Privacy Policy
What we collect, why, who receives it, how long we keep it, and how you can control it. In plain language.
Last updated October 3, 2026 · version 2026-10-03
1. Who we are
[LEGAL_NAME, the company’s registered name: set it in the environment] (“Axidort”, “we”) runs this website and the Axidort scanner. We decide why and how your personal data is used, which makes us the “controller” under the GDPR and the “data fiduciary” under India’s Digital Personal Data Protection Act, 2023 (DPDP Act). Our address is [LEGAL_ADDRESS, the registered address: set it in the environment].
Privacy questions and requests: axidort@gmail.com. Complaints officer (grievance officer): [GRIEVANCE_OFFICER, the person who handles complaints: set it in the environment], at the same address. You can also use the request form below.
2. What we collect, why, and our legal basis
| What | Why | Legal basis |
|---|---|---|
| Account data from Google. Your email address, name, profile picture and Google’s account identifier. We ask Google only for the basic sign-in scopes (openid, email, profile). We never see your Google password and we do not read your Gmail, Drive, contacts or calendar. | Create and run your account, sign you in, show your reports, contact you about your account. | Contract (providing the service you asked for) |
| Your scans. The website address you enter, the result and score, the notes our AI agents write, and screenshots of the public pages the agent visited. | Produce and keep your reports and show your history. | Contract |
| Billing data. Dodo Payments collects your card and billing details. We receive and keep only your Dodo customer reference, plan, subscription status and dates, and the amount, currency and status of each payment. We never receive your full card number. | Give you the plan you paid for, show your billing page, keep records for tax and accounting. | Contract; legal obligation |
| Consent records. Which document and version you accepted, when, how (tick box on the login page, the accept page or checkout), the exact wording shown, a one-way hash of your IP address and your browser’s user-agent text. | Prove that you agreed and to what, as the law requires us to be able to do. | Legal obligation; legitimate interest |
| Security and usage logs. Actions on the service (sign-in, starting a scan, viewing a report), request identifiers, and your IP address stored only as a salted one-way hash. We do not log the contents of the pages we scan. | Run the service safely, rate-limit, prevent abuse, fix faults. | Legitimate interest (security and reliability) |
| Shared report links. If you press Share, a random link, the time it was made, who made it and how many times it was opened (a number only: no addresses, no browser details). | Let you show a result to people you choose. | Contract (a feature you switch on) |
| Your requests. Anything you send through our forms or email, such as a privacy request, contact request or complaint. | Answer you and keep proof that we did. | Legal obligation; legitimate interest; consent for contact requests |
| Operational alerts. When someone signs up or starts a scan, a short alert (which can include the account email and the domain) goes to a private messaging channel used by our team. | Operate and support the service. | Legitimate interest |
We do not collect sensitive personal data on purpose. Please do not type personal data into the website-address field. Where the public pages we scan contain personal data (for example a name on a contact page), we process it only as a by-product of measuring the site, and only to produce the report.
Sharing is your choice, and limited. A report is private until you press Share. Anyone who has the link can then see that report: the domain, the score and breakdown, the agent’s purchase journey with its screenshots, the product data it read and the static checks. They cannot see your name, email or account, your scan history, or your other reports, and the page is kept out of search engines. You can stop sharing whenever you like: the link then stops working for good. Do not share a link with people you would not want to see that result, and remember that anyone who has it can pass it on.
3. Cookies and similar technologies
- Sign-in cookie (axid_session). Keeps you logged in. Strictly necessary. Up to 30 days, renewed while you use the service.
- Browser identifier (axid_anon). A random value that lets the browser that started a scan claim its report after you log in. Strictly necessary. Up to one year.
- Sign-in flow cookies. Short-lived cookies (10 minutes) that protect the Google sign-in against forgery.
- Analytics. If switched on, we use Plausible, which sets no cookies, keeps no persistent identifier and builds no profile of you across sites or days.
- We use no advertising, tracking or social-media cookies, so there is no cookie banner. Because only strictly necessary cookies are used, they do not need consent under the EU ePrivacy rules.
4. How the AI is involved
To measure a website, our agent browses its public pages and sends what it sees (page text, screenshots) to an AI model provider, currently Google (Gemini) or Anthropic, depending on our configuration. We do not send your name, email or account details to them. The AI’s output is an automated estimate that no person reviews before you see it. It does not produce any legal or similarly significant decision about you. Each provider’s own terms and privacy notice govern its handling of that content.
5. Who receives your data
- Google: sign-in; and, if configured, the Gemini model that reads scanned pages.
- Anthropic: the Claude models that read scanned pages, if configured.
- Dodo Payments: our merchant of record. It sells you the plan, takes payment, calculates and pays tax, issues receipts and handles chargebacks. Dodo is an independent controller of your payment data under its own privacy policy, which you can read at checkout.
- Hosting, database and storage providers that run our servers, under contracts that require them to protect the data.
- Plausible Analytics (aggregate, cookie-free statistics) and our internal alert channel (see section 2).
- Authorities, courts and advisers where the law requires it or to protect our rights. A buyer if the business is sold, bound by this policy.
We do not sell your personal data and we do not share it for cross-context behavioural advertising. We have no “data brokers” as recipients.
6. Transfers outside your country
Our providers process data in several countries, including India and the United States. When personal data leaves the EU/EEA, the UK or another region with transfer rules, we rely on the safeguards those rules allow, such as the European Commission’s standard contractual clauses or an adequacy decision. Ask us if you want a copy of the safeguards.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, reports, screenshots, domain list | While your account exists. We erase them within 30 days of a valid erasure request (section 9), except what we must keep. |
| Billing records (customer reference, plan, payments) | As long as tax and accounting law requires, which can be up to 8 years. They are not used for anything else. |
| Consent records | While your account exists and for 3 years afterwards, to be able to answer a claim. |
| Security and usage logs | 12 months, then purged. |
| Privacy, site-owner and rights-holder requests | 3 years after we close them. |
| Sign-in sessions | Until they expire (30 days) or you log out. |
8. Your rights
Depending on where you live you have the right to: know what we hold about you and get a copy (access); correct it; have it erased; restrict or object to some uses (including uses based on our legitimate interest); receive it in a portable format; withdraw consent at any time without affecting what happened before; not be subject to a decision based solely on automated processing that significantly affects you (we make none); and, under the DPDP Act, nominate someone to exercise your rights if you die or cannot. California residents have the rights to know, delete, correct, and to opt out of sale or sharing (we do neither) and will not be treated worse for using their rights.
We answer within 30 days. We may ask you to prove who you are so that nobody else can get your data. To withdraw consent to the Terms and Privacy Policy, use the form below: the account will no longer be able to run scans or buy plans, and you can ask us to erase it.
Complaints. Please write to our grievance officer first; we aim to resolve complaints within 15 days and always within 90. If you are not satisfied you can complain to your data-protection authority (in the EU/EEA, your national authority; in the UK, the Information Commissioner’s Office; in India, the Data Protection Board of India once you have used our grievance process; in California, the California Privacy Protection Agency).
9. Children
The service is for people aged 18 or over, and we ask you to confirm that when you sign up. We do not knowingly collect data from anyone younger. If you think a child has an account, write to us and we will erase it.
10. Security
We use encrypted connections, store session tokens only as one-way hashes, store IP addresses only as salted hashes, and limit who can reach the data. No system is perfectly secure. If a breach puts your rights at risk we will tell you and the authorities as the law requires.
11. Google user data
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use your Google profile only to sign you in and run your account, and we never use it for advertising or sell it.
12. Changes
If we change this policy in a way that matters, we change its version date above and ask every account to accept it again before it can run scans or buy a plan. Earlier versions and your consent records are kept. Read the Terms of Service and the Disclaimers too.