Privacy Policy
We built Website Auditor to collect as little data as possible. No tracking cookies, we never sell your data, and auditing on the web needs no login.
- No login needed for web audits
- No tracking cookies
- We never sell or share your data
- All traffic encrypted over HTTPS
Data Collection
We collect minimal data. Auditing a website through our website does not require account creation or login. Programmatic access through our API and MCP server does require an account and API key — see AI Tools & MCP Access below.
Analytics
We use GoatCounter for analytics, which is privacy-friendly and does not use cookies. GoatCounter collects only aggregate usage data without tracking individual users.
Audit Reports
When you audit a website, we temporarily store the report to deliver results. Reports are not permanently retained and are not shared with third parties.
AI Tools & MCP Access
Website Auditor is available as a Model Context Protocol (MCP) server and API, so you and the AI assistants you authorize can run audits programmatically. This works differently from our website, and this section explains how.
Account and API key: Unlike the website, API and MCP access requires a free Website Auditor account and a personal API key. We identify each request by that key so we can apply your plan, enforce quotas, and secure your account.
What we receive: When an AI client calls our MCP tools, we receive only the tool inputs — the website domain you want to audit, and for some tools items such as competitor domains. We do not receive your conversation history, prompts, or any other context from the AI application.
Local vs. hosted MCP server: The MCP server comes in two forms. The local server (installed via npm or as a desktop extension) runs on your own computer: your API key stays in your MCP client's configuration, and only the tool inputs described above ever reach our servers. The hosted endpoint (mcp.website-auditor.io) runs on our infrastructure: your MCP client sends each request, authenticated by your API key, directly to our servers, where it is handled under the same rules as an API request. In both forms we receive the same tool inputs and nothing more, and each request additionally records which of the two entry points it arrived through.
What we store: To operate the service we keep records tied to your API key, including the domains you audit, the resulting scores and reports, request timestamps, and basic usage telemetry (which MCP client and tool were used, whether the call succeeded, and how long it took). We use this to run and secure the service, enforce rate limits, apply your subscription, and improve the product. We do not log your IP address for API or MCP requests.
Terms acceptance: When you start a subscription or free trial, we record that you accepted our Terms — the Terms version, when you accepted, and where (for example, the checkout page). We keep this record for as long as your account exists, as evidence of the agreement; it is deleted with your account.
Retention: We keep this data for as long as your account is active. You can revoke an API key at any time from your account to stop further use of it, and you can request deletion of your data by contacting us at support@website-auditor.io. We never sell this data or share it with third parties.
Third-party AI clients: The AI assistant or host application that connects to our MCP server is operated by a third party (for example, the AI platform you use). Anything you share within that assistant is governed by that provider's privacy policy, not ours.
Chrome Extension
The AI Visibility Score extension puts a site’s score on your browser toolbar. It is a different surface from this website, with different data flows, so this section covers it on its own.
What we receive: the domain of the tab you are on — example.com, never the full address, its path, or its query string — which is what a score is looked up by. Nothing on the page is read: the extension injects no code into the sites you visit, and it is permitted to contact exactly one server, api.website-auditor.io. Lookups are cached for 60 seconds per domain, so moving between tabs does not repeat them.
This applies signed out as well. Already-scored domains are served anonymously, so if the toolbar badge is on, a domain lookup reaches us whether or not you have an account.
How to stop it: turn off Show badge on toolbar in the extension’s Settings. With the badge off the extension makes no passive lookups at all — it stops before the network call, not after it.
Scans: a scan only ever starts when you open the extension’s panel yourself. The passive lookups behind the toolbar icon cannot trigger one, and they never spend from your allowance.
What stays in your browser: your API key and your preferences are held in Chrome’s synced storage, which means they travel to your other signed-in Chrome installations if you use Chrome Sync. The 60-second lookup cache lives in session storage and is discarded when you close the browser. Neither is readable by the websites you visit.
Your API key: sent only to api.website-auditor.io, as a request header. The extension refuses redirects outright, so the key cannot be forwarded to another server even if one were to ask.
Connecting without pasting: if you press the connect button in the member portal, the extension collects your key for you the next time you open it, so the key is never shown on screen or put on your clipboard. That one request carries your sign-in session cookie for api.website-auditor.io instead of an API key — it is how we know the request is yours — and it goes to that same single server, with redirects refused as above. It only happens when you have asked for it: with no pending request from the portal, the extension is told there is nothing waiting and does nothing. Pasting a key by hand still works exactly as before.
Once a request reaches us it is handled exactly as described under AI Tools & MCP Access above — the same records, the same retention, and the same commitment never to sell it or share it.
Data Sharing
We do not sell your data. We do not share audit results with third parties. We do not use tracking cookies.
Security
All communications with Website Auditor use HTTPS encryption. We take reasonable measures to protect the integrity of our service.