Privacy policy

What SiteGuardrail stores and why

How SiteGuardrail handles submitted website URLs, scan reports, access tokens, payments, analytics, retention, and privacy requests.

Last updated
21 July 2026
Unpaid access
7 days
Paid access
30 days

1. Information you provide

When you start a scan, SiteGuardrail receives the public website URL and the scan-mode choices submitted with it. If you contact us, we receive the information you include in that message. Do not submit credentials, private URLs, personal records, or a target you are not permitted to assess.

2. Scan and report data

The service stores report metadata, the submitted and final public URL, scan status, summary counts, preview evidence, scope, timing, and an access-token hash. The complete report is stored privately and is returned only when the correct bearer access token is supplied and any applicable unlock has been verified.

Scans may contain information already exposed by the target, such as public headers, file paths, scripts, DNS records, and sensitive-looking values. Customer-facing evidence is redacted; you should still treat reports as security-sensitive.

3. Browser storage

The browser temporarily stores the pending report ID, report access token, and access-expiry time in local storage so the report can be restored after Stripe checkout. The access token is not added to the Stripe payment URL. Clear site data to remove the local copy.

4. Retention

  • Unpaid report access expires after 7 days.
  • A verified payment grants 30 days of anonymous report access.
  • Private complete-report objects have a 45-day storage lifecycle limit.
  • Operational logs may be retained separately for security, reliability, abuse prevention, and legal obligations.

5. Payments

Stripe processes checkout and payment information under its own privacy terms. SiteGuardrail receives the transaction identifiers, payment status, amount, currency, payment-link identifier, and timestamps needed to verify and fulfil the report unlock. It does not receive or store full card details.

6. Analytics

Privacy-conscious Plausible analytics may record page views and coarse funnel events such as scan submitted, completed, failed, checkout started, report unlocked, report downloaded, focused tool outcome, and retest. SiteGuardrail does not attach the scanned URL, affected URL, access token, or finding detail to analytics events. Analytics remains off unless the production Plausible script is configured.

7. Service providers and security

Hosting, cloud storage, queueing, logging, DNS, payment, and analytics providers process limited information to operate the service. SiteGuardrail uses access tokens, hashed token storage, private report storage, encryption at rest, bounded network requests, and response redaction, but no internet service can promise absolute security.

8. Your requests

Contact hello@siteguardrail.com to ask about personal information associated with a support or payment interaction, or to request deletion where applicable. Include enough information to locate the interaction without sending a live credential or report access token.

9. Changes

This page may change as SiteGuardrail adds features, providers, or legal requirements. Material changes will be reflected by the updated date on this page.