Privacy Policy

Last updated September 11, 2026

This Privacy Policy explains what PixelPioneer, LLC (“we”, “us”) collects when you use CrawlSpec, why, who can see it, and how long we keep it.

What we collect

  • Account identity: your name, email address, and password (stored as a salted hash).
  • IP address, in two places. First, when an action writes a row to our internal audit log - creating a project, attesting ownership of a domain, an admin changing a project setting, an admin entering or leaving audited support access on your workspace, and starting a subscription checkout. Second, keyed with your account email, in short-lived abuse-prevention rate-limit windows for sign-in, sign-up, and password-reset requests; these windows are pruned automatically and are separate from the audit log.
  • Google Search Console query-level data (search queries, clicks, impressions) for any property you connect.
  • Metadata about the third-party pages a crawl visits - URLs, headers, status codes, and a SHA-256 hash of each page's HTML. We never store the raw HTML of a crawled page.
  • The bytes of any WebSite Auditor export you upload or point us to, until you delete it.
  • Any third-party API credential you add under Integrations (Google Search Console service account, DataForSEO login, Anthropic key), encrypted at rest.

Who can see your workspace content

Only members of your workspace, by default. Our own staff do not have standing access to any workspace's projects, briefs, or crawl data. A platform administrator can reach a specific workspace's content only through an explicit, time-boxed “support access” grant that they must request for that workspace; entering and leaving that grant each write a row to the audit log. Our administrative area otherwise shows workspace metadata only - counts, plan, and status - never your content.

Anthropic and content generation

When you generate a content brief, we send the relevant Google Search Console query text and metrics for that page to Anthropic to produce the brief. We do not use your workspace's content or briefs to produce CrawlSpec's own marketing content.

Retention

  • Google Search Console metrics and audit log entries: kept for the life of the account, with no automatic expiry.
  • Crawl data: pruned automatically to the 5 most recently completed crawl runs per project.
  • Uploaded WebSite Auditor exports: kept until you delete them.
  • A revoked or replaced API credential is kept encrypted and marked revoked - it is never hard-deleted, so we can show you a history of what was connected and when.

See our Data Processing Addendum for the full list of subprocessors that may handle your data on our behalf.

Shared client report links

A report you share generates a link containing an unguessable token. Anyone with that link can view the report, including any Google Search Console query data it contains, so treat it like a password. Every share link carries an expiry date you set when you create it; an expired or revoked link stops working.

Free scans

Anyone can ask us for a free audit of a site at /free-seo-audit, with no account. When you do, we store:

  • Your email address in readable form, but only while one of your reports is still live. We always keep a one-way SHA-256 hash of it, which is what lets an unsubscribe or a deletion keep working after the readable address is gone.
  • The address you asked us to scan, and the domain we derived from it.
  • The exact ownership attestation you agreed to, word for word, with the time you agreed and the version of the Terms shown to you.
  • The IP address and browser user agent of the request, for abuse prevention on an endpoint that makes us fetch a third party's website.
  • Whether you ticked the optional box asking for product email. Ticking it is never required to receive your report.

Retention, and these are the numbers the code enforces rather than an intention: a report stays readable for 14 days and is then deleted; your readable address is removed once no report of yours is live; and a scanned project that nobody claims is deleted 90 days after its last scan. We do not run AI over a free scan, and we never sell or share the address.

Your rights

You can ask us to delete your account and its data. We do not yet have a self-serve delete button for accounts, so we fulfill account deletion requests manually, within 30 days of your request, by emailing legal@crawlspec.dev.

For a free scan there is a self-serve path, and it is the fastest one. Every report email carries a link to a page with two buttons: stop these emails, which suppresses your address for scan email only, and delete my data, which also removes every scan, the record of your address and any project the deletion left empty. The same requests reach us through the chat widget on this site or by email to legal@crawlspec.dev, and we act on them within 30 days. If a site was scanned that is not yours to authorize, the crawler page has a removal request and a self-serve block that needs no account.

Google API Services

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Cookies

We use one category of non-essential cookie: analytics, via Google Analytics. It is set only after you accept it in the cookie banner, and you can change your decision at any time from the “Cookie settings” link in the footer.

Changes to this policy

We may update this policy as the Service changes. The date at the top of this page is when it was last updated.

Contact

Questions about this policy or a data request: legal@crawlspec.dev.