Skip to main content

Privacy policy

Last updated: 2026-08-18

Who we are

DigestSEO is operated by Tomi Šeregi, based in Ljubljana, Slovenia. For privacy questions or requests, email . For product support, start on the support page.

This policy covers the digestseo.com website, the public Web Validator app, the free Site Audit, the DigestSEO workspace, the hosted waitlist endpoint, and any DigestSEO-hosted mcp-gsc endpoint. Open-source MCP servers can also be self-hosted. When you self-host, the operator of that deployment controls its data and must provide its own notices.

What data we collect

Do not submit credentials, payment-card information, health information, government identifiers, or other sensitive personal data to the Web Validator or Site Audit. Do not submit private URLs or content that you are not authorized to share. Cloudflare and upstream providers may still process network metadata, such as an IP address, to operate and secure their services.

Why we use the data

We process hosted waitlist details, where received, to provide the notification requested (GDPR Art. 6(1)(b)), and support or privacy requests to respond and protect the service (Art. 6(1)(b), 6(1)(f), or a legal obligation as applicable). Tool inputs are processed to return the report or validation result you requested and to prevent abuse (Art. 6(1)(b) and 6(1)(f)). Google Analytics is optional and is loaded only after your consent (Art. 6(1)(a) and the applicable e-privacy consent requirement). Account data is processed to create and secure your workspace, verify ownership of the email address, and prevent abuse (Art. 6(1)(b) and 6(1)(f)). We do not use tool inputs or account data to train AI models or for advertising.

How we store your data

Legacy waitlist submissions may be stored in a Cloudflare D1 database when that binding is enabled and are forwarded to Formspree for notification. If D1 is unavailable or not configured, Formspree is used as the fallback store. The public Web Validator does not write submitted content, fetched site-audit resources, or results to an application database. Site Audit quota hashes are stored in Cloudflare KV for seven days and are not used for advertising. Hosted mcp-gsc tokens are encrypted before storage in the hosted worker's storage. Account records, password authentication, sessions, email verification, and social sign-in are handled by Clerk; DigestSEO does not receive or store user passwords. Cloudflare, Clerk, Google, GitHub, Formspree, Nu, and other upstream providers may retain operational logs under their own policies.

Third parties and transfers

Depending on the feature you use, data is shared with Cloudflare (Pages, Workers, D1, KV, and security), Formspree (hosted waitlist forwarding), Google (optional Analytics, PageSpeed Insights, OAuth, and Search Console APIs), Clerk (account authentication and verification), and GitHub when you choose GitHub sign-in, the Nu HTML Checker at https://html5.validator.nu/?out=json, and the host of a public page you explicitly ask us to audit. For a hosted Web Validator site audit, the service may request the authorized seed URL, same-origin robots.txt, same-origin XML sitemap documents, and up to eight eligible same-origin public HTML pages in one call. HTML supplied to the Validator or fetched for validation is sent to the Nu HTML Checker; local CSS, SEO, and JSON-LD checks run in the DigestSEO Worker. Focused broken-link checks contact eligible public URLs only when you request them; the site audit does not perform site-wide link checks. The hosted site audit does not authenticate to target sites, access private or local-network addresses, execute JavaScript, recursively follow arbitrary HTML links, or fetch linked assets or stylesheets. Some providers may process data outside the EU/EEA using an adequacy decision, the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses and other safeguards.

How long we keep data

We keep hosted waitlist details only while the requested notification remains useful or until you ask us to delete them, subject to legal obligations and provider backups. We aim to remove application records within seven days of a valid deletion request. Web Validator inputs and results are not kept in an application database. Site Audit quota hashes expire after seven days. Hosted OAuth data is kept while the connection is active or until deletion is requested. Account data is kept while the account is active or until deletion is requested, subject to security logs and legal obligations. Google Analytics retention is controlled by the configured Google property and your consent choice.

Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw analytics consent at any time by choosing “Change analytics preference” below or clearing the consent cookie. Email to exercise a right or request deletion. You may also complain to the Slovenian Information Commissioner (Informacijski pooblaščenec) or another competent supervisory authority.

Cookies and analytics

The site stores one functional consent-preference cookie named digestseo-analytics-consent for up to one year so it can remember your choice. Google Analytics cookies are created only after you allow analytics; they are not used for advertising or ad personalization. Cloudflare may set strictly necessary security cookies or process request metadata to protect the site. The language picker stores your explicit language choice in browser localStorage under digestseo-locale-choice; that preference is not sent to our server and can be removed through your browser settings.

No profiling

DigestSEO does not make automated decisions about you or use the data described here for profiling.

Changes to this policy

We will post material changes here and update the last-updated date.

Contact

Email for privacy requests. For product support, use the support page or the relevant project issue tracker: Web Validator, mcp-gsc, or mcp-geo.