Legal
Privacy Policy
Effective 28 July 2026. We update this page when the product changes, not on a schedule.
LinkAudit analyses public web pages and reports how visible they are to AI search engines. This page describes what we collect while doing that, who we send it to, and what we do not do with it.
What we collect
Account data. If you sign in, our authentication provider stores your email address and, if you use a social login, the name and avatar that provider returns. We do not store passwords — we never see them.
Scan data. When you submit a URL we fetch that page as a normal web client would, and store the resulting analysis: the URL, the scores, the findings, and extracted page content such as headings, meta tags and body text. This is what makes your scan history and monitoring trends work.
Payment data. Card details are handled entirely by our payment provider. We receive a customer identifier and subscription status. We never see or store card numbers.
Product analytics. We record page views and feature-level events (for example: a scan was started, a report was opened) to see which parts of the product are used. We also collect anonymous performance measurements such as page load timings.
Email you send us. If you use the contact form or write to support, we keep the message so we can reply.
A note on the pages you scan
You can submit any publicly reachable URL. We fetch it over the public internet, unauthenticated, exactly as a search engine crawler would — we do not log in, bypass paywalls, or access anything not already public.
We do not verify that you own the site you submit. If you scan a page that is not yours, its public content ends up stored in your scan history. Do not submit URLs that expose someone else's private information through a public link.
Who we share it with
We do not sell your data and we do not share it for advertising. We use the following processors, and no others:
- Vercel — hosting, request logs, and performance measurement.
- Clerk — authentication and session management.
- Supabase — the database holding accounts, scans, monitoring runs and credit history.
- Polar — payment processing and subscription management.
- PostHog — product analytics.
- Airtable — a second store holding account records, scan results, and credit history alongside Supabase, plus waitlist entries.
- Amazon SES — sending transactional email.
- Anthropic, Google, and Perplexity — AI models that analyse the content of the pages you scan.
How AI providers handle your content
Producing a report means sending the content of the scanned page to third-party AI models. We access them through their business APIs, and their own terms govern what they do with what we send. We do not make a training guarantee on their behalf.
Separately, part of what we measure is whether AI search engines already cite you. To do that we send real search-style questions to a live AI search API and inspect the sources it returns. Those questions are about your topic, not about you — we do not send your account details, and the queries are stored alongside the result so any number in your report can be traced back to what was actually asked.
How long we keep it
Scan results and account data are kept while your account is open, because scan history and trend lines are the point of the product. There is currently no self-serve delete button for an individual scan — email us and we will remove it.
Email us from the address on the account to close it, and we delete your account record and associated scans. Payment records are retained by our payment provider where they are required to keep them, and backups roll off on their own schedule.
Your choices
You can request a copy of your data, correction of it, or deletion of your account, by emailing support@linkaudit.app from the address on the account. We do not require a specific form of words.
Analytics cookies come from our analytics providers; blocking them in your browser or using a tracker-blocking extension does not affect any product functionality.
Security
Traffic is served over HTTPS. Database access is restricted by row-level security so one account cannot read another's scans. Credentials for third-party services are held as server-side environment variables and are never exposed to the browser.
No system is immune. If we discover a breach affecting your data we will tell you what happened rather than issue a statement about how seriously we take security.
Changes to this policy
When we add a processor or start collecting something new, we update this page and change the effective date above. Material changes affecting existing accounts are announced by email.
Contact
Privacy questions and data requests: support@linkaudit.app.
Questions about this page: support@linkaudit.app