Privacy
What PageAudit keeps about the people who use it, for how long, which infrastructure it shares, and how to request access or deletion.
Who processes the data
PageAudit is run by the same house as the other products listed in the footer. Requests about personal data go to contato@pageaudit.online and are answered by e-mail.
What this product keeps
- Each audit stores the URL, score, findings and summary (title, metas, headings, links, redirects, robots.txt and sitemap status, JSON-LD, discovery-file observations and response headers without Set-Cookie). The page HTML and discovery-file bodies are not stored.
- A page you put under the daily watch: the e-mail the alert goes to (the account's, or another one you type), when we last checked it and when we last wrote to you. Switching the watch off stops the checks and the e-mails.
- A hash of the network of origin on each audit and on the daily quota, so the free allowance is per network, not per person.
- Shared reports (/r/…) are public to anyone with the link until you unshare them.
- Account: e-mail, password, passkeys, sign-in codes and sessions are kept by the account system shared by our products, in its own database — this product keeps only the account id next to what is yours. Without an account, a signed guest token stored in your browser owns what you create; signing in moves it to your account.
- Pay-per-call payments (x402) settle on the Base network, which is public by design; here we keep the transaction reference and the amount for reconciliation and accounting.
- Prepaid credit: the token is stored only as a SHA-256 hash with its balance and movements; whoever holds the token holds the credit, and it cannot be recovered by e-mail.
- Contact: your message, the e-mail you give and the reply go through Amazon SES to the product mailbox.
For how long
- Audits are kept: closing a tab does not delete its history, so the timeline of a URL survives; deletion requests are handled by e-mail.
- Turnstile verifications expire after 15 minutes.
- Sign-in codes expire within minutes; the account session ends when you sign out or when it expires.
- Per-network rate-limit counters (guest, contact, sign-in code) expire on their own within minutes or hours.
- Payment and credit records stay as long as accounting requires.
Infrastructure and third parties
- Cloudflare provides hosting, storage, distribution and service protection. Traffic passes through its infrastructure, with operational logs retained for a limited time and cookieless Web Analytics.
- Cloudflare Turnstile confirms a form was sent by a person; it does not identify who.
- Amazon Web Services (SES) sends transactional e-mail on behalf of the product.
- Interface libraries (Bootstrap) are served from the product's own domain, not from a third-party CDN.
- Google Analytics 4 measures pages and events only after the first interaction (tap, click or key), with ad storage denied and no sale or sharing for advertising.
- PayAI (x402 facilitator) verifies and settles payments on the Base network; the paying wallet is yours, and its address is public on-chain.
- The audited page is fetched by our Worker the way a crawler would; the site you audit sees that request coming from Cloudflare, not from you.
Cookies and browser storage
- When you sign in, the account session lives in an HttpOnly cookie on this domain; without an account, the guest token stays in your browser and identifies what you created.
- Screen preferences (theme, filters) stay in the browser's local storage and never leave it.
- There is no advertising cookie and no cross-site tracking.
IP address
To limit abuse, the IP address goes into a hash with a secret salt and the country comes from the Cloudflare edge; the raw IP is not stored, except where this page says otherwise.
Your rights
You can request access, correction or deletion of what exists about you by writing to contato@pageaudit.online. We answer within the terms of the Brazilian data protection law (LGPD) and, where it applies, the GDPR. Data from public sources (official registries) stays at the source; only the copy here is removed.
Last updated: 21 September 2026.