Privacy Policy
This policy describes what AI Readable collects, why, and what happens to it. It describes actual behavior only — there are no clauses here written to fill space.
Account information
Sign-in and sign-up are handled by Clerk. Your email, password, and session live with Clerk, not in our database. We store no passwords and no sessions, so neither can leak from here.
Our database keeps one shadow row: your Clerk user ID, your primary email (used only for display and troubleshooting), and your remaining free quota. Clerk's own privacy policy governs the data it holds.
URLs you submit
When you run an audit, our server fetches the URL you submitted, reading that page's HTML plus the site's robots.txt, llms.txt, and sitemap. These requests come from our server and will appear in your site's access logs.
The fetched result and the report are stored so you can revisit them under “My reports.” A report includes excerpts of the audited page — its title, the first few hundred characters, the specific elements a rule flagged — because a report without evidence cannot be checked.
Only publicly reachable pages are fetched. We do not bypass login walls, submit forms, or execute JavaScript on the page. Requests aimed at private or reserved address ranges are refused outright.
Report visibility
Anyone who has a report's link can view it. Report links use random IDs that cannot be guessed, and reports are excluded from search engines (noindex), but we do not check who opens them. A report contains only what we fetched from the public page you submitted. Do not share a link you want to keep private.
Rate limiting
To keep free audits usable, we count audits per source. For signed-in users the source is the account; for everyone else it is a one-way hash of the IP address that Cloudflare reports for the request. We store the hash, never the address itself, and delete the counters after two days.
What we do not do
- No ads, no ad targeting
- We do not sell your report contents or the page data we fetch
- We do not send marketing email
Analytics
We use Google Analytics to see which pages get visited and where people give up — that is what decides what we improve next. It records page addresses and click behaviour, and it sets cookies.
Audit contents and reports are never sent to analytics. When you submit a URL we report only the host (for example example.com), never the path — so which page you audited is something our database knows and our analytics does not.
Cookies
Three kinds: Clerk's session cookie, preferences that remember your chosen language and theme, and Google Analytics' cookies. The first two are ours and store nothing about your behaviour; the third is described under Analytics above.
Retention and deletion
Reports are kept until you delete them or delete your account. To remove everything, reach out via Contact and the account plus all reports will be erased.
Reports created without signing in are not tied to any account. To have one removed, send us its link via Contact.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. Material changes will be called out in the app.