Is This Site AI?
Privacy Policy
Effective Date: May 16, 2026 | Last Updated: May 18, 2026
Privacy at a Glance We analyze URLs you submit and store derived results (scores, signals) for caching and service improvement. We do not store raw scraped content of third-party sites. If you create an account, we store your email, subscription tier, and Stripe customer ID. We use PostHog for product analytics based on our legitimate interest in improving the Service. You can opt out at any time. We do not sell your personal data to third parties. Scan logs are retained for 90 days, then archived for up to 12 months, then deleted. You can request deletion of your data at any time by contacting us. This policy is governed by GDPR and Estonian law (isikuandmete kaitse seadus).
1. Introduction
Is This Site AI? ("we," "our," or "us") operates isthissiteai.com (the "Service") from the Republic of Estonia. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights under the General Data Protection Regulation (GDPR), the Estonian Personal Data Protection Act (isikuandmete kaitse seadus), and other applicable law.
As an Estonian-based operator, we are subject to GDPR as directly applicable EU law. Our supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).
By using our Service, you agree to the collection and use of information described in this Policy. If you do not agree, please do not use the Service.
2. Who This Policy Applies To
This Policy applies to:
- Anonymous visitors who use the Service without creating an account
- Registered users who have created a free or paid account
- Pro subscribers who have purchased a paid subscription through Stripe
This Policy does not apply to third-party websites that our Service analyses. Those sites have their own privacy policies. For information on how we handle the content of analysed sites, see Section 3.2 and our Terms of Service, Section 5.
3. Information We Collect
3.1 Account and Authentication Data
When you create an account, we collect the following through Supabase Auth:
- Email address
- Password (hashed and managed by Supabase; we never store plaintext passwords)
- Authentication user ID (UUID assigned by Supabase)
- OAuth sign-in data if you authenticate via Google (name, email, profile photo URL as provided by Google)
- Session cookies used to maintain your login state
We also store in our database:
- Your subscription tier (free or pro) and its expiry date
- Your Stripe customer ID (a reference token, not payment card data)
- Account creation timestamp
3.2 Scan and Analysis Data
When you submit a URL for analysis, we collect and store the following derived data:
- The full URL you submitted
- Analysis results: structural score, semantic score, final score, origin label, and confidence level
- Detection signals identified during analysis (stored as structured JSON)
- Signal summary/fingerprint entries shown in the product response
- Identified AI builder tools or frameworks detected on the scanned site
- Whether the result was served from cache
- Scan processing time in milliseconds
- Your user ID (if authenticated) or null (if anonymous)
- Timestamp of the scan
Important: We store derived analysis results, not raw scraped content. The HTML, markdown, and page content fetched during analysis is processed transiently and is not stored in our database. Results are cached by URL for 24 hours to avoid redundant re-scanning.
3.3 IP Address and Rate-Limiting Data
We collect and use your IP address for the following anti-abuse purposes:
- Enforcing anonymous daily usage limits (5 scans per day for unauthenticated users)
- Enforcing per-IP burst rate limits (3 requests per 60 seconds)
- URL-specific abuse controls (repeat cooldown and shared per-URL daily caps)
Your IP address is used to construct pseudonymous rate-limiting keys in Redis (e.g., isthissiteai:anon:<ip>:<date>). These keys expire daily and are not stored in our primary database or linked to your account.
3.4 Cookies and Local Storage
We use the following client-side storage mechanisms:
| Name | Type | Purpose |
|---|---|---|
| anon_scans | HttpOnly Cookie | Tracks anonymous scan count as a fallback when Redis is unavailable. Expires at midnight UTC. Secure, SameSite=Lax. |
| Supabase auth cookies | HttpOnly Cookie | Maintains your authenticated session. Set and managed by Supabase Auth. |
| signin_guard_v1 | localStorage | Tracks failed sign-in attempts to apply a temporary client-side lockout. Stored only in your browser; never sent to our servers. |
We do not use third-party advertising cookies. We do not use cookies for cross-site tracking.
3.5 Billing and Payment Data
We use Stripe to process all payments. We do not collect or store payment card numbers, bank details, or other sensitive financial data on our servers. When you subscribe to a Pro plan:
- Your email is shared with Stripe to create a customer record
- Your Supabase user ID is stored in Stripe's metadata for internal linking
- Your Stripe customer ID is stored in our database
- Stripe sends us webhook events (checkout completed, payment succeeded, subscription cancelled) to update your subscription status
All payment data is governed by Stripe's Privacy Policy at stripe.com/privacy. Stripe acts as an independent data controller for payment processing.
3.6 Analytics Data (PostHog)
We use PostHog for product analytics to understand how the Service is used and to improve it. Our legal basis for this processing is legitimate interests (Art. 6(1)(f) GDPR), specifically our interest in understanding product usage to improve the Service, balanced against your privacy interests. We have assessed that this processing does not override your fundamental rights given the non-sensitive nature of the data and the product-improvement purpose.
Analytics notice: By using this Service, PostHog's SDK automatically collects standard browser metadata (browser type, OS, screen resolution, referrer URL) and usage event data. This occurs on the basis of our legitimate interests. You have the right to object to this processing at any time — see Section 8 for how to exercise this right.
PostHog collects:
- Usage events such as: account sign-up, sign-in, URL analysis submission, analysis completion, results sharing, and Pro plan interactions
- Event properties including: a pseudonymised user identifier derived from your email (used for session continuity and funnel analysis), submitted URL, scan scores, origin fields, subscription tier, and billing lifecycle data
- Unhandled client-side JavaScript exceptions (for error monitoring)
- Standard browser metadata (browser type, OS, screen resolution, referrer) collected automatically by the PostHog SDK
Pseudonymisation: Where technically feasible, we send a hashed or pseudonymised identifier to PostHog rather than your raw email address, to minimise the identifiability of analytics data transferred to a US-based provider.
You have the right to object to this processing at any time. To opt out of PostHog analytics, please contact us at [email protected] and we will configure your account to be excluded. PostHog data is governed by PostHog's Privacy Policy at posthog.com/privacy.
3.7 Application Logs
Our server-side application logs may incidentally contain:
- Hostname (not full URL) of scanned sites
- Scan scores, origin labels, and performance timing
- User subscription tier
- Webhook processing messages and error traces
- Security and rate-limiting events
Logs are used for debugging, security monitoring, and system reliability. Log retention follows our infrastructure provider's (Vercel) standard policies.
4. How We Use Your Information
| Purpose | Information Used |
|---|---|
| Providing the core analysis service | Submitted URL, IP address, user ID (if authenticated) |
| Caching analysis results | URL, derived analysis results, cache version |
| Enforcing usage limits and preventing abuse | IP address, user ID, Redis rate keys, anon_scans cookie |
| Authentication and account management | Email, password hash (Supabase), session cookies |
| Subscription and billing management | Email, Stripe customer ID, Stripe webhook events |
| Product analytics and improvement | PostHog events, email, scan results, tier, billing events |
| Security and fraud prevention | IP address, CSRF tokens, application logs |
| Customer support | Email, account information, scan history |
| Legal compliance and record-keeping | Billing data, account data, as required by law |
5. Legal Basis for Processing (GDPR)
As an Estonian-based operator, GDPR applies directly to all our processing activities. We process your personal data under the following legal bases:
| Legal Basis | Applicable Processing Activities |
|---|---|
| Performance of a contract (Art. 6(1)(b)) | Providing analysis results, managing your account, processing your subscription |
| Legitimate interests (Art. 6(1)(f)) | Rate limiting, abuse prevention, security, fraud prevention, application logs, product analytics (PostHog), service improvement |
| Legal obligation (Art. 6(1)(c)) | Retaining billing records as required by applicable financial and tax law |
We no longer rely on consent as a legal basis for PostHog analytics. Instead, we rely on legitimate interests, and you have the right to object to this processing at any time (see Section 8).
6. Data Sharing and Third-Party Services
We do not sell your personal data. We share your information with third parties only as described below. All third-party processors are required to process data only on our documented instructions and to implement appropriate security measures.
| Service Provider | Category | Data Shared |
|---|---|---|
| Supabase | Auth & Database (EU region) | Email, hashed password, user IDs, scan logs, subscription tier, account metadata |
| Stripe | Payment Processing | Email, Supabase user ID (as metadata). Stripe independently collects payment data as a data controller. |
| PostHog | Product Analytics | Email, usage events, scan metadata, subscription events, browser metadata |
| Firecrawl | Web Scraping (transient) | The URL you submit. Page content processed transiently; not retained by us after analysis. |
| Anthropic Claude | AI Semantic Analysis (transient) | Scraped page content for semantic scoring. Processed transiently; no personal data shared. |
| Upstash (Redis) | Rate Limiting | Pseudonymous IP-based keys for quota enforcement. Keys expire daily. |
| Vercel | Hosting & Deployment | Processes all web traffic. May log IP addresses per standard hosting infrastructure. |
7. Data Retention
We retain your data for the following defined periods in accordance with GDPR's storage limitation principle (Art. 5(1)(e)):
| Data Type | Retention Period |
|---|---|
| Account data (email, tier, Stripe ID) | Until account deletion or upon request, subject to legal holds |
| Scan logs (primary table) | 90 days, then automatically moved to archive |
| Archived scan logs (scan_logs_archive) | Maximum 12 months from original scan date, then automatically deleted |
| Analysis cache | 24 hours per URL entry (auto-expires) |
| Redis rate-limiting keys | 24 hours (auto-expires at midnight UTC) |
| Anonymous quota cookie (anon_scans) | Until midnight UTC (auto-expires) |
| PostHog analytics data | Per PostHog's retention settings (configurable in our PostHog account) |
| Stripe billing records | 7 years, as required by Estonian accounting law (raamatupidamise seadus) and applicable EU financial law |
| Application logs (Vercel) | Per Vercel's standard infrastructure log retention policy |
Scan logs older than 90 days are moved to scan_logs_archive by a scheduled database job (pg_cron). A second scheduled job automatically deletes archived records that are more than 12 months old from the original scan date. This ensures a defined, GDPR-compliant retention window.
8. Your Privacy Rights
8.1 Rights Under GDPR (All EEA/UK Users)
As we are based in Estonia and subject to GDPR, all users have the following rights:
- Right to access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): Request deletion of your personal data (subject to legal retention requirements)
- Right to restrict processing (Art. 18): Request that we limit how we use your data
- Right to data portability (Art. 20): Request your data in a machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests, including PostHog analytics
- Right to withdraw consent: Where any processing is based on consent, you may withdraw it at any time without affecting prior processing
- Right to lodge a complaint: You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or the supervisory authority in your country of residence
8.2 Additional Rights for California Residents (CCPA / CPRA)
- Right to know: Know the categories and specific pieces of personal information we collect
- Right to delete: Request deletion of personal information we have collected
- Right to opt out of sale: We do not sell personal information. No opt-out is needed.
- Right to non-discrimination: Exercising privacy rights will not result in denial of service
8.3 How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or within one month as required by GDPR Art. 12). We may need to verify your identity before processing certain requests.
If you are unsatisfied with our response, you have the right to escalate to the Estonian Data Protection Inspectorate at www.aki.ee or your local supervisory authority.
9. Security
We implement appropriate technical and organisational measures to protect your personal information, including:
- CSRF origin/referer validation on all state-changing API routes
- Row-Level Security (RLS) in Supabase so users can only access their own data
- Server-side service-role authentication for privileged database writes
- SSRF protections to prevent our analysis pipeline from being used to probe internal networks
- Secure, HttpOnly, SameSite cookies for session management
- Stripe webhook signature verification to prevent spoofed billing events
- Idempotency locks on Stripe webhook processing to prevent duplicate billing actions
- TLS encryption for all data in transit
No method of electronic transmission or storage is 100% secure. While we implement commercially reasonable security measures, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate within 72 hours and affected users without undue delay, as required by GDPR Art. 33-34.
10. International Data Transfers
We are based in Estonia (EU) and prefer EU-region data processing where available (e.g., Supabase EU region). However, some of our third-party service providers may process data outside the EEA, including in the United States.
Where data is transferred outside the EEA, we rely on appropriate safeguards as required by GDPR Art. 46, including:
- Standard Contractual Clauses (SCCs, 2021 edition) as implemented by our data processors
- Adequacy decisions by the European Commission where applicable
Schrems II note: Following the CJEU judgment in Data Protection Commissioner v Facebook Ireland (C-311/18, "Schrems II"), transfers to US-based processors (including PostHog, Vercel, and Upstash) rely on the 2021 SCCs supplemented by a Transfer Impact Assessment (TIA). In particular, for PostHog, we take additional steps to minimise transferred data (pseudonymisation of identifiers where feasible) to reduce the risk of US government access to identifiable personal data. You may request a summary of our TIA by contacting us at [email protected].
Please review the privacy policies of our third-party processors (Stripe, PostHog, Vercel, Firecrawl, Google, Upstash) for details of their specific transfer mechanisms.
11. Children's Privacy
Our Service is not directed at children under 13 years of age (or under 16 in the EEA, in line with our Terms of Service minimum age). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take steps to delete it promptly.
12. Contact Us and Data Protection
For questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
Operator: Is This Site AI?
Email: [email protected]
Website: https://isthissiteai.com
Jurisdiction: Republic of Estonia, European Union
Supervisory Authority: Andmekaitse Inspektsioon (www.aki.ee)
We will respond to all privacy enquiries within 30 days.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy
- Post the updated Policy on this page
- Notify registered users via email or a prominent in-app notice at least 30 days before the changes take effect, where required by law
Your continued use of the Service after any changes constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.
Is This Site AI? · isthissiteai.com · [email protected] · Estonia, EU · AKI supervised