Privacy
What PageAudit keeps about the people who use it, for how long, which infrastructure it shares, and how to request access or deletion.
Who processes the data
PageAudit is run by the same house as the other products listed in the footer. Requests about personal data go to contato@pageaudit.online and are answered by e-mail.
What this product keeps
- Each audit stores the URL, the score, the findings and the summary the checks produced (title, metas, headings, link counts, redirect chain, robots.txt and sitemap status, response headers without Set-Cookie) — not the page's full HTML.
- Without an account, a guest token in your browser owns your tabs and audits; with an e-mail sign-in, the e-mail, the sign-in codes (short-lived, hashed) and the session.
- A hash of the network of origin on each audit and on the daily quota, so the free allowance is per network, not per person.
- Shared reports (/r/…) are public to anyone with the link until you unshare them.
- Pay-per-call payments (x402) settle on the Base network, which is public by design; here we keep the transaction reference and the amount for reconciliation and accounting.
- Prepaid credit: the token is stored only as a SHA-256 hash with its balance and movements; whoever holds the token holds the credit, and it cannot be recovered by e-mail.
- Contact: your message, the e-mail you give and the reply go through Amazon SES to the product mailbox.
For how long
- Audits are kept: closing a tab does not delete its history, so the timeline of a URL survives; deletion requests are handled by e-mail.
- Turnstile verifications expire after 15 minutes; sign-in codes within minutes.
- Per-network rate-limit counters (guest, contact, sign-in code) expire on their own within minutes or hours.
- Payment and credit records stay as long as accounting requires.
Infrastructure and third parties
- Cloudflare hosts the Worker, the database (D1), files (R2) and DNS; traffic passes through its edge, which keeps operational logs for a limited time and cookieless Web Analytics.
- Cloudflare Turnstile confirms a form was sent by a person; it does not identify who.
- Amazon Web Services (SES) sends transactional e-mail on behalf of the product.
- jsDelivr serves interface libraries (Bootstrap) from its CDN.
- Google Analytics 4 measures pages and events only after the first interaction (tap, click or key), with ad storage denied and no sale or sharing for advertising.
- PayAI (x402 facilitator) verifies and settles payments on the Base network; the paying wallet is yours, and its address is public on-chain.
- The audited page is fetched by our Worker the way a crawler would; the site you audit sees that request coming from Cloudflare, not from you.
Cookies and browser storage
- When you sign in with e-mail, the session lives in a cookie; without an account, a guest token stays in your browser and identifies what you created.
- Screen preferences (theme, filters) stay in the browser's local storage and never leave it.
- There is no advertising cookie and no cross-site tracking.
IP address
To limit abuse, the IP address goes into a hash with a secret salt and the country comes from the Cloudflare edge; the raw IP is not stored, except where this page says otherwise.
Your rights
You can request access, correction or deletion of what exists about you by writing to contato@pageaudit.online. We answer within the terms of the Brazilian data protection law (LGPD) and, where it applies, the GDPR. Data from public sources (official registries) stays at the source; only the copy here is removed.
Last updated: 5 September 2026.