The short version
There is no sign up, so there is nothing to sign up with. There is no database. There is no analytics script on any page of this site and no advertising tag in your browser.
One cookie is set when you give us your email address on a free report. It holds that address, so you are not asked again, the rest of a free report opens for you, and the sites you scan later from the same browser are recorded against it.
We do advertise, and we do tell Meta when somebody asks for a report or buys one. That happens from our server, using a hash of the email address you gave us, which Meta matches against its own accounts. Nothing is placed in your browser for it. You can turn it off on the Your Privacy Choices page, and a Global Privacy Control or Do Not Track signal from your browser turns it off too.
The list below is not a summary of what we keep. It is all of it.
The domain you scanned
When a domain is scanned, the result is written to a file on our server so that reloading a report does not re-run the scan and quietly change a report someone already shared. The file is named for the domain and holds the check results taken from its public pages.
It is replaced when it is more than an hour old, so a report is never more than an hour stale. A failed scan is deliberately not kept at all.
The buying questions derived from a site are cached the same way, per domain, alongside a plain counter of how many derivations ran that day so that one visitor cannot loop it.
Every scan started from the scan form also adds one line to a log file on our server: the domain, the time, the version of the terms accepted for that scan, and the email address this browser gave us, if it gave one. Each line is deleted 24 months after the scan.
Your email address, if you paid
Stripe asks for it at checkout so it can send you a receipt. It reaches us once, in the message Stripe sends our server to say the payment succeeded, and it is used for two things: sending you the link to the report you paid for, and, as a SHA-256 hash, telling Meta that an advertised purchase happened. The advertising section on the cookies page describes that in full, and the Your Privacy Choices page turns it off.
It is not stored in a database, because there is not one. Buying a report does not put you on a mailing list. The address exists in our email provider's log of that message, and in Stripe's record of the payment.
If you arrived from a Meta ad, the click ID from that link is also stored on the Stripe checkout session, so that our server can attach it to the purchase report described above. It identifies the advertisement, not you, and it is discarded with the session.
Your email address, if you asked us to send you a free report
A free scan runs without an email address. A form on the free report asks for one, if this browser has not given one already, and typing an address there sends you the link to that report through our email provider, Resend. You can read the score and every failing check without giving it.
It also adds the address to our mailing list, and the form says so where you type it. The list is held by Resend and Klaviyo, and it is used to send occasional notes about how AI search picks businesses. Every note carries a one-click unsubscribe link. The address is never sold, rented or passed to anyone else.
Klaviyo also stores the domain you scanned with the address, and each site you scan later from the same browser.
We count how many of these a single internet address asks for in a day, so that nobody can use the form to send mail to other people. The count is kept as a number against a scrambled form of the address and is replaced the next day.
Your report link
A report opens only with a key in its link. For a free report, the key is a signed statement that this browser ran the scan of that domain, and it stops working after 30 days. For a paid report, it is a signed statement that the domain was paid for at a given tier, and it stops working after a year. There is no row anywhere recording either.
Each key is signed so it cannot be edited into a key for another domain. Anyone you send the link to can read that report, so treat it as you would a document rather than a password.
Payment
Payment is handled entirely by Stripe on Stripe's own pages. Your card number never touches this site and we never see it.
Stripe keeps what it needs under its own privacy policy at stripe.com/privacy. What comes back to us is the answer to one question, whether the payment succeeded, along with the domain it was for and the address to send the report to.
The AI search engines, on a Complete report run
A Complete report sends the derived buying questions to Anthropic, OpenAI and Google and records what came back. They receive the questions and the answers, not your email address and not your payment.
Those questions are written from your site's public pages, so nothing private is in them.
Sites we read on your behalf
We request pages the way any visitor's browser would, and our requests appear in that site's logs as ordinary traffic. We keep the measurements taken from a page, not a copy of the page.
Your browser
The one thing this site stores in your browser is which theme you chose, light or dark, so the page does not flash the wrong one on your next visit. It is kept in your browser's own storage, it never leaves your machine, and it is not a cookie, so it is never sent to us.
When you submit a scan or an email address, the page loads Cloudflare Turnstile, a check that a person and not a script sent the request. Cloudflare receives technical information from your browser for that check, under Cloudflare's own privacy policy. It does not load before you submit one of those.
Server logs
Our host records ordinary request logs, including IP addresses, the way every web server does. They are used to see whether the site is working and are not joined to anything else here.
Your rights, and asking us to delete something
If you are in California, the CCPA gives you the right to know what is held about you, to have it corrected or deleted, to opt out of its sharing, and not to be discriminated against for using any of these rights. We do not sell personal information. We share it with Meta for advertising, as described in the short version above, and you can opt out of that on the Your Privacy Choices page. If you are covered by the GDPR, the equivalent rights apply and you may complain to your local authority.
Browser signals. We treat a Global Privacy Control signal and a Do Not Track signal the same way: as a request not to send anything from that browser to Meta. Neither signal changes anything else on this site, because nothing else here tracks you.
To use any of them, write to hello@keigeo.com. A cached scan, a scan log line, and the address on our mailing lists are deleted the day the mail is read. For anything Stripe holds, including your receipt, the request goes to Stripe, and we will point you at the right place if that is easier.
Children
This is a tool for businesses. It is not directed at children, and we do not knowingly collect anything from anyone under 13.
Last updated 2026-09-23.