Privacy Policy
Effective date: to be set at launch.
Who we are
CheckWeb is an early-access website security check and scanner. The data controller is the CheckWeb operator; the operating legal entity (planned: an individual entrepreneur in Armenia) will be named here before paid plans launch. Contact: hello@chkweb.com.
What we process
• The URL/domain you submit and the resulting scan results — stored so the public report at chkweb.com/report/<domain> loads instantly and can be re-shared. Reports contain only passive, publicly observable data about the website (no logins, no private content). • Your IP address — used only transiently for rate-limiting (to prevent abuse); it is not part of the report and is not sold or used for tracking. • Aggregated, anonymous usage analytics (page views and a few product events) — no personal profiles.
Third parties
To run some checks we send the submitted domain to Google APIs: PageSpeed Insights (Performance / Core Web Vitals) and Google Safe Browsing (Reputation). Those requests are subject to Google's terms. We do not use these to profile you. Everything else runs on our own infrastructure.
Public reports
A scan creates a stored, public, indexable page at chkweb.com/report/<domain> and an embeddable badge. These show only passive, publicly observable data about the website. To request removal, use the “Request removal” link on the report page or email hello@chkweb.com; on removal the report is taken down (returns 404, de-indexed, and dropped from our sitemap). Owner-controlled hiding after domain verification is planned.
Email alerts (Watch)
If you subscribe to health alerts for a domain (the “Watch this website” form), we store your email address together with that domain in order to email you when the website's health changes (for example a score drop, an expiring SSL certificate, or a new blacklisting). The legal basis is your consent, confirmed by a double opt-in email — we only send alerts after you click the confirmation link. We keep the subscription only until you unsubscribe; every email carries a one-click unsubscribe link (and honors one-click list-unsubscribe), and unsubscribing removes/deactivates the subscription so no further emails are sent. We do not use these addresses for anything other than the alerts you asked for, and we do not sell or share them.
Feature waitlist
Some paid features (continuous Monitor, the Agency plan) are not built yet. If you leave your email on their waitlist, we store your email together with which feature you asked about, for one purpose: to email you once, when that feature launches. The legal basis is your consent. Every message carries a one-click unsubscribe link, and you can ask us to remove your address at any time (hello@chkweb.com). We do not use these addresses for anything else, and we do not sell or share them.
Accounts and the deep scan
The free scan needs no account. An account is created only when you sign in to run a deep scan — the active check of a website you have verified you control. We store: your email address (the sign-in is a passwordless emailed link, so there is no password); the domains you have verified and the token you published to prove it; a record of each permission you granted or withdrew, with its timestamp and the IP and browser it came from (this is the audit trail for why an active check was authorised); and the results of each deep scan, including the specific findings — for example a readable configuration file or an open port — together with the PDF report generated from them. Deep-scan results are PRIVATE: they are readable only inside your account, no public page shows them, and they are excluded from search engines and our sitemap. We store deep-scan findings as metadata (which path, which port, which service) and never the contents of a file we find.
Your data: export and deletion
From your account settings you can download everything tied to your account as a JSON file (your address, verified domains, permissions, and deep-scan results), and you can permanently delete your account. Deletion is immediate and irreversible: it removes your account, your verified domains, your permission records, and every deep-scan result and PDF — including the consent audit trail. We keep nothing back, because in early access there is no paid service or invoice we would be entitled to retain it against. You can also do either by emailing hello@chkweb.com.
Your rights
You may request access to, export of, or deletion of data relating to you, and you may contact us about how your data is handled. If you have an account, export and deletion are self-service in your account settings (see “Your data: export and deletion”); a public report for your domain can be removed via the report page or by email. Email hello@chkweb.com for anything else. If you are in the EU/EEA, you also have the rights afforded by the GDPR, including the right to lodge a complaint with a supervisory authority.
Retention
Stored public reports are kept so their pages stay available, and are refreshed when a website is re-scanned; you can have one removed at any time (see “Public reports”). Account data — your email, verified domains, permissions, and deep-scan results — is kept for as long as your account exists and is erased when you delete it. IP addresses used for rate-limiting are transient and not retained as identifiable records. Analytics data is aggregated and anonymous.
Contact
Questions about privacy: hello@chkweb.com.