SiteLens

1. Controller and contact

The controller determines why and how personal data connected with SiteLens is processed.

2. Scope and service design

SiteLens provides automated technical, SEO, performance, security and accessibility checks for public web pages. It has no user accounts. Audit results remain private by default; a full report is stored on the server only when a user explicitly chooses “Create public link”. Minimal aggregate request statistics may be stored separately as described below.

This policy covers the SiteLens website and its audit API. A website you choose to audit remains subject to its own privacy policy.

3. Information we process

  • Audit input: the public URL you submit, the selected audit mode and the time of the request.
  • Aggregate audit statistics: only the audited hostname, total request count and the first and latest request timestamps. Paths, query parameters and visitor IP addresses are not stored in this statistics table.
  • Public website data: response headers, public HTML, linked pages, DNS records, RDAP domain information, hosting signals and audit findings.
  • Network and security data: your IP address, browser type, request time and similar diagnostic data may be processed by our hosting and security provider, Cloudflare.
  • Local browser data: language preference and up to five recent audit summaries are kept in your browser’s local storage.
  • Optional public report: when you choose “Create public link”, SiteLens stores the normalised hostname, audit report JSON, scores and publication/update timestamps and serves them at a permanent public URL. Submitted paths and query parameters are not included in that URL.
  • Optional analytics: after explicit consent, Yandex Metrica processes page URLs, referrers, device and browser characteristics, approximate location derived from network data, clicks, scrolling, outbound links and Webvisor session replays. Contents entered into SiteLens URL and payment fields are marked for masking.
  • Messages: if you contact us, we process the contact details and content you provide so we can reply.
  • Voluntary support: SiteLens sends you to LHV for EUR payments or displays a public cryptocurrency address. SiteLens does not receive your bank authentication details, card credentials, wallet private keys or seed phrase.

Do not submit private administration links, access tokens, passwords or URLs whose path or query contains sensitive information. SiteLens is intended for publicly accessible sites.

4. Purposes and legal bases

  • To perform the audit you request and return a report — performance of the requested service or steps taken at your request (GDPR Article 6(1)(b)).
  • To protect the service, prevent abuse, diagnose failures and manage capacity — our legitimate interests in operating a secure and reliable service (Article 6(1)(f)).
  • To understand service demand through minimal per-domain and overall request counters and to notify the service administrator of new audit requests — our legitimate interests in operating and improving the service (Article 6(1)(f)).
  • To remember your language and local audit history — necessary service functionality requested by you; this data stays on your device.
  • To create and maintain a public report after you explicitly request it — performance of the requested service and our legitimate interest in providing useful, current technical information about public websites (Articles 6(1)(b) and 6(1)(f)).
  • To understand use of SiteLens through Yandex Metrica and Webvisor — your consent (Article 6(1)(a)). Analytics remains optional and can be withdrawn through “Cookie settings”.
  • To respond to correspondence and comply with legal obligations — performance of the service, legitimate interests or Article 6(1)(c), depending on the request.
  • To make a voluntary project contribution method available when you choose it — actions taken at your request and our legitimate interest in funding operation of the service (Articles 6(1)(b) and 6(1)(f), as applicable).

SiteLens does not use audit data for advertising, user profiling or automated decisions that produce legal or similarly significant effects.

5. Storage and retention

  • Full audit reports may be cached at Cloudflare’s edge for up to 15 minutes.
  • Quick comparison reports may be cached for up to 30 minutes.
  • Failed audit responses may be cached for up to 60 seconds.
  • Reverse-IP results may be cached for up to 24 hours; failed reverse-IP responses for up to 15 minutes.
  • The browser keeps up to five recent audit summaries until you clear history, clear site data or remove them through browser settings.
  • An opt-in public report may be retained while SiteLens operates or until it is removed. It is marked as potentially outdated after 30 days and excluded from the report sitemap and search indexing after 180 days without an update. Exclusion from indexing does not itself delete the stored report.
  • Yandex retains analytics identifiers and aggregated statistics according to its applicable settings and terms. Webvisor session recordings are retained for up to 15 days.
  • Infrastructure security and diagnostic logs may be retained by Cloudflare according to the service owner’s Cloudflare configuration and Cloudflare’s applicable terms.
  • Aggregate per-domain counters and first/latest request timestamps may be retained in Cloudflare D1 while SiteLens operates. They contain no SiteLens visitor account, visitor IP address, URL path or query string.
  • If administrator notifications are enabled, Telegram retains the notification messages according to the administrator’s chat settings and Telegram’s applicable terms.
  • SiteLens does not store bank or card credentials. LHV retains payment information under its own terms. Cryptocurrency transactions are recorded on a public blockchain and may remain publicly visible permanently.
  • Correspondence is kept only as long as necessary to answer the request and meet applicable legal requirements.

Cache entries can expire or be evicted earlier. They are not a permanent archive and should not be treated as a backup.

6. Providers and public data sources

To deliver an audit, relevant input or public technical data may be sent to:

  • Cloudflare — hosting, edge cache, security, DNS-over-HTTPS queries, optional browser rendering of JavaScript websites, public report storage and minimal aggregate audit counters in D1.
  • Yandex Metrica — optional consent-based traffic analytics, click and link maps, bounce measurement and Webvisor session replay through counter 110860777.
  • Telegram — optional private administrator notifications containing the audited hostname, audit mode, cache state and aggregate counters. Visitor IP addresses are not included.
  • LHV LinkPay — optional EUR contributions. LHV presents the available payment methods and processes the payment under its own terms and privacy notice.
  • Public Ethereum network and the contributor’s wallet provider — optional cryptocurrency contributions. Public transaction data can include sender and recipient addresses, asset, amount, transaction hash and time.
  • IANA and RDAP operators / rdap.org — domain registration metadata.
  • The Green Web Foundation — public green-hosting information.
  • Google PageSpeed Insights and Google Web Risk — only when the service owner has configured the relevant API integrations.
  • HackerTarget — reverse-IP lookup, only after you press the neighboring-sites lookup button.
  • ipwho.is — approximate country and city lookup for the audited website’s primary public IPv4 address.
  • The audited website and its hosting providers — they receive the technical fetch made by SiteLens infrastructure.

These providers may process data under their own terms and privacy notices. Do not submit a URL if you are not comfortable with it being shared as required to perform these checks.

7. Cookies and local storage

SiteLens does not set advertising cookies. Necessary local storage remembers your choice. “Preferences only” enables the selected language and local audit history without analytics. “Preferences + analytics” additionally enables Yandex Metrica and Webvisor, which may set _ym* cookies or local-storage identifiers. You can change or withdraw the choice through “Cookie settings”, delete history with “Clear history”, or clear all site data in your browser.

Cloudflare may use strictly necessary security cookies if traffic protection features are enabled. These are used to maintain service security, not by SiteLens for advertising.

8. International transfers

Some providers may process data outside Estonia or the European Economic Area. Where GDPR requires it, the controller relies on an adequacy decision, Standard Contractual Clauses or another valid transfer safeguard offered by the relevant provider. Contact us for information applicable to the deployed service configuration.

9. Your rights

Subject to the GDPR and any applicable limitations, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time.

Because SiteLens has no account system, private browser history and aggregate hostname statistics normally cannot be linked to a particular visitor. Public reports can be located by hostname. We may need reasonable information to verify a deletion or other data-rights request without collecting unnecessary data.

You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the supervisory authority in your habitual EU residence or workplace.

10. Security

We use data minimisation, limited audit-cache periods, transport encryption, request validation and infrastructure security controls. Public-report URLs contain only a normalised hostname. No internet service can guarantee absolute security, so avoid placing secrets or personal data in submitted URLs.

11. Children

SiteLens is a general technical tool and is not directed at children. We do not knowingly request names, contact details or other profile information from children.

12. Changes

We may update this policy when the service, providers or legal requirements change. The current version and effective date will remain available on this page. Material changes will be presented prominently where reasonably possible.