Controller and contact
SiteScoreAI is operated by Petran Emil Laurentiu Persoană Fizică Autorizată, CUI 50305265, F40/4774/2024, Romania. For privacy questions, contact sitescoreai@gmail.com.
This policy applies to the SiteScoreAI website, account dashboard, website-audit service, reports, support communications, and related billing interactions.
Information processed
Information you provide
- Name, email address, password credential, and profile details.
- Public website URLs submitted for preview or full audit, plus any audience, goal, or report context you provide.
- Contact-form messages and support correspondence.
- Plan selection and billing identifiers. Full payment-card details are handled by Stripe and are not stored by SiteScoreAI.
- Optional report-branding assets, cover accent, and report footer text.
Information generated or collected
- Account, subscription, audit-credit, website, report, and product event records.
- Crawled public page content, headings, links, forms, metadata, screenshots, and technical observations needed for an audit.
- Audit findings, category scores, recommendations, evidence references, hypotheses, and processing telemetry.
- IP address, browser/device information, request logs, error data, security signals, and consent preferences.
Purposes and legal bases
- Contract and requested service: create accounts, run previews and audits, produce reports, manage credits, process subscriptions, and provide support.
- Legitimate interests: secure the service, prevent abuse, diagnose errors, measure essential product operations, and improve reliability.
- Consent: load optional analytics and marketing technologies where consent is required.
- Legal obligations: maintain accounting, tax, payment, and compliance records where required by law.
Where processing is based on consent, you may withdraw that consent through Cookie settings. Withdrawal does not affect earlier lawful processing.
Website and AI processing
When you submit a public URL, SiteScoreAI may retrieve several pages, normalize page content, capture screenshots, extract evidence, and send bounded audit inputs to model providers to generate structured findings. Do not submit private, confidential, or personal information through a public page URL or audit context.
Firecrawl supports public-page crawling and screenshot capture. OpenRouter provides access to configured AI models used for evidence extraction, synthesis, and support features. AI-generated output can be inaccurate and should be reviewed before action.
SiteScoreAI does not use customer audit content to promise or infer an actual conversion rate. Findings are directional recommendations.
Service providers
Current service-provider categories include:
- Supabase: authentication, database, and optional report-branding storage.
- Stripe: checkout, subscriptions, billing portal, payment status, and fraud prevention.
- Firecrawl: retrieval and capture of submitted public websites.
- OpenRouter: routing audit and support inputs to configured AI model providers.
- Vercel: hosting, application delivery, and optional consented analytics.
- Google Ads and LinkedIn: marketing measurement only after marketing consent.
- Email delivery infrastructure: contact, support, and operational notifications.
Providers receive only the information reasonably required for their role and process it under their own terms and applicable data protection commitments.
International transfers
Some providers process data outside Romania or the European Economic Area. Where required, transfers should rely on adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. The exact safeguards and provider locations must be confirmed during qualified legal review.
Retention and security
Account and audit data is generally retained while an account is active and as needed to deliver reports, resolve disputes, protect the service, and meet legal obligations. Billing and tax records may be retained for statutory periods. Anonymous preview-security records may be retained for a shorter anti-abuse period.
SiteScoreAI uses access controls, transport encryption, database policies, URL validation, rate limiting, and provider security features. No internet service can guarantee absolute security. Retention schedules and deletion exceptions require legal approval before this draft is published.
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to a supervisory authority. Romanian and EEA users may contact the Romanian National Supervisory Authority for Personal Data Processing.
Send requests to sitescoreai@gmail.com. Identity verification may be required. Some information may be kept where law or legitimate security needs require it.
Changes and contact
Material updates will be reflected by a new effective date and, where appropriate, an in-product or email notice. Questions and privacy requests may be sent to sitescoreai@gmail.com.