Version: 1.0 · Published and effective 7 September 2026
What is stored in your browser
Authentication tokens maintain your signed-in session. Human-verification controls help prevent abuse. Theme, route and navigation preferences support the interface.
A completed Quick Scan can be retained in local browser storage for 30 days. It expires after that period and is cleared when the Website next reads it; a closed browser does not run Website code. Use the clear-browser-scan control or your browser settings to remove it earlier.
The Quick Scan Terms acknowledgement is a local version and timestamp, not proof of an identified person's acceptance. Website registration and Deep Scan acceptance are recorded separately against a verified account.
Your choices
Signing in does not upload your browser Quick Scan. Choose “Save this Quick Scan to my account” to upload it. “Keep it in this browser” does not upload it. Clearing a browser copy does not delete an existing server record.
Optional marketing, analytics or advertising consent is not included in Terms acceptance. Any feature requiring separate storage consent must obtain it before that storage is used.
Storage and duration
Function
What it does
When it is removed
Authentication
Keeps the session for the account you sign in to; tokens are maintained by our authentication provider
Sign out, clear site data, or session expiry/revocation; tokens may refresh while you remain signed in
Human verification
Provides a short-lived challenge token when you use a protected form
Token expiry or replacement; a successful challenge is not a permanent login
Theme and interface preferences
Remembers day/night theme and interface choices on this device
Until replaced or cleared through the interface or browser
Quick Scan progress and result
Supports the local scan you request; logging in alone does not upload it
Local expiry is checked on return, or you clear it earlier; completed local results expire after 30 days
Quick Scan Terms acknowledgement
Remembers the version and local acknowledgement time, without account identity
After 30 days, a document change, or clearing site data
We do not use these choices as permission for advertising or cross-site tracking. Essential sign-in and requested scan functions need their associated storage. You can clear site data in your browser; doing so may sign you out and remove unsaved local work. Your browser may also cache fonts and other page files under its normal cache controls. Google receives font requests as described in the Privacy Policy.
Website activity and support diagnostics · 10 September 2026
For logged-out visitors we measure page views, selected navigation/action clicks, visits and active viewing time. A random first-party identifier is stored in this browser for up to 90 days to recognise repeat visits. On the server we store a hash of that identifier, visit identifiers and minute-level page presence to calculate unique browsers and returning guests. This is pseudonymous browser recognition, not identification of a person. We do not use fingerprinting or link guest identifiers to accounts after sign-in. The owner dashboard displays aggregate guest statistics, not individual guest histories. Older records do not support unique-browser counts.
When signed in, page visits, selected clicks, timestamps and approximate active time are linked to your verified account for support and troubleshooting. These records can be viewed in the owner control room alongside your saved scan progress and AI usage. An account identifies the account holder; it cannot identify which employee used shared credentials.
For recognised guest browsers, we also store the approximate country code supplied by Vercel from the request’s network location, plus the observation time. We do not store the IP address, city or precise coordinates in this activity stream. The dashboard shows distinct guest browsers by their first known country within the selected period and page filter. VPNs can affect the estimate. Older or unavailable country observations stay unknown; countries are not reconstructed from account information. These records use the same activity setting and 90-day retention described below.
This activity stream does not include typed answers, passwords, company secrets, IP addresses, full URLs, screen recordings or cross-site activity. Existing hosting and database providers process the records for us. Hosting/security logs and the contents you deliberately submit to scans are separate.
Measurement is on unless disabled in “Activity settings” in the footer. Earlier refusals remain respected. Turning it off does not restrict scans or account access, and does not disable necessary service, cost or security records. The setting is stored in this browser until changed or cleared. Guest visits are grouped across reloads and tabs until 30 minutes of inactivity. Signed-in visit state is held in memory and resets on reload or sign-in changes. Turning measurement off also removes the guest identifier from this browser; existing server records expire under the retention policy. Records are removed after 90 days by daily cleanup. For access or deletion requests, use our contact form.
This supplementary notice describes the activity feature. It does not record consent or change any previously accepted Terms version.
Vercel Web Analytics
We also use Vercel Web Analytics for aggregate page views, visitor estimates, referring sites, approximate location and browser/device statistics. We send only allowlisted page paths, with query parameters and fragments removed; we do not send account identifiers, our guest browser identifiers, answers or custom events. Owner, admin, API and individual report URLs are excluded. Vercel uses a request-derived visitor hash that is discarded after 24 hours, not our 90-day browser identifier, so its visitor totals can differ from the control room. Vercel analytics follows the same “Activity settings” choice and respects earlier refusals. Its reporting retention is separate from our 90-day support records. See Vercel’s analytics privacy information.