Privacy Policy

Last updated: 6 October 2026

1. Introduction

AuditCrow is operated by 4D Services ("we", "us", "our"). This Privacy Policy explains how we collect, use, and protect information when you use auditcrow.com (the "Service"). We are committed to protecting your privacy and handling your data transparently.

2. Information We Collect

Scan data: When you submit a URL for scanning, we store the URL and the resulting report data (scores, issues, page analysis) under a randomly generated scan ID. We also record each scan request (the URL you entered, the time, and the scan it returned).

Abuse-prevention identifiers: With each scan and scan request we store a one-way, salted hash of your IP address and, where available, of a random device ID that your browser keeps in local storage. We never store the raw IP address or device ID. We use these hashes only to enforce scan limits and to investigate abuse. They are kept with the scan records they belong to (see section 4).

Report email: If you ask for the full version of a scan report, we email you a link to it. We store your email address against that scan, together with the exact consent wording you agreed to and when you agreed to it, and we note when you open the link so we know the address is yours. By ticking the box you also agree that we may send you the occasional email about AuditCrow. You can unsubscribe at any time using the link in every email, and your reports will still work. Our email provider is Resend, which sends our emails and holds our mailing list, and our database provider is Supabase, which stores the records above. Both act as processors on our behalf. When you open your full report we may ask AI assistants (Anthropic's Claude, OpenAI's ChatGPT and Google's Gemini) a general question about businesses like yours in your area, and we use Anthropic's Claude to analyse the public content of the page you scan. We send them only public website content and a general question such as the type of business and town, never your email address or other personal details. We keep your email address until you ask us to remove it.

Waitlist email: If you choose to join our waitlist, we collect your email address and your marketing consent preference.

Technical data: Our hosting provider keeps standard server logs, which may include IP addresses, browser type, and referring pages. We use them for service monitoring and security.

3. How We Use Your Information

  • Scan reports: To generate, store, and display your website health report.
  • Waitlist: To notify you about AuditCrow product updates and new features, only if you have given marketing consent.
  • Rate limiting: To prevent abuse, we limit free scans to 5 per IP address, 3 per device, and 3 per scanned domain each day, with an overall cap of 300 scans a day across all users. These counts use the hashed identifiers described in section 2.
  • Service improvement: To understand usage patterns and improve the Service.

4. Data Retention

We do not store reports permanently. Scan results are retained on our side for up to 90 days - within that window a repeat scan of the same domain returns the same report - and a copy stays available in the browser you ran the scan in. Waitlist email addresses are retained until you request removal. You can request deletion of your data by contacting us.

5. Data Sharing

We do not sell, rent, or trade your personal information. Note that scan reports are keyed to the scanned domain: anyone who scans the same domain within the retention window sees the same report. We may share anonymised, aggregated data for analytical purposes.

6. Cookies

For details on how we use cookies, please see our Cookie Policy.

7. Your Rights

Under applicable data protection laws (including UK GDPR), you have the right to:

  • Request access to the personal data we hold about you.
  • Request correction or deletion of your personal data.
  • Withdraw your marketing consent at any time.
  • Lodge a complaint with the Information Commissioner's Office (ICO).

8. Security

We implement appropriate technical and organisational measures to protect your data, including SSRF protection, rate limiting, and restrictive database access policies.

9. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the most recent revision.

10. Contact

For privacy-related enquiries, please contact us via 4D Services.

Join the waitlist

Be first when scans reopen

Scans are paused for a moment. Join the waitlist and we'll tell you when they're back.

We'll email you when free scans are back