Privacy Policy
Plain English, no dark patterns. This explains exactly what WebsiteSpa collects, why, and who else ever sees it.
Last updated 21 August 2026
The short version
We collect your email address, the website addresses you ask us to analyse, and — if you create an account — a hashed password. We use them to run your audits and scans, to keep you signed in, and to send you the newsletter only if you asked for it. We do not sell your data, we do not run advertising trackers, and we never see your card details.
What we collect
- Your email address — when you create an account, request an audit report, join the AI visibility early-access list, or subscribe to the newsletter.
- Your password — stored only as a salted PBKDF2 hash. We cannot read it, and neither can anyone who obtains the database.
- Website addresses you submit — for audits and AI visibility scans, along with the results we generate. Our crawler reads only pages that are already publicly available on that site.
- Subscription reference — if you subscribe, we store the PayPal subscription identifier so we can confirm your plan is active. Card and bank details never reach our servers; PayPal handles payment entirely.
- Basic technical data — your IP address is used transiently to rate-limit free scans and to protect the admin login from brute force. It is not used to profile you.
How we use it
- To run the audits and AI visibility scans you request, and to show you the results.
- To create and maintain your account, keep you signed in, and apply your free unlocks or PRO access.
- To send you our newsletter and occasional product updates — only to people who gave us their email for that purpose. Every email carries a one-click unsubscribe, and we honour it immediately.
- To answer you when you contact support.
Who else sees it
We use a small number of processors to run the service. Each receives only what it needs:
- PayPal — payment processing and subscription status.
- Brevo — newsletter delivery. Receives your email address.
- Google — only if you choose "Sign in with Google", to verify your identity and share your email address with us.
- DeepSeek — generates the plain-English analysis in your audit. Receives the technical crawl findings for your website. It does not receive your email address, your password, or your payment details.
- Hostinger — hosts the site and the database.
We do not sell, rent or trade your personal data to anyone, for any purpose.
Cookies and local storage
We run no advertising cookies and no third-party tracking pixels. Your browser's local storage holds only what the site needs to work: your light or dark theme preference, your sign-in token, and a flag noting that you have already dismissed a pop-up. Clearing your browser storage signs you out and resets these.
How long we keep it
Account data stays while your account is open. Audit and scan results are retained so you can revisit them and track changes over time. Newsletter subscribers are kept until they unsubscribe. Ask us to delete any of it and we will.
Your choices
- Unsubscribe — use the link in any newsletter, or email us.
- See what we hold — ask and we will send you a copy.
- Delete it — ask and we will erase your account and associated data.
Email hello@websitespa.net for any of the above. No forms, no hoops.
Security
The site is served over HTTPS. Passwords are salted and hashed. API credentials live in server-side environment variables, never in the pages you download. No system is perfect, but we do not store what we do not need — which is why we never hold card details.
Children
WebsiteSpa is a business tool and is not directed at children under 16. We do not knowingly collect their data.
Changes
If this policy changes materially we will update the date at the top of this page, and tell newsletter subscribers by email.
Contact
WebsiteSpa — hello@websitespa.net. We usually reply within one business day.
