What we collect
- Your email address — to identify your account and send account email.
- A password hash — scrypt with a per-account random salt. We never store your actual password and cannot recover it, which is why a forgotten password requires a reset link rather than us telling you what it was.
- Session tokens — random values in an httpOnly cookie, stored so sessions can be revoked.
- URLs you check, and the reports generated — so your history is available in your dashboard.
- Usage events — one row per check, for metering and billing.
- Payment claims — the email, transaction reference (UTR), amount and any note you submit, so we can verify a payment against our bank records.
What we don't collect
- Card or bank credentials. Payment happens entirely inside your own UPI app. We only ever see a transaction reference number you type in yourself.
- Third-party analytics or advertising trackers. There are none on this site.
- Anything from pages you check beyond the analysis itself. We fetch the page, analyse it, store the resulting report, and discard the raw HTML.
Who your data is shared with
Only the processors needed to run the product:
- Our hosting and database provider — stores the application and its database.
- OpenAI and/or Anthropic — the AI-judged portion of a full audit sends extracted page content to whichever provider is configured, to be scored. This applies to content you submit for audit, not to your account details.
- Our transactional email provider — receives your email address in order to deliver password reset messages.
We do not sell personal data, and we do not share it for advertising.
Pages you analyse
When you submit a URL, our servers request that page from its origin, identifying as the relevant crawler user-agent. That request appears in the target site's logs with our server's IP address. Only submit URLs you have a legitimate reason to analyse.
Retention
- Account records and audit history are kept while your account is open.
- Sessions expire after 30 days, and are deleted immediately on sign-out or password reset.
- Password reset tokens expire after one hour and are deleted the moment they're used.
- Payment claims are retained for accounting purposes.
Your rights
Email us and we will action these promptly:
- Access — a copy of the data held about you.
- Correction — fix anything inaccurate.
- Deletion — close your account and erase your data, subject to records we must keep for tax and accounting.
- Export — your audit history in a machine-readable form.
Security
Passwords are hashed with scrypt and compared in constant time. Session cookies are httpOnly, Secure and SameSite. Sign-in, signup and password-reset endpoints are rate limited. Traffic is served over HTTPS. No system is perfectly secure, but we don't cut corners on the basics.
Children
AI Page Audit is a business tool and is not directed at anyone under 18.
Contact
Privacy questions or requests: support@citerank.app.