, in the same plain English we use everywhere else. It is written to be read, not to be survived.

The short version is in section 1. Everything after it is the detail behind that summary.

Summary in plain English

The short version, before the detail.

What we collect

  • Your email address — the one you use to buy, the one you want alerts sent to, and the one you sign in with (they can all be different).
  • The web addresses you ask us to scan or watch.
  • The results of our checks on those websites: whether the site responded, certificate and domain expiry dates, DNS records, broken links, response times.
  • A small set of product events (for example “a scan finished”) tied to a random id that lasts for one browsing session.
  • Which version of a page we showed you. We run split tests of our own wording, and your assignment is kept in a cookie on your device for 90 days and attached to those product events.
  • If you have an account: your sign-in sessions. There is no password to collect — signing in is a one-time link we email you.
  • If you install our WordPress plugin: facts about that installation — the WordPress, PHP and plugin versions, the theme, and the contact forms it found.
  • Technical records of scan requests, including the IP address they came from, so we can stop abuse of the free scanner.
  • Anything you write to us for support.

What we never collect

  • Nothing about your website’s visitors. We look at your site from the outside, like any visitor. We never receive your visitor logs or analytics.
  • No card or payment details. Ever. Lemon Squeezy takes the payment; those details never touch our servers.
  • No advertising trackers, no ad pixels, no third-party analytics, no cross-site tracking.
  • No logins for your website. We never ask for your hosting, CMS, FTP or email passwords, and would refuse them if offered.

We also do not sell your personal information, and we do not share it for advertising.

Who we are

SiteQuiet is operated by [LEGAL ENTITY], of [ADDRESS]. For data-protection law, [LEGAL ENTITY] is the controller of the personal data described in this policy — meaning we decide why and how it is used, and we are the ones you can hold to this document.

This policy covers the SiteQuiet website, the free scanner, your SiteQuiet account, paid website protection, and our WordPress plugin.

What we collect

Your email addresses

Your account email, which you enter before checkout, identifies your subscription, receives service messages, and is the address you sign in with. Your alert email is where monitoring alerts go — it can be a different address, such as the person who looks after your website.

The websites you ask us to check

Every address you enter, in a form we tidy up so that “www.Example.com/” and “example.com” are treated as one website. For a paid subscription we store which website occupies each of your protected-website slots.

What our checks observe

When we check a website we keep the results, not a copy of the site. In practice that means: whether it responded and with what status, the final address after redirects, response and connection timings, SSL certificate facts (issuer, validity dates), DNS records, the domain’s registration expiry date, and any dead links found — recorded as the link address, the page it was found on and its link text. When protection is active we also keep the history of these observations and any incidents they led to.

Your account and how you sign in

There is no password, so there is no password to store. When you ask for a sign-in link we record the email address you asked for it with, a one-way hash of the link itself (the usable link exists only inside the email, so a copy of our database cannot sign anyone in), when it expires, whether it has been used, and a short one-way hash of the IP address the request came from.

When you use the link we create a session record: your account id and email, when the session started, when it was last seen, when it expires, and the first 200 characters of the identification string your browser sends. Your browser holds only an opaque reference to that record — see section 6.

Product events

We record a small, fixed list of first-party product events — for example “landing page viewed”, “scan finished”, “checkout started”. Each event carries its name, a timestamp, a random session id that lives only for the current browser session, the version of the page you were shown (below), and a little context such as the website address scanned, the health score, or the plan chosen. No email address is ever sent to this collector. Only names on our fixed list are accepted; anything else is discarded. Your IP address is used to limit how often the collector can be called and is not written down with the event.

Which version of a page you were shown

We test our own wording, and we assign every visitor to one version on their first visit to a public page. That assignment is a short list of names, such as “hero:a|cta:scan|pricing_default:annual”. It is stored in a cookie on your device for 90 days, it is attached to every product event above, and it is saved with a purchase you start. That is what lets us tell whether a change actually helped rather than guessing. It says nothing about you. Section 6 describes the cookie itself.

Scan telemetry (abuse prevention)

Separately from product events, the free scanner keeps an operational log of its own decisions — “scan requested”, “rate limited”, “served from cache”, “scan finished”. Every entry carries a timestamp and the name of what happened.

Beyond that, entries differ. “Scan requested”, “rate limited” and a failed human-verification step record the IP address the request came from — plus, for a failed human-verification step, a short note of why it failed — and nothing about the website. The entries about the scan itself record the website address, or for a per-domain limit only its domain, and no IP address; a scan that goes wrong also records a short technical note about the failure. Entries such as “too busy right now” record neither. No single entry holds both an IP address and a website address — but they are written to one time-ordered log, so we will not pretend the two could never be connected.

We keep this for one reason: the free scanner is an obvious target for abuse, and without it we cannot tell a customer from an attacker.

Proving that you control a website

Before we do anything to a website beyond reading it, you prove you control it. We generate a random token for you to publish — as a DNS record, a file, a meta tag, or via our WordPress plugin — and we record that token, when it expires, how many times we have looked for it, which method finally worked and when, and, if a check did not succeed, a plain-English note of why.

If you install our WordPress plugin

The plugin is optional and you install it yourself. When it connects, it sends us your website address, its WordPress and plugin versions, the connect code you pasted in, and the WordPress administrator email address — which our connect endpoint does not save.

After that it checks in periodically, and each check-in carries: your website address, the plugin, WordPress and PHP versions, the active theme, whether the install is a multisite, the address alerts should go to, whether you have switched contact-form testing on, and a list of the contact forms it found — for each form, the form plugin, its id, its title and the page it appears on. We keep only the most recent check-in from each installation; a new one replaces the last. Its requests also identify themselves in their user-agent header with your site address.

The plugin never reports anything about your visitors. It looks at the installation, not at the people using it.

Billing records

From Lemon Squeezy we read and store your email address, which plan you bought, your subscription status, the date your subscription is paid through, and Lemon Squeezy’s own reference ids — its customer, subscription and order ids. We never read or store any card details — not even the card brand or the last four digits.

The emails we send you

We keep a record of each email we sent: the address, what kind of message it was, the subject line, when it was sent, whether the provider accepted it and any error it gave back. That record is how we can tell whether an alert actually went out — which matters most on the day it did not. We also record when you unsubscribe from the weekly summary or from product email, and when an attempt to email an address fails.

Support correspondence

If you email us, we keep the message and our reply so we can help you and remember the context next time.

Waiting lists

If you join an early-access or waiting list, we store the email address you gave, the website address if you provided one, and where on the site you signed up.

What we do not collect

  • Personal data about your website’s visitors. We request your pages the way an ordinary anonymous visitor does. We receive no data from your visitors, and we have no access to your analytics or server logs. We never place any code of ours on your website; the only thing that runs on your site is our WordPress plugin, if you choose to install it, and it reports on the installation — never on the people using it.
  • Copies of your pages. Page content is read only for as long as a check needs it — to find the links on a page, or to confirm the page loaded — and then discarded. Responses are size-capped as they are read. What we keep is the conclusion, not the content.
  • Payment card data. Card and payment details are entered on Lemon Squeezy’s checkout, on their own domain, and are never sent to, seen by, or stored by SiteQuiet.
  • Advertising or cross-site tracking data. There are no ad pixels, no retargeting tags and no third-party analytics services on this site.
  • Credentials for your website. Our checks never sign in, never submit forms without your explicit consent, and never need a password from you.
  • Special-category data. We have no reason to collect anything about health, beliefs, politics or similar, and we ask you not to send it to us.

Our web fonts are served from our own domain, so simply reading this page does not send a request to any font or advertising network.

How we use it, and our legal basis

What we doData usedLegal basis (UK/EU GDPR)
Run the free scanner and show you the resultThe website address, technical scan resultsLegitimate interest — providing a service you asked for before any contract exists
Monitor a protected website and send alertsWebsite address, check results, alert emailPerformance of our contract with you
Give you an account, sign you in, and keep you signed inAccount email, the sign-in link record, your session recordPerformance of our contract; legitimate interest in keeping accounts secure
Confirm that you control a website before doing anything active to itWebsite address, the verification token, what we found when we looked for itPerformance of our contract; legitimate interest — never acting on a website for someone who does not control it
Receive check-ins from our WordPress plugin, if you install itWebsite address, plugin, WordPress, PHP and theme details, forms found, alert address, your form-testing choicePerformance of our contract
Take payment, manage your subscription, send receiptsAccount email, plan, subscription status, Lemon Squeezy referencesPerformance of our contract; legal obligation for tax records
Stop abuse of the free scanner and protect our systemsScan telemetry, IP address, human-check resultLegitimate interest — keeping the service available and not letting it be used against other people’s websites
Understand which parts of the product workFirst-party product events with a session idLegitimate interest — improving a service we cannot see anyone using
Show you one version of our wording and see which version leads whereThe split-test assignment stored on your device (see section 6), attached to product events and copied onto a purchase you startLegitimate interest — improving a service we cannot see anyone using
Send the weekly summary, and keep a record of the emails we sendAlert or account email, what was sent, whether it was acceptedPerformance of our contract; legitimate interest in being able to prove an alert was sent
Publish a status page for a website, when you switch one onWebsite address, current state, when we last checked, the 30-day availability percentage, and confirmed incidents with their dates and durationsConsent — you turn it on, and turning it off takes the page down
Answer your support messagesYour message and contact detailsPerformance of our contract; legitimate interest
Send optional product or marketing email, if you ask us toYour email addressConsent — which you can withdraw at any time

We do not use your data to make automated decisions with legal or similarly significant effects, and we do not profile you.

Cookies and similar technologies

SiteQuiet sets two cookies and uses two pieces of browser storage. There are no third-party cookies, no advertising identifiers, and nothing here follows you to another website.

NameKindWhat it holds, and who sets itHow long
sq_sessionCookieThe reference to your signed-in session — an opaque id, not your email address and nothing readable. Set when you open a sign-in link. It is marked HttpOnly, so page scripts cannot read it, SameSite=Lax, so it is not sent from other websites, and Secure on our live site.30 days from signing in, or until you sign out — signing out both deletes it and cancels the session on our side
sq_expCookieWhich version of our wording you were shown, as a short list of names such as “hero:a|cta:scan|pricing_default:annual”. Set on your first visit to a public page. It is deliberately readable by our own page scripts, because the code that records product events reads it to attach your version to each event. SameSite=Lax, and Secure on our live site.90 days from the visit that set it
sq_sessionsessionStorageA different thing with the same name — see the note below. A random id that lets us join up the steps of one visit (for example “scan started” then “scan finished”) without identifying you.Until you close the browser tab
sq_pending_protectionlocalStorageThe reference number for a purchase you started — not your email address or your website address — so you can come back and finish it instead of starting again.Until you dismiss the offer to finish, or clear your browser storage. Completing a purchase does not remove it, and only a purchase started from the checkout page replaces it.

Two different things are called sq_session. If you open your browser’s storage panel you will see the name twice, and they are unrelated. Under Cookies, sq_session is your sign-in session: it exists only if you have an account and have signed in, it lasts 30 days, and your browser will not show you its value because it is HttpOnly. Under Session storage, sq_session is a random id used to group one visit’s product events: it exists whether or not you have an account, it is readable, and it disappears when you close the tab. Deleting the session-storage one signs nobody out. Deleting the cookie signs you out.

The sign-in cookie and the unfinished-purchase entry exist to do things you asked for: stay signed in, and finish a purchase you started. The split-test cookie and the session-storage id are not needed to deliver the site — they are how we measure our own wording. The scanner, the reports and every public page work with all four cleared; only staying signed in needs the sign-in cookie. Clearing browser storage removes them, though a later visit will be assigned a fresh split-test arm.

When the human-verification step is enabled on the scanner, it is Cloudflare Turnstile, loaded from Cloudflare. It exists to tell people from bots and is not an advertising tool; it may use its own browser storage to do that job, under Cloudflare’s privacy terms.

If we ever add advertising, third-party analytics or any cross-site identifier, we will ask for your consent first and update this section before doing so.

Who else processes your data

We keep the list of companies involved deliberately short. Each one is bound by a contract to process data only on our instructions.

WhoWhat they doWhat they receive
Lemon SqueezyPayments, as Merchant of Record — they are the seller of record and handle tax, refunds and receiptsYour email address, the plan, and the payment details you enter directly with them
VercelHosting for the SiteQuiet website and its APIsRequests to our site, including IP addresses, as any web host does
CloudflareThe human-verification step on the free scanner, and network-level abuse protectionThe verification token and the IP address of the request
[EMAIL PROVIDER]Sending alert and service emailsThe alert or account email address and the content of the message we send you
[DATABASE PROVIDER]Storing subscription, site and monitoring recordsThe data described in section 3, at rest

Public internet lookups

Checking a website necessarily involves asking the internet about it: DNS resolvers are queried for its records, and the domain-registration (RDAP) service for its extension is asked when the domain expires. Those services receive the website address being checked. They do not receive your email address or anything else about you.

Things you choose to publish

A status page is off unless you switch it on. When you do, anyone with the link can see the website address; whether it is currently working, including how many smaller things are worth a look when there are any; when we last checked; the percentage of our availability checks over the last 30 days that found the website up, once enough have run to state a figure; and the problems we confirmed in that period — for each one, its headline, the date we confirmed it, whether it is still going on, and roughly how long it lasted once it is over. A confirmed problem that is still open can appear even if it began before that 30-day window. The page does not show your alert address, your account, your plan, the technical detail behind a check, or a problem we have not confirmed. Switching the page off takes it down.

We keep this list current. We do not sell personal data, and we do not pass it to anyone else except where the law requires it, or where it is necessary to establish or defend a legal claim.

How long we keep it

We keep data only as long as it is doing a job. Some of that is enforced by a scheduled deletion job, and some of it is not yet — this section says which is which, because a period nobody enforces is not a promise.

Deleted automatically

A scheduled job deletes these on exactly these periods.

WhatHow longWhy
Individual check results — each time we looked at your website90 daysEnough to show recent history and explain an alert
Incidents24 months after the incident started, and only once it has been resolved. An incident still open is never deleted.So you can see your website’s track record — and so we never forget an outage we are in the middle of reporting
Alerts we decided to send24 monthsThe record of what we told you, and when
Our record of the emails we sent180 daysSo we can answer “did that alert actually go out?”
Sign-in links, and sessions that have expired or been signed out7 days after they expire or are cancelledAn expired sign-in link is worthless; it should not sit in a database
A purchase you started and did not finish30 days, unless it led to a payment — one that did is kept.So you can come back and finish it — and so an abandoned one does not linger

Kept while they are doing a job

Nothing deletes these on a timer today. They are kept while the reason for holding them lasts, and you can ask us to delete them sooner — see section 9.

WhatHow longWhy
Account, subscription and site recordsWhile your subscription is active and while your account existsSo you can come back without starting over
Billing and tax recordsAs long as tax and accounting law requiresLegal obligation — typically 6–10 years depending on the country
Scan telemetry (including IP addresses)While it is still useful for investigating abuse of the free scannerWithout it we cannot tell a customer from an attacker
Product events, including the split-test assignmentWhile we are still learning from themUnderstanding how the product is used
The most recent check-in from a WordPress installationUntil the next check-in replaces it, or the site is removedOnly the latest one tells us anything
Free scan resultsHeld in memory for a few minutes — ten by default — and never written to our database unless the website is protectedRepeat scans of the same address reuse a recent result
Support correspondenceWhile it is useful contextContext for future support
Waiting-list and marketing list membershipUntil you unsubscribe or ask to come offConsent, withdrawable at any time

When we delete, the data is deleted or irreversibly aggregated so it no longer identifies anyone. You can ask us to delete your data sooner — see section 9.

Your rights

If you are in the UK or the EU

Under the UK GDPR and EU GDPR you have the right to:

  • get a copy of the personal data we hold about you (access);
  • have inaccurate data corrected (rectification);
  • have your data deleted (erasure);
  • receive your data in a portable, machine-readable format;
  • restrict how we use your data while a concern is being resolved;
  • object to processing we base on legitimate interests, including any direct marketing; and
  • withdraw consent at any time, where consent is what we relied on.

If you are a California resident

Under the CCPA/CPRA you have the right to know what personal information we collect and why, to request its deletion, to request correction, and not to be discriminated against for exercising these rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use sensitive personal information to infer characteristics about you. Because we do not sell or share, there is no opt-out link to give you.

How to exercise them

Email [SUPPORT EMAIL] from the address we hold for you, and tell us what you want. We will not charge you, and we will not ask for more identifying information than we need to be sure it is you.

We respond within one month (UK/EU) or 45 days (California). If a request is unusually complex we may extend that, and we will tell you why before the original deadline passes. You may also use an authorised agent.

Some data cannot be deleted on request — billing records we are legally required to keep, and abuse records where deleting them would defeat their purpose. If that applies to your request we will say so and explain why.

Security

A service whose whole job is fetching web addresses strangers give it has to be careful. Concretely:

  • Every outbound request is checked before it is made. We refuse to connect to private, internal, loopback or cloud-metadata addresses, only allow ordinary web addresses and ports, and re-check every redirect hop against the same rules — so our service cannot be used as a way into someone else’s network.
  • We never hold credentials for your website. There is nothing to steal, because we never ask for a password, and our checks never sign in.
  • There is no SiteQuiet password either. Signing in is a one-time link that expires in fifteen minutes, and we store only a one-way hash of it — so a stolen copy of our database cannot sign anyone in. Keys held by our WordPress plugin are stored the same way, with only a short prefix kept readable so you can tell one key from another.
  • Payment data is out of scope by design. Card details go to Lemon Squeezy directly; there is no card data in our systems to protect.
  • Email addresses are kept out of product analytics. The event collector accepts only a fixed list of event names and never receives an email address.
  • Billing messages from Lemon Squeezy are cryptographically verified before we act on them, so a forged “subscription cancelled” message cannot turn off your monitoring.
  • Scan requests are individually authorised with short-lived signed tokens that are tied to the one address being scanned, so the scanning endpoint cannot be driven with arbitrary addresses.
  • Traffic between you and SiteQuiet is encrypted in transit (HTTPS).

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data we will tell the relevant supervisory authority within 72 hours where the law requires it, and tell you directly without undue delay where there is a high risk to you.

Children

SiteQuiet is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, tell us and we will delete it.

International transfers

Some of the companies listed in section 7 operate outside the UK and the European Economic Area, including in the United States. Where personal data is transferred out of the UK or EEA, we rely on the safeguards those providers offer — such as the European Commission’s Standard Contractual Clauses with the UK Addendum, or an adequacy decision covering the destination country.

You can ask us for details of the safeguards that apply to a particular transfer, and we will provide them.

Changes to this policy

We will update this policy when what we do changes — in particular if we add a cookie, an analytics provider, or a new processor. The “Last updated” date at the top always shows the current version.

If a change materially affects how we use your data, we will email subscribers before it takes effect rather than relying on you to re-read this page.

Contact and complaints

For anything in this policy — a question, a data request, or a complaint — email [SUPPORT EMAIL]. A person reads it, and we aim to reply within two business days.

Postal address: [LEGAL ENTITY], [ADDRESS].

If you are not satisfied with how we have handled your data, you have the right to complain to a data-protection supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU, the authority in the country where you live or work. We would rather you came to us first, but you do not have to.