Privacy
In short: there are no accounts or passwords, we do not store raw IP addresses, and a report is visible only to those who have its link.
What we store
- The address of the checked site and the results: check results, the AI agent's steps, screenshots and text snapshots of the public pages it opened.
- A hash of the IP address of whoever started the check: SHA-256 with a secret salt. We use it to limit the number of checks (at most 3 per hour from one address); the IP itself cannot be recovered from it.
- An e-mail address — only if you left one yourself: so that the AI agent checks the remaining scenarios of your site, or to hear about the launch of monitoring. It is stored with the check it came from; we do not send newsletters.
- Technical logs of the check — to find errors and to confirm that the bot did not submit forms.
What we do not store
- Raw IP addresses, visitors' cookies, login data.
- Personal data from the checked sites: the bot types only test data into forms and submits nothing.
Who sees the reports
A report opens by its direct link — there is no public list of reports. You can share the link, and then anyone who has it will see the report. A badge with the site's latest score is available at an address like /badge/example.com.svg.
How the data is used
Check results, agent steps and screenshots are stored without a time limit: they make up anonymous statistics on how ready websites are for AI agents, and we use them to improve the AI agent and the methodology. Only the report at a particular link is shown publicly: the score, the recommendations, the agent's steps and screenshots.
Text snapshots of pages — what the AI model saw at each step — are not exposed in the report or through the API and are erased automatically after 90 days.
How the bot works and how to opt your site out is described on the AgentReadyBot page.