Privacy Policy
Last updated 27 September 2026
This policy explains what personal information Site Medic collects, why, who sees it, and what you can do about it. We collect only what we need to run the service. We do not sell your data and we do not show advertising.
Information you give us
- Account details: your first and last name, email address, phone number, and company name if you give one. You also choose a password, which we store only as a one-way hash, so nobody at Site Medic can read it. We also keep your time zone, your plan, and the date you signed up.
- Projects: the websites you ask us to check, with the settings, rules, sitemap address and ignored checks you choose, and any email addresses you ask us to notify when a crawl finishes.
- Payments: if you buy a paid plan, our payment provider (Stripe) collects your card and billing details on its own pages. We never see or store your card number. We keep a reference to your Stripe customer and subscription, which plan you have, whether it is active, and when the period you have paid for ends.
- Messages: anything you send us when you contact us.
Information we collect when we run the service
- Crawl results. When we check a website for you we store what is publicly visible there: the addresses of its pages and links, the status each returned, redirect paths, page titles, meta and social tags, link text, response headers, the names and security flags of cookies it sets (never their values), certificate and DNS details, and similar technical facts. We do not log in to your site or submit forms, so we do not see anything that is not public. Pages can contain personal data (for example a name in a page title), and if so it is held as part of the results. We keep only the most recent crawls of each project, as many as your plan allows, and older ones are deleted automatically.
- Page Shots. When you ask for screenshots of a web page we keep the address you typed and the pictures taken of that page at each screen size, for you only. We keep your most recent requests for each address, and delete every request and its pictures after 30 days. Pictures show what is publicly visible on the page at that moment.
- A session cookie. When you visit the site we set one cookie that keeps you logged in and protects our forms from forgery. It is needed for the site to work, it is not used to track you, and it is removed when you log out. We use no advertising or analytics cookies and no third-party trackers, and our fonts and scripts are served from our own address.
- Technical logs. Our web server records the address, time and page of each request, as most servers do, and reports errors. We use these to keep the service running and to investigate abuse.
- Abuse protection. To slow down password guessing and automated sign-ups we count recent attempts per email address and per network address. We store only a scrambled hash of each, not the address itself, and delete these records within a day.
How we use it
- to create your account, confirm your email address, and log you in;
- to run the checks you ask for and show you the results;
- to send email that the service needs to work: confirming your address, resetting your password, telling you your password was changed, telling you if a payment for your plan fails, and crawl notifications you turned on. We do not send marketing email;
- to keep the service secure, prevent abuse and fix faults;
- to meet our legal obligations and to protect our rights.
Where the law requires a reason for using personal data, ours is that it is necessary to provide the service you asked for, that we have a legitimate interest in keeping it secure and working, or that the law requires it.
Who we share it with
Only with companies that help us run Site Medic, and only as much as they need:
- our email delivery provider, Brevo, which receives the recipient's address and the text of each email we send;
- our payment provider, Stripe, which handles paid plans: it receives your name, email address and payment details, and tells us whether a payment succeeded. Stripe is responsible for the payment details it collects and has its own privacy policy;
- our hosting provider, whose servers store everything described above.
We may also disclose information if the law or a court requires it, or to protect the safety and rights of people or of the service. If Site Medic is ever sold or merged with another business, your information may move with it, and we will tell you first. Other Site Medic users cannot see your account details or results.
Our providers may be based in, or handle data in, other countries. Where we can, we use providers that protect it to a standard equal to the one described here.
How long we keep it
- Account details: for as long as you have an account, and deleted when we delete the account. Stripe keeps payment and invoice records for as long as the law requires it to.
- Page Shots requests and pictures: up to 30 days, and the older ones for an address are removed as you make new requests.
- Projects and crawl results: until you delete the project, or, for older crawls, until they fall outside your plan's crawl history. Deleting a project deletes all its results.
- Email confirmation and password reset links: they expire (24 hours for confirmation), and we store only a hash of each.
- Abuse-protection records: about a day.
- Server logs: for a limited time, then deleted.
Copies made for backup disappear as the backups are replaced. We may keep what the law requires us to keep for longer.
Keeping it safe
Connections to Site Medic use HTTPS. Passwords are hashed, and confirmation and reset links are stored only as hashes. Access to the systems that hold your data is limited to the people who need it. No method of storing or sending data is completely secure, so we cannot promise absolute security, but we take care and fix problems we find. If a breach affects your data and the law requires us to tell you, we will.
Your choices and rights
You can see and change your name, contact details, time zone and password in your Account settings, and delete any project (with its results) yourself. Depending on where you live, you may also have the right to ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to complain to your data protection authority. To use any of these rights, or to have your account and all its data deleted, contact us at the address below. We may need to confirm it is you first.
The websites we check are not ours, and their owners decide what they publish. If you own a website and want our crawler to stop visiting it, see the crawler page.
Children
Site Medic is for people aged 18 and over. We do not knowingly collect information from children. If you think a child has given us any, contact us and we will delete it.
Changes to this policy
If we change this policy, the date at the top will change. For a change that matters we will tell you by email or in the service before it takes effect.
Contact us
Questions about this policy, or requests about your data, can be sent to crawler@mysitemedic.com.
Terms of Service · The Site Medic crawler · What is Site Medic?
