Privacy Policy
Last updated: October 1, 2026
What We Collect
When you scan a website: We collect the URL you submit and the analysis results. If you scan without providing an email, we do not collect any personal information — the scan is anonymous.
When you provide your email: We store your email address to create an account and send you your report link. We may also send you relevant updates about your report and our service.
When you purchase a report or subscribe: Payment is processed by Stripe. We do not store your credit card number. We receive your name, email, and a Stripe customer ID to manage your subscription.
Automatically: Our servers log standard access information (IP address, browser type, pages visited). We also use analytics tools to understand page views, funnel events, and product interaction patterns. We use this for security, service reliability, and product improvement, not for advertising or selling data.
How We Use Your Information
We use your information to:
- Generate and deliver your AI readiness reports
- Save your reports so you can access them later
- Process payments through Stripe
- Send you report updates, score change alerts, and service notifications
- Improve our analysis methodology and service
We do not sell your personal information. When we run paid ads, we may use advertising measurement tools to understand which campaigns lead to scans, email signups, and purchases.
Third-Party Services
We use the following third-party services to operate GPTmyWebsite:
- Stripe — Payment processing. Stripe's privacy policy: stripe.com/privacy
- Resend — Transactional and lifecycle email delivery for report links, account access, billing notices, support messages, and opted-in product updates. resend.com/legal/privacy-policy
- Open PageRank — Domain authority data (we send only domain names, no personal data)
- Google PageSpeed Insights API — Performance analysis (we send only URLs, no personal data)
- Google Tag Manager — Event routing for analytics and product measurement
- Microsoft Clarity — Site usage analytics and session replay to help us improve the product experience
- Meta Pixel — Advertising measurement when Meta campaigns are active
Cookies
We use essential cookies required for the Service to function, plus analytics cookies or local storage used by our analytics providers:
- Session cookie — Keeps you logged in. Expires when you close your browser or after inactivity.
- CSRF token — Protects against cross-site request forgery. Required for form submissions.
- Analytics storage — Helps us understand scan starts, report views, email captures, checkout starts, and product usability issues.
When ad campaigns are active, advertising measurement cookies may help us understand which campaigns led to scans, email signups, or purchases. You can control cookies through your browser settings.
Data Retention
Active accounts: Scan results and reports are retained for as long as your account exists so you can access them anytime. Score history and snapshots are kept to show trends over time.
Free scans (no account): Anonymous scan results are retained for 90 days, then automatically deleted.
Account deletion: If you delete your account, we will delete your personal information and de-associate your scans within 30 days. Some anonymized, aggregated data may be retained for service improvement.
Payment records: Retained as required by law (typically 7 years for tax/accounting purposes) and Stripe's policies.
Email communications: Transactional email logs are retained for 90 days. You can unsubscribe from non-essential emails at any time.
Your Rights
Regardless of where you are located, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Request a portable copy of your data in a structured format
- Withdraw consent for data processing at any time
- Object to processing of your data for specific purposes
- Unsubscribe from marketing emails at any time (every email has an unsubscribe link)
To exercise any of these rights, email [email protected]. We will respond within 30 days.
European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
Legal basis for processing:
- Contract performance — Processing your domain scan, delivering reports, and managing your subscription
- Legitimate interest — Improving our service, preventing fraud, and ensuring security
- Consent — Sending you marketing emails (you can withdraw at any time)
- Legal obligation — Retaining payment records as required by tax law
Data transfers: Your data may be processed in the United States. We use standard contractual clauses and industry-standard security measures to protect data during international transfers.
Supervisory authority: You have the right to lodge a complaint with your local data protection authority if you believe your data is being processed unlawfully.
Data Protection Officer: For GDPR inquiries, contact [email protected].
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- We do not sell personal information
- We do not share personal information for cross-context behavioral advertising
- You may request to know what data we collect about you
- You may request deletion of your data
- You will not be discriminated against for exercising your rights
Contact us at [email protected] to exercise these rights.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on our website.
Contact
Questions about privacy? Email [email protected].