Legal
Privacy policy.
How we handle personal data — from Berlin, in line with the EU GDPR.
Last updated: 21 February 2026
Draft — not yet binding. These pages are pre-launch placeholders. The registered company name, address, VAT ID and contact details will be finalised before public launch.
Who is responsible
The controller responsible for processing your personal data within the meaning of the EU General Data Protection Regulation (GDPR) is the provider named in our Imprint. You can reach us for any privacy matter at hello@webreport.example.
This policy explains what we collect, why, on what legal basis, how long we keep it, and the rights you have. It is a pre-launch draft and the final version will document each practice in full.
What we collect
We deliberately collect as little as possible. Depending on how you use Sight, we process:
- Scan data — the URLs you submit and the publicly accessible content of the pages we crawl. Raw page snapshots are deleted after processing; test results and scores are retained to render your reports.
- Purchase data — your email address and Stripe transaction references. Card details never touch our servers and are handled entirely by our payment processor.
- Account data (subscriptions) — email address, password hash, and records of your sites, scans and usage.
- Technical data — IP address, browser and device information, and server logs, used to secure the service and diagnose problems.
Why we process it, and our legal bases
We process personal data to run a scan you requested, to deliver and bill the reports you buy, to operate accounts and scheduled monitoring, and to keep the service secure and reliable.
Processing rests on the performance of a contract with you (Art. 6 (1)(b) GDPR), our legitimate interest in operating and securing the service (Art. 6 (1)(f) GDPR), and — where required, for example for non-essential communications — your consent (Art. 6 (1)(a) GDPR), which you can withdraw at any time.
Processors and third parties
We share data only with service providers that process it on our behalf under data processing agreements, and only as far as needed to run the service. We do not sell personal data.
- Stripe — payment processing and billing.
- Resend — transactional email such as report links and receipts.
- OpenRouter — AI-model probes; only public page content is sent, never your account data.
- Cloud hosting — infrastructure to store and serve your data.
International transfers
Where a provider processes data outside the EU/EEA, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses, together with additional safeguards where appropriate, so that your data remains protected to the standard required by the GDPR.
How long we keep it
Raw page snapshots are deleted immediately after a scan is processed. Report results are retained while your account is active or as needed to make your reports available. Purchase and invoice records are kept for as long as statutory retention periods require. When data is no longer needed, we delete it.
Cookies
We set no advertising or cross-site tracking cookies. A single first-party cookie is used to keep you signed in to an authenticated session. Any analytics we run are privacy-preserving and used only to improve the product.
Your rights
Under the GDPR you have the right to access, rectification, erasure, portability, and restriction of your personal data, and the right to object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time with effect for the future.
To exercise any of these rights, email hello@webreport.example. You also have the right to lodge a complaint with a supervisory authority — for us, the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
Data security
We protect your data with encryption in transit, access controls, and monitoring. No method of transmission or storage is completely secure, but we work continuously to safeguard your information and to limit who can access it.
Changes to this policy
We may update this policy to reflect changes to the service or the law. When we make material changes we will update the date above and, where appropriate, notify you by email.
Questions about this document? Email hello@webreport.example.