Legal

Privacy Policy

No cookies, no ad networks, no data sales. Here is the rest.

Last updated: 12 August 2026

Who we are

This site is operated by Isla Studio, the data controller. For anything in this policy — including access, correction, or deletion — contact [email protected].

What we collect, and why

When you run an audit

You do not need to give us your name or email to run an audit. When you submit a website address, we store:

  • the website address you entered, and the address it resolved to after redirects
  • the business type you selected
  • the date and time of the audit
  • the resulting scores and findings

This record holds no name or email address. If you go on to request the full report, that request stores a reference to the audit — which links the two. Audit records are kept for 90 days.

Your results page has its own link and no password on it. Anyone who has the link can open it, so treat it as public.

Keeping the tool available

The audit tool is free and open to anyone, so we cap how often one visitor can use it. We use your IP address as a short-lived counter key — a count of recent requests, not a log of what you did:

  • up to 10 audits per hour, and separately up to 10 report requests per hour
  • both counters are deleted one hour after your last request

We rely on our legitimate interest in keeping the service available and preventing abuse (GDPR Art. 6(1)(f)).

The three-audit limit

After three audits in a day, we ask you to request a report before running more. To do that we count your audits against your IP address for 24 hours, and once you have submitted the form we store a marker against your IP for 30 days that lifts the limit.

We should be straight about this one: it is a commercial limit on a free tool, not a security measure. The legal basis is our legitimate interest in offering the tool free of charge as a source of enquiries (GDPR Art. 6(1)(f)). You can object to it — see your rights below.

When you request the full report

If you fill in the report form, we collect and store:

  • your name, email address, and — on the results page — your phone number; these are required
  • your business name, and any notes, if you choose to give them
  • the website address you audited, the business type, which page you submitted from, and a reference to the audit you ran
  • your IP address, the country it resolves to, and the date and time

We use this to prepare and send you the report you asked for, and to follow up about it. The legal basis is that the processing is necessary to take steps at your request before entering into a contract (GDPR Art. 6(1)(b)). These records are kept for 12 months.

Who your data is shared with

We do not sell your data, and we do not share it with advertising networks. Two companies are involved in running this site:

  • Cloudflare, Inc. — hosts the site, serves it, and stores the audit and report records described above, acting as our processor.
  • Google — in two separate ways. When you run an audit, the website address you submitted is sent to Google's PageSpeed Insights API to measure loading speed; your name, email, and IP address are not sent. Separately, this site loads its font stylesheet from fonts.googleapis.com, and as with any external request your browser makes, Google receives your IP address.

Cloudflare and Google are US-based. Transfers outside the EEA rely on the European Commission's standard contractual clauses and the EU–US Data Privacy Framework.

Cookies, analytics, and what sits in your browser

This site sets no cookies of its own, and there is no consent banner because none is required.

We do not currently run analytics on this site — no page-view counting, no visitor measurement of any kind. When we do, it will be Cloudflare Web Analytics: cookieless, no fingerprinting, no tracking across other websites, aggregate numbers rather than individuals. This page will be updated to say so before that is switched on.

One thing is stored in your browser: when you unlock a results page, we save a list of unlocked audit IDs in your browser's local storage so you do not have to unlock the same result twice. It stays on your device, is never sent to us, and you can clear it any time by clearing your browser data.

Cloudflare may set a small number of strictly necessary security cookies (such as __cf_bm) to distinguish humans from bots. These are exempt from consent requirements.

How long we keep things

DataKept for
Audit results90 days
Report requests (name, email, phone, IP, country)12 months
Audit-limit marker (IP)30 days
Daily audit counter (IP)24 hours
Hourly rate counters (IP)1 hour after your last request

Each of these is deleted automatically when its period expires, and we do not copy the data anywhere else. One exception worth naming: if our storage is briefly unavailable, a report request may be written to Cloudflare's server logs instead so that it is not lost. Those logs are kept on Cloudflare's schedule, not ours.

Your rights

If you are in the EU or UK, you have the right to:

  • access the personal data we hold about you
  • have it corrected if it is wrong
  • have it erased
  • restrict or object to how we use it
  • receive it in a portable format

Email [email protected] and we will deal with it within one month. You do not need to give a reason to have your data deleted.

You also have the right to lodge a complaint with your national data protection authority. In Spain this is the Agencia Española de Protección de Datos.

Security

The site is served over HTTPS only, with HSTS enforced. Audit requests are rate-limited, and we block audit requests to private and internal network addresses. We do not collect or process payment card details anywhere on this site.

Changes

If we change how we handle data, we will update this page and the date at the top.

Powered by Isla Studio

Home Contact Privacy