Privacy at a glance
Accounts
Not required for free audits
Personal data sales
We do not sell it
Advertising
Not currently embedded
Report indexing
Most reports are noindex
We process enough information to deliver the audit, prevent abuse, and keep the service reliable. We do not ask for a profile, billing details, or access to Search Console for the current free product.
Data used for an audit
A submitted domain tells our servers what to fetch. Checks are limited to publicly reachable pages and public infrastructure records; we do not sign in to the target website.
- Submitted URL or domain
- Start the requested audit and build its report URL.
- Appears in the shareable report.
- Public page HTML
- Read titles, headings, links, images, schema, and GEO signals.
- Summarized as findings; not republished as full HTML.
- Public technical signals
- Check redirects, robots.txt, sitemap, DNS, TLS, and RDAP.
- Selected results appear in the report.
- Request metadata
- Operate rate limits, security, troubleshooting, and reliability.
- Not displayed in public reports.
Shareable reports are public by design
Audit results are published at predictable /audit/[host/path] routes. When protocol, port, trailing slash, encoded path, or an allowed query matters, the full submitted URL is also included in the report address as an encoded ?url= parameter. Anyone with the link can open the report. Treat it as public and do not submit a URL if you do not want it or its publicly observable technical signals summarized this way.
A shareable URL is not the same as broad search distribution. Newly generated and random reports default to noindex,follow, and our sitemap includes only a small curated set of example domains. Search engines and third parties ultimately control their own crawling and caches.
Data kept in your browser
The “Recent audits” convenience list is stored in your browser using local storage. It keeps a readable label and the exact public report link, which can include the submitted path and allowed query parameters, so you can return without creating an account. This list stays on that browser and can be removed with the Clear action or by clearing site data in your browser settings.
Theme preference may also be stored locally so dark or light mode persists between visits. Interactive tools, including the SEO Site Ladder, may store progress locally so you can continue later.
Your analytics choice is stored under the local-storage key theseosoul:analytics-consent:v1. It contains only granted or denied. Clearing site data removes this choice and we will ask again on a later visit.
Operational logs and abuse prevention
Like most hosted web services, our infrastructure may record IP address, user agent, timestamps, requested paths, submitted domains, response codes, and diagnostic errors. We use these records to apply rate limits, investigate failures, prevent abuse, and maintain security.
Do not place passwords, API keys, personal messages, or other secrets in a URL submitted for audit. URLs can be included in request logs and the resulting report.
Infrastructure and public-data providers
Hosting, networking, DNS resolution, certificate inspection, and public RDAP services help us deliver an audit. Those providers may process request metadata under their own privacy terms and security practices. We disclose only what is reasonably needed to make the requested check operate.
Google acts as our analytics provider only when you allow analytics. Google processes those events under its own terms and privacy practices. Analytics retention is also governed by the settings of our Google Analytics property and Google's provider rules.
When error monitoring is configured, Sentry helps us diagnose failures and protect service reliability independently of optional audience analytics. An error event may include a stack trace, browser or server metadata, the affected page or tool, and the URL submitted for that failed check. We configure Sentry not to collect default personal identifiers. Retention follows our project settings and Sentry's provider rules. See the Sentry Privacy Policy.
Fetching a target website also reveals our server request to that website and its hosting or security providers, just as any web crawler request would.
How long data stays
Audit results may be cached to make repeated checks faster and protect free upstream services. Shareable report routes can continue to regenerate a current public-data snapshot when visited.
Operational logs are kept only as long as reasonably needed for security, abuse prevention, debugging, and infrastructure requirements. Backups and provider logs may expire on separate schedules.
Your choices and requests
- Do not submit a URL you do not want summarized.
- Clear recent audits from the homepage or browser storage.
- Review or withdraw analytics permission using the control in the Cookies & analytics section above.
- Use your site’s robots.txt and access controls to express crawler policy.
- Contact us about a report, log, correction, or deletion request.
For a request involving a domain report, include its full URL and be prepared to demonstrate reasonable control of the domain. Legal privacy rights vary by location; we will assess applicable requests based on the information involved.
Policy changes
This page will change as the product evolves. The date and version at the top identify the current policy. Material changes will be reflected here, especially before introducing accounts, payments, or materially different tracking.
Privacy contact
Email hello@theseosoul.com with privacy questions or requests. Include the report URL or domain when relevant, but do not send passwords or identity documents unless we specifically request a safe verification method.
TheSeoSoul · https://theseosoul.com