Privacy Policy
Last updated 2026-09-09. Operated by The Infrastructure Agent. Contact: chris@theinfrastructureagent.com.
This policy describes what getcitedby.ai actually does with information, as implemented in the service today. It is written against the code, not against an aspiration. If a data flow changes, this page changes with it.
1. What we collect
| Information | When |
|---|---|
| The website address you submit | Every scan. Required — it is what the scan examines. |
| The scan result: readiness score, group scores, which checks passed or failed, and a timestamp | Every scan. |
| Private scan intelligence: submitted root domain, scan type, score or result status, profile summary, coverage summary, and standardized issue summaries | After a saved scan succeeds. Kept privately for up to 90 days for service analytics, event coaching, and product planning. This log does not collect names, emails, IP addresses, or browser/session identifiers. |
| Contact details you send directly to us | Only when you contact us outside the scanner. The current scanner does not invite or store contact details for report delivery. |
| Your IP address | Used while the request is being handled, to enforce rate limits. See section 5. |
We do not ask for and do not collect payment details, government identifiers, or any special-category data. There are no user accounts and no passwords.
2. Why we use it
- To run the scan you asked for and return the report to your browser.
- To prevent abuse of the service and of the paid third-party search API it calls.
- To understand, in aggregate, which checks sites commonly fail, so the scoring model can be improved.
We do not sell personal information, and we do not share it with advertisers or data brokers.
3. Who else processes it
We use these providers to run the service. They process data on our behalf, or receive it as an unavoidable consequence of your browser loading the page.
| Provider | What it receives |
|---|---|
| Cloudflare | Hosts and serves the whole service. Handles every request, including your IP address, and stores the rate-limit counters and the page cache. |
| Cloudflare Turnstile | When new event access requires verification, its widget checks browser signals and receives your network address. We validate its one-time proof server-side. Admission attempt counters use a keyed digest of the network address; proof records store a digest, not the proof itself. |
| Google (Sheets) | Legacy operational records may contain scan summaries. The current scanner flow does not write contact details or consent records for report delivery. |
| Brave Search | Only used if you run the Brave Search Presence Check. We send search queries built from the scanned site's domain and business name. Your name, email and phone are never sent to Brave. |
| Cloudflare Web Analytics | If the zone has Cloudflare Web Analytics enabled, Cloudflare may inject its own measurement beacon into the served page and receive your IP address, user agent, page URL and browser timing data. It does not receive what you type into the form. |
4. How long we keep it
- Scan and lead records: 12 months from the date of the scan, then deleted. This deletion is carried out as a periodic operational task; the spreadsheet does not expire rows on its own.
- Private scan intelligence: up to 90 days. This compact internal log retains the root domain, scan type, score or result status, and standardized issue summaries for service analytics, event coaching, and product planning. It does not include names, emails, IP addresses, raw evidence, or browser/session identifiers.
- Rate-limit and admission counters: automatic. Depending on the safety control, current windows range from minutes to 24 hours, and their counters expire automatically after the applicable window. Event-admission counters use a keyed digest of the network address rather than storing the raw address. These counters are not copied into scan reports.
- Cached page content: 30 days. This is the HTML of scanned public websites, not information about you.
If you ask us to delete your details sooner, we do it on request rather than waiting for the 12 months to run out.
5. Rate limiting and your IP address
Each request's IP address is used to count requests against a short fixed window, so that one visitor cannot exhaust the service or the paid search API for everyone else. The counter key contains the IP address and expires automatically. The IP address is not written into the scan record and is not used to profile you.
6. Access, correction and deletion
Email chris@theinfrastructureagent.com to ask for:
- a copy of what we hold about you,
- a correction to it,
- its deletion, or
- withdrawal of any prior contact consent.
Because there are no accounts, we locate records by the email address you submitted — please write from that address, or tell us what it was. We aim to respond within 30 days. There is no charge.
7. Security
What is actually in place:
- The site is served over HTTPS only, with a content security policy and the associated protective response headers.
- API credentials are held as encrypted platform secrets, not in the source code.
- Everything the scanner reads from a third-party website is rendered as text, never as markup, so a hostile page cannot execute code in your browser through our report.
- Requests are rate limited, and internal and diagnostic endpoints are disabled in production.
- The current scanner flow does not collect contact details for report delivery.
No service can promise perfect security, and we do not claim any certification or audit we have not undergone.
8. Cookies and analytics
Access-code redemption sets a signed, HttpOnly session cookie so this browser can retain scan access. New event admission may use the Cloudflare Turnstile verification widget described above; it loads only when the configured access gate is opened. We do not run advertising pixels or store your access code in browser local storage. Cloudflare Web Analytics, if enabled at the zone, may inject its measurement beacon as described above.
9. Children
This is a tool for website owners and is not directed at children. We do not knowingly collect information from anyone under 16.
10. Changes to this policy
If this policy changes, the "last updated" date above changes with it. Where a change materially affects how we use information you have already given us, we will say so on this page, and where we hold your email address and have your consent to contact you, we will tell you directly.
11. Contact
Privacy questions, access requests and deletion requests: chris@theinfrastructureagent.com. This is the fastest and the only monitored route.