1. Information We Collect
We collect the minimum information needed to provide the service:
- Email address: collected when you sign in via magic link. Used solely for authentication and transactional emails.
- URLs you submit: when you run a scan, the URL you provide is sent to the Anthropic Claude API for analysis. We store the URL alongside your scan results.
- IP address: logged temporarily for rate limiting and abuse prevention. Not linked to your account or stored beyond that purpose.
- Payment information: billing is handled entirely by Stripe. We do not store or have access to your card number, CVV, or full payment details. We retain only your Stripe customer ID and subscription status.
- Scan results: the visitor simulation output generated for each URL you submit is stored in our database and associated with your account. For Pro and Agency plans, this includes accessibility audit data: DOM structure analysis, colour contrast measurements, form field accessibility metadata, and interactive element properties used for WCAG compliance checking. All data is derived from the publicly accessible page you submit.
- Website analytics: with your consent, we use Google Analytics 4 to understand how visitors find and use the site: pages viewed, the channel you arrived from, buttons clicked, scroll depth, and conversion steps such as starting a scan, signing up, or starting checkout. Visitors in the UK, the EEA and Switzerland are asked first. Until you accept, no analytics cookie is set and no identifier is used; Google may still receive anonymous signals without a cookie or identifier, which it uses to estimate totals. Elsewhere, analytics is on by default and you can switch it off at any time from the Cookie settings link in the site footer. We never send your email address to Google. For signed-in users we send a one-way scrambled identifier instead, so your activity can be grouped across devices without identifying you to Google. Google's advertising features and Google Signals are switched off.
- Conversions confirmed by our server: when analytics is allowed for you, our server may also send Google Analytics a small number of confirmed events (a completed purchase, a new account, a finished scan), joined to the same analytics session. This keeps the numbers accurate when a browser extension blocks the tracking script. It never happens if you declined analytics.
- How you found us: when you sign in or start a checkout, we record where your first visit came from (the referring site, campaign tags in the link, and the page you landed on) so we can tell which channels bring customers. It is sent only with a request you make yourself, and it is stored in a cookie only if analytics is allowed for you.
- Product usage by customers: when you are signed in, we keep a record of the actions you take inside the product, such as running a scan, marking a fix done, publishing or exporting a report, editing your tracked questions, or a client opening a report you shared. It also records which screens you open, how long each one is in active use (only while the tab is visible and you have interacted with it in the last minute), and what you open to read, such as expanding a move, opening a competitor's placements or sorting a table. It does not record what you type or where your pointer moves. This is how we support your account, measure whether the product is working for you, and spot problems early. It is stored in our own database, sets no cookie, is never sold or shared, and is not used for advertising.
- Session recordings: with your consent, we record browsing sessions (mouse movements, clicks, and page content) to diagnose usability issues, using PostHog on EU servers. Recordings mask password fields and do not start until analytics is allowed for you.
2. How We Use Your Information
- To provide and operate the WhyIQ service.
- To send magic link sign-in emails via Resend (transactional only; no marketing without explicit opt-in).
- To enforce rate limits and prevent automated abuse of the scanning engine.
- To process payments and manage your subscription through Stripe.
- To improve the product and the site. We review aggregated analytics to understand how people find WhyIQ and where they get stuck, and customer product-usage records to support accounts and improve features.
- To understand how the free AI Radar check and the free page scan are used. These are the only parts of WhyIQ you can use before you have an account, so we record which screens of the free result you open, how long you spend reading them, and whether you go on to a paid screen. Those records are attached to the check or scan itself, not to you, until the moment you create an account. We do not record the text you type or your pointer movements.
- To measure which marketing channels bring customers, including revenue by first-visit channel, calculated in our own database.
3. Data Sharing
We share data only with the third-party services required to operate WhyIQ. We do not sell your data.
- Anthropic: URLs you submit and their associated content are processed by the Claude API to generate visitor simulations. Anthropic's privacy policy applies to data sent to their API.
- Stripe: payment processing. Stripe receives your email address and billing information to manage subscriptions. Their privacy policy applies.
- Resend: we use Resend to deliver magic link emails. Your email address is passed to Resend for this purpose only.
- Google (Google Analytics 4): website analytics, only when analytics is allowed for you. Google acts as our processor. Data may be transferred to the USA under the EU-US Data Privacy Framework and its UK Extension, and is kept for 14 months. Google's privacy information applies.
- PostHog: session recording and, for a transition period, a copy of our product analytics events, only when analytics is allowed for you. For signed-in users, PostHog receives your user ID and email to link activity to your account. Data is processed on PostHog's EU servers. Their privacy policy applies.
- Railway: our infrastructure is hosted on Railway. Application data, including your scan results, resides on Railway-managed servers.
- DataForSEO: when you use our AI search visibility features (Radar), we query DataForSEO to measure how AI search engines and traditional search results reference your domain and your competitors. We send the domains and search queries being tracked. No account email or payment data is shared. Their privacy policy applies.
The current list of sub-processors that may handle your data:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Anthropic | Page analysis and visitor simulation | USA |
| Stripe | Payment processing | USA / EU |
| Resend | Transactional email delivery | USA |
| Google (Analytics 4) | Website analytics, with consent | USA / EU |
| PostHog | Session recording and product analytics, with consent | EU |
| Railway | Application and database hosting | EU |
| DataForSEO | AI and search visibility measurement | USA / EU |
4. Data Retention
- Scan results are retained for 90 days from the date of the scan, then permanently deleted.
- Email address is retained while your account is active. Deleting your account removes it.
- IP addresses are automatically removed from scan records after 90 days. This runs as an automated daily job; no manual request is needed.
- Product usage records and report view records are kept for 25 months, then deleted, so we can compare how an account uses the product year on year.
- Free check and free scan usage records made before you had an account are kept for 90 days, then deleted. They are held against the check or scan, not against a person. If you go on to create an account, the records from that check become part of your account history and follow the 25-month rule above.
- Google Analytics data is kept by Google for 14 months.
- Purchase records are kept as financial records. If you delete your account, the amount and date are kept but your identity is removed from them.
- Magic links expire 15 minutes after they are issued and cannot be reused. Expired links are purged within the hour.
These retention periods are enforced automatically by a scheduled daily cleanup job, not by manual review.
5. Your Rights
You have the right to:
- Request deletion: email [email protected] and we will delete your account and all associated data within 30 days.
- Export your data: request a copy of your scan history, product usage records and purchases by emailing us.
- Change your analytics choice: use the Cookie settings link in the site footer at any time. Declining removes our analytics cookies from your browser and stops both browser and server-side analytics for you.
- Manage email preferences: signed-in users can turn individual email categories (product updates, blog, scan notifications, marketing) on or off from their account settings. Marketing emails also include a one-click unsubscribe link, and you can contact us directly to opt out.
6. Cookies and Browser Storage
We set no advertising cookies. Strictly necessary storage keeps you signed in and protects the free scan. Analytics cookies are set only when analytics is allowed for you: after you accept in the UK, the EEA and Switzerland, or by default elsewhere until you switch it off from the Cookie settings link in the footer.
Strictly necessary
- Session cookie (
whyiq_session): set server-side when you sign in. HttpOnly (not accessible to JavaScript), Secure in production, 30-day TTL. Used exclusively to keep you authenticated. Deleted on sign-out. - Device ID (
whyiq_device_id, localStorage): a randomly generated token stored in your browser's localStorage. Used solely to enforce the one free scan limit for signed-out visitors and prevent abuse of the scanning engine. It is never linked to your identity, never sent to third parties, and contains no personal information. You can clear it by clearing your browser's site data. - Scan you ran before signing in (
whyiq_anon_scan, cookie, 30 days): holds the id of a scan you ran while signed out, so it is saved to your account when you sign up. - Your cookie choice (
whyiq_consent_v1, localStorage, andwhyiq_consent, cookie, 12 months): remembers whether you accepted or declined analytics, so we do not ask again and our server can respect your choice. - Sign-in handoff (
whyiq_auth_evt, cookie, 2 minutes): tells the page you land on after signing in whether you created an account or signed back in. It is deleted as soon as it has been read. - Upload temp data (sessionStorage): if you upload an HTML file for analysis, the file contents are held in sessionStorage only for the duration of the browser tab session and cleared immediately after the scan is submitted. Nothing is persisted beyond the tab.
Analytics (only when allowed)
- Google Analytics (
_gaand_ga_*, 13 months): distinguish visits and sessions so page views and conversions can be counted. - First visit (
whyiq_ft, 90 days): how you first arrived (referring site, campaign tags, landing page), used to attribute sign-ups and purchases to a channel.
Declining analytics deletes these cookies. Session recording runs in memory and stores nothing on your device.
7. Contact
Questions about this policy or your data? Email us at [email protected]. We aim to respond within 5 business days.