SiteRescue
← SiteRescue

Privacy

What we collect

  • The URLs you scan, and the results. A scan stores the address, the findings, and the evidence for each one. You can run a scan without an account, in which case the report belongs to nobody and is reachable only by its unguessable link.
  • Your email address, if you sign in. We use magic links, so there is no password — a password we do not hold is a password we cannot leak.
  • Billing records. Stripe holds your card details; we hold only a customer reference, your plan, and what you bought.
  • Messages you send us in a rescue thread.

What we do not collect

No advertising trackers, no cookies for tracking, and nothing sold or shared. We count page views through Vercel Analytics, which records the page and the country and does not identify you or follow you between sites — and a handful of anonymous product events, like a scan started or a plan chosen, counted the same way and never carrying a URL, an email, or anything else that could point back to you or your site.

We do not ask for or store your website builder, hosting, or domain registrar passwords, and there is nowhere in our system to put one.

Keeping the free scan usable for everyone

To stop the free scan being used to flood a site or hammer our own service, we keep a one-way hash of the requesting address — never the address itself — for two days, purely to count how often it has asked. It cannot be reversed back into an IP address and is deleted automatically after that window.

Test messages through your form

When we test a contact form, the message we send arrives in whatever inbox that form feeds. It contains no personal data — it identifies itself as an automated SiteRescue test and gives a no-reply address.

Where it lives

Data is stored with Supabase (EU, Frankfurt) and Vercel. The people we rely on:

  • Supabase — database, accounts and authentication (EU)
  • Vercel — web hosting and serverless functions
  • Fly.io — the scanning worker (Frankfurt)
  • Stripe — payments — card details go to Stripe, never to us
  • Resend — transactional email
  • Vercel Analytics — counting page views — cookieless, and it does not identify you

How long we keep it

Scan reports are kept while your account exists, so you can compare a site over time. Billing records are kept as long as tax law requires. Delete your account and we delete your reports, sites and messages. A scan run without signing in — nobody to ask, nobody to find it again — is deleted automatically after 30 days, unless it earned a certificate that is still standing; our own error logs are kept 30 days, and a Site Watch incident for a year.

Your rights

You do not have to ask us. From your dashboard you can download everything we hold as a single file, and delete your account outright — both immediate, both self-serve.

Two things survive deletion, and both are deliberate. A payment record is kept because tax law requires it, stripped of anything identifying. A certificate is withdrawn rather than erased, because it is public and someone may be relying on it — a proof that silently vanishes is worse for them than one withdrawn honestly.

For anything else, email hello@siterescue.app. If you are in the EU or UK you may also complain to your data protection authority.

Last updated 2 September 2026.