Privacy Policy
Last updated 14 September 2026
What we collect
| What | Why | How long |
|---|---|---|
| Your email address | To log you in and send alerts, and once, a day or two after you sign up, a reminder if you have not added a website yet | Until you delete your account |
| Websites you add | To check them | Until you remove them |
| Check results and history | To show trends and detect changes | 12 months, then deleted |
| A one-way hash of your IP address | To rate-limit the free checker so it cannot be abused | 30 days |
| The time of each check you run by hand, each site you add, and each fix write-up you ask for | To apply the daily limits on each plan, so nobody can use us to flood a website with requests | 2 days |
| Login session | To keep you signed in | 30 days, or until you log out |
| An email address you ask us to send a client report to | To email that report every 30 days, if you switch it on for a site | Until you remove it or delete the site |
| A count of page views, and a daily one-way hash of your IP address and browser | To know how many people visit this website. Counted on our own server; the date is inside the hash, so it cannot be joined up across days into a history of one person | 45 days for the hash. Only the daily total is kept |
| A daily count of what happens at the check box: shown, clicked into, and submitted, and whether it was submitted from our research page or after arriving by one of our ad links | To find out which step people stop at, so we can fix it. No address, no hash and no identifier of any kind is recorded — a date, which of these happened, and a number. Nothing here can be traced to a person, including by us | Kept as a daily total only |
| The campaign tag in the link you arrived by (for example "li-ad"), if it had one and you created your account on that visit | To know whether an ad or a post led to an account. Only the tag we wrote into our own link is kept; nothing is stored in your browser to do this | Until you delete your account |
| The browser description your browser sends (its user agent), saved with each login session | Recorded when you sign in, so a session can be told apart from another one if you ever ask us about a sign-in you do not recognise. Nothing else uses it | Deleted with the session: after 30 days, when you log out, or when you delete your account |
| Your billing country, and your VAT number if you enter one at checkout | Copied from Stripe when you subscribe, to work out how the sale is taxed | Until you delete your account |
| A Slack webhook address, and on the Agency plan the agency name, logo (a link you paste or an image you upload), report colour, and the client name and note you add to a report | To post alerts to your Slack, and to put your name, logo and colour on client reports. An uploaded logo is served from an unguessable address so emailed reports can show it | Until you clear the field or delete your account |
| Your name, email address and message if you use the contact form, and a one-way hash of your IP address | To reply to you | Until you ask us to delete it. It is not deleted automatically, and deleting your account does not remove it |
| Emails you send to any @seensure.com address: your address and name, the subject and the text of the message | To read and answer them, and keep each conversation together | Until you ask us to delete it. It is not deleted automatically, and deleting your account does not remove it |
If you are an agency using SeenSure for clients
When you ask us to email a client report, that address is your data and we are only processing it for you: we use it to send the report you configured and for nothing else, we never contact them about anything else, and we delete it when you remove it or delete the site. We do not sell, rent or share it, and it is not used to train anything.
We do not have a standard data processing agreement yet. If your organisation needs one before it can use us, write to hello@seensure.com and tell us what it has to cover.
If someone sends you a report about your website
Our customers are agencies, and one of them may have asked us to email you a monthly report about a website of yours. If that is why you are here: we hold your email address and nothing else about you — no name, no tracking, no profile, and we never use it for anything but that report.
You can stop it at any time. Reply to the report, or write to hello@seensure.com, and we will remove your address. You do not need an account and you do not have to ask the agency.
If we sent you an email
The table above is about people with an account. If you received a cold email from us and you do not have an account, this is the part that concerns you, and it is short.
The link to our Baseline page in that email ends in ?r= and a random string. It is unique to your copy of the email, so if you open it we can see that your agency did. We store the random string, the time it was first opened, and how many times. That is all the link records. No IP address, no browser or device information, nothing that follows you anywhere else.
| What | Why | How long |
|---|---|---|
| Your email address, the website the email was about, and the subject and text of what we sent you | So we never email the same address twice by mistake | Until you ask us to delete it |
| Whether the email was delivered, bounced (with the reason given) or reported as spam, as reported back by Resend, and whether you replied | To stop writing to addresses that do not work or do not want our email | Until you ask us to delete it |
There is no tracking pixel and we do not know whether you opened the email — only whether you clicked the link, which is something you chose to do. Reply with "no thanks" and we will delete your address and never write again.
What we deliberately do not collect
- No tracking pixel in any email we send, so we cannot tell whether a message was opened or read. A pixel fires when your mail program loads an image, which is not a decision you made.
- No card or bank details. Payment happens on Stripe's own pages; we only store the customer reference Stripe gives us.
- No passwords. We email you a one-time link instead, so there is no password to leak.
- No advertising or analytics trackers, and no third-party cookies. We count page views on our own server, so nothing about your visit is ever sent to anyone else.
- No health, financial, biometric, government-ID or other sensitive personal data. The service has no use for any of it.
- No content from the pages we check beyond what is needed to score them. We store your robots.txt and llms.txt so we can show you what changed — both are public files anyone can read.
Cookies
One cookie, used to keep you logged in. It is strictly necessary for the service to work, contains no personal information, and is not used for tracking. That is why you have not been shown a cookie banner.
Who else touches your data
- Cloudflare — hosting and database.
- Stripe — payments. They handle card details entirely; we never see them.
- Resend — sends our emails.
- Google — email sent to any @seensure.com address, including replies to our emails and support requests, is forwarded to our Gmail inbox.
- Anthropic — if you use the optional plain-English fix explanations, the technical details of that finding are sent to Claude to write the explanation. Your email address is never included, and the feature can be switched off.
That is the complete list. We do not sell, rent or share your data with anyone else.
Your rights
You can export or permanently delete everything we hold from your account settings — immediately, without emailing anyone. If you would rather we did it, write to hello@seensure.com.
If you are in the UK, EU, or a similar jurisdiction, you have the right to access, correct, export, or erase your data, and to object to how we use it. The delete button does all of this instantly.
Children
SeenSure is a business tool and is not intended for anyone under 16.
Changes
If we ever change this in a way that matters, we will email you before it takes effect rather than quietly updating the date at the top.