Privacy Policy
Effective date: April 19, 2026
What we collect
Account data
Name, email address, hashed password, profile image.
Website data
URLs you submit for monitoring, scan results, Lighthouse scores, Core Web Vitals, and generated PDF reports.
Real User Monitoring (RUM)
Performance timing metrics, page paths, device type, browser user agent. No IP addresses are collected or stored in RUM data.
Integration credentials
Optional GitHub personal access tokens, Google service account JSON keys, Slack webhook URLs. These are encrypted at rest and never included in data exports.
Payment data
Billing plan, transaction status, and amount. Full card details are processed exclusively by Paddle and never stored by AuditJet.
Operational logs
Security and abuse-prevention event logs (including IP addresses, endpoint accessed, and event type) retained for up to 30 days, then permanently deleted. IP addresses in these logs are used solely to detect and block malicious activity such as brute-force login attempts and are never used for tracking or advertising.
Legal basis for processing
Contract (Art. 6(1)(b))
To provide the AuditJet service you have signed up for.
Legitimate interests (Art. 6(1)(f))
Platform security, abuse prevention, and improving service quality.
Legal obligation (Art. 6(1)(c))
Compliance with applicable law and fraud prevention.
How we use your data
- Run performance audits and generate reports for your websites.
- Deliver alert emails and Slack notifications based on your preferences.
- Process subscription payments via Paddle.
- Provide account support and respond to your enquiries.
- Maintain platform security, reliability, and fraud prevention.
We do not sell your personal data, use it for advertising, or share it for purposes unrelated to the service.
Third-party sub-processors
| Service | Purpose |
|---|---|
| Paddle | Payment processing (Merchant of Record) |
| Resend | Transactional email delivery |
| Twilio | SMS alert delivery (only if you enable SMS alerts) |
| Google PageSpeed Insights | Website performance audits |
| Google Analytics (GA4) | Aggregate traffic analytics (all pages) |
| OpenAI | AI Fix Blueprints (PRO/AGENCY, opt-in) |
| GitHub | Performance issue creation (optional) |
| Cloudflare R2 | Scan report storage |
| Upstash Redis | Rate limiting and abuse prevention |
| Railway / Vercel | Hosting and infrastructure |
Data retention
Scan and report data is automatically deleted based on your plan:
- Free7 days
- Watchdog30 days
- Pro90 days
- Agency180 days
Account data is retained until you delete your account. Server access logs are deleted after 30 days.
Security measures
- Passwords are hashed with bcrypt (12 salt rounds) and never stored in plaintext.
- Optional two-factor authentication (TOTP): secrets are encrypted at rest with AES-256-GCM and recovery codes are bcrypt-hashed.
- Integration credentials are encrypted at rest using AES-256-GCM.
- All data is transmitted over HTTPS/TLS.
- Session cookies are set with HttpOnly, Secure, and SameSite=Lax attributes.
Your rights (GDPR)
Access (Art. 15)
Request a copy of your personal data.
Rectification (Art. 16)
Correct inaccurate or incomplete data.
Erasure (Art. 17)
Request deletion of your account and all associated data via Dashboard → Settings → Delete Account, or by emailing us.
Data portability (Art. 20)
Download a machine-readable export via Dashboard → Settings → Export Data.
Restriction (Art. 18)
Request we limit processing of your data.
Objection (Art. 21)
Object to processing based on legitimate interests.
To exercise any right, email [email protected]. We will respond within 30 days.
Cookies
AuditJet sets one essential cookie: a session token required for authentication. No third-party tracking cookies are set inside the authenticated dashboard.
Google Analytics (GA4) with IP anonymisation enabled is loaded on all pages (including the authenticated dashboard) to measure aggregate traffic. You can opt out using the Google Analytics Opt-out Add-on.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, the CCPA and CPRA grant you additional rights.
Categories of personal information we collect
- Identifiers: Name, email address, account ID, profile image URL.
- Commercial information: Billing plan, payment status, and transaction amounts (processed by Paddle).
- Electronic network activity: Website URLs you submit, Lighthouse scores, Core Web Vitals, real-user performance metrics. IP addresses are transiently logged in security event records for abuse prevention and deleted after 30 days; they are not stored in RUM or scan data.
- Professional information: None collected.
- Sensitive personal information: None collected.
We do not sell or share your personal information
AuditJet does not sell your personal information and does not share it for cross-context behavioural advertising. Google Analytics (GA4) is used for aggregate traffic measurement across all pages, with IP anonymisation enabled.
Your California rights
- Right to know (§ 1798.100): Request disclosure of categories and specific pieces of personal information collected about you in the past 12 months.
- Right to delete (§ 1798.105): Request deletion of your personal information, instantly available via Dashboard → Settings → Delete Account.
- Right to correct (§ 1798.106): Request correction of inaccurate personal information.
- Right to opt-out of sale/sharing (§ 1798.120): Not applicable — we do not sell or share personal information for advertising.
- Right to non-discrimination (§ 1798.125): We will not discriminate against you for exercising any of the above rights.
- Shine the Light (Cal. Civ. Code § 1798.83): We do not disclose personal information to third parties for their own direct marketing purposes.
To submit a California request, email [email protected] from the address associated with your account. We respond within 45 days. You may also export your data directly via Dashboard → Settings → Export Data.
Contact & complaints
Data controller: Rohan Dhir, operating as AuditJet.
For privacy questions or complaints contact [email protected]. If you are not satisfied with our response you may lodge a complaint with your local data protection authority (e.g. ICO in the UK, or your national DPA in the EU).