LEGAL
Privacy Policy
Plain English, no fine-print surprises. This page covers what ReadableByAI collects when you run the free scan, request an audit, or configure customer-owned crawler monitoring, why it is processed, where it goes, and how long it is kept. Last updated6 September 2026.
What we collect
The domain you ask us to scan
When you run the free scan, our server fetches the homepage of the domain you type in — once with a normal browser user-agent, once each with the 12 AI-crawler user-agents we test — and analyzes the raw HTML and robots.txt it gets back. The result is held in server memory for up to 24 hours, keyed by the domain, so a repeat scan of the same domain returns the cached result instead of re-probing it. This cache is not a database — it lives inside the running server process and is cleared automatically, including on every deploy.
Your IP address, briefly, for abuse prevention
We track how many fresh scans an IP address has requested in the last 10 minutes (capped at 5) so the scanner can't be used to hammer someone else's site. That record lives in server memory only, is never written to a database, and rolls off once the 10-minute window closes.
Your email address — only if you submit a business inquiry
The free scan itself never asks for your email. If you request the Verified AI Search Audit or submit a data-partnership inquiry, we send your email address, the inquiry type, and any company or scanned-domain field you chose to provide to PostHog, our analytics and event-capture provider, as a single event so Alex can follow up. We do not collect payment information at that step.
Your email address and the domain you ask us to watch — free Watch plan
If you use the free Watch feature on a scan result, we store the email address and domain you give us so we can send the alerts you asked for. Nothing is watched until you click the confirmation link in the one email we send — an unconfirmed request is automatically discarded after 48 hours. Once confirmed, we scan the domain on the same weekly schedule as paid subscriptions, but only email you when access changes (a crawler that could reach the domain becomes blocked, or a blocked crawler recovers); Watch never sends a routine weekly digest. Every Watch email, including alerts, carries a one-click unsubscribe link that needs no login — clicking it immediately stops future emails and deletes your email address and the watched domain from our records.
Server and hosting logs
Vercel, who hosts this site, keeps standard request logs (IP address, requested path, timestamps, response codes) as part of running any web service — that's Vercel's infrastructure logging, not something our application code writes anywhere. Separately, we filter a stream of those logs — restricted to requests carrying a known AI-crawler user-agent (GPTBot, ClaudeBot, PerplexityBot, and similar) — and forward that subset to PostHog so we can track how AI systems fetch our own pages. That pipeline measures crawler traffic to readablebyai.com; it does not process ordinary visitor traffic and it is not about you.
Customer-owned hosted log streaming
A Vercel customer can configure the hosted endpoint at /logs/hosted to send minimized crawler events into a PostHog project the customer controls. The setup request includes the domain, PostHog Cloud region, and a write-only PostHog project token. Those values are encrypted into an opaque endpoint credential; the application does not create a customer account or database row for them. A separate per-drain secret is shown to the customer and stored only as a hash inside the encrypted credential.
When Vercel calls that endpoint, our function necessarily receives the delivered log batch and processes it in memory. It rejects missing or incorrect drain secrets, rejects log entries whose hostname does not match the configured domain, and drops entries without a recognized crawler user-agent. For a crawler entry, the client IP is compared with a vendor-published network where available. The function then omits the IP, raw user-agent, and query string. It sends only the configured domain, bot token, verification outcome, path, status code, and timestamp to the customer's PostHog project, with PostHog person-profile processing disabled.
The full minimized operational event goes to the customer's PostHog project. The free hosted tier also contributes a smaller domain-level event to ReadableByAI: domain, vendor and bot token, verification outcome, route category, status class, latency band when available, timestamp rounded to the hour, terms version, and a deduplication identifier. ReadableByAI uses that panel to build and commercialize domain intelligence, benchmarks, datasets, reports, APIs, alerts, research, and models. It does not include the client IP, exact path, query, raw user-agent, headers, cookies, referrer, or PostHog token. See the Data Contribution Terms. Removing the Vercel drain stops new deliveries and contributions.
Page-view counting, and what we don't do
We run Vercel Web Analytics, which counts page views so we know which pages get read. It sets no cookies, builds no cross-site profile, and does not fingerprint your device — it records the page, referrer, and coarse details like country and device type, with no identifier that follows you anywhere. That is the only script on this site.
We don't set cookies, we don't run an ad pixel, and there is no third-party advertising or profiling tracker here.
Why we collect it, and how long we keep it
The processing above exists to run the free scan, stop abuse, let Alex respond to audit requests, relay customer-selected crawler events to a customer-owned destination, and build the commercial crawler benchmark panel described above. Visitor-level data is not sold. ReadableByAI may sell or license intelligence and derived outputs built from the contributed domain-level fields.
| Data | Purpose | Retention |
|---|---|---|
| Scanned domain + result | Serve cached results, avoid re-probing | Up to 24h, in memory only |
| Which domain was scanned, and its score and classification (no visitor identifier) | Know which sites people check, and measure sites fixing themselves over time | Kept as aggregate operational data |
| Your IP address | Rate-limit abuse (5 scans / 10 min) | Up to 10 minutes, in memory only |
| Email + optional company/domain (business inquiries only) | Let Alex follow up with you | Until you ask us to delete it |
| Email + watched domain (free Watch plan) | Send the alerts you asked for | Deleted when you unsubscribe, or automatically if never confirmed within 48h |
| AI-crawler request logs (our own site only) | Measure crawler traffic to our pages | Kept as aggregate operational data |
| Hosted drain delivery and customer operational event | Relay crawler telemetry to the customer's own PostHog project | Processed transiently by ReadableByAI; retained under the customer's PostHog settings |
| Contributed domain-level crawler event | Build and commercialize crawler intelligence and benchmarks | Retained while useful; future collection stops when the customer removes the drain |
Who processes it
We use a small number of processors to run this service:
- PostHog — our PostHog project receives your email, inquiry type, and optional company or scanned domain if you submit an audit or data-partnership inquiry, minimized crawler events for readablebyai.com, and the contributed domain-level benchmark event for free hosted monitoring. It also receives one event per scan recording the domain that was scanned and its result. That event is keyed to the domain, not to you: it carries no IP address, no cookie, and no visitor identifier, and PostHog person profiles are disabled on it, so it cannot be tied back to the person who ran the scan. The customer operational event separately goes to the PostHog Cloud project and region selected by that customer. The application does not forward raw client IPs in any of these events.
- Vercel (United States) — hosts the site, runs the scan as a serverless function, and generates the standard request logs described above.
- OpenAI and Perplexity — queried only as part of a paid Verified AI Search Audit engagement, to sample how those systems answer business/topic search prompts (for example, "best project management software"). Those API calls carry prompt text and the audit client's domain — never a website visitor's personal data.
We do not sell visitor-level data or original customer log batches. ReadableByAI may sell or license commercial outputs derived from the contributed domain-level crawler panel, as disclosed at setup and in the Data Contribution Terms.
Your rights — access, correction, deletion
Wherever you're located, you can ask us what we hold on you, ask us to correct it, or ask us to delete it — including the kinds of rights described under the EU/UK GDPR and the California CCPA/CPRA. We try to honor the same request from anyone, regardless of where you live, rather than gate it by jurisdiction. In practice, what we hold on you is usually your email address and an optional company or domain from a business inquiry. Email alex+privacy@midnightdev.dev and we'll handle it directly — this is a small, single-operator service, so requests are actioned by a person, not a self-serve portal. Hosted monitoring may also leave us with contributed domain-level crawler records. A domain owner can request removal with reasonable proof of control; aggregate outputs and trained model parameters that can no longer reasonably be separated may remain.
Cookies and tracking opt-out
There's nothing to opt out of here in the usual sense — this site sets no cookies and runs no tracking script in your browser, so there's no consent banner because there's nothing for one to gate. If you'd rather not be recorded at all, the free scan doesn't require it: simply don't submit the audit or data-partnership inquiry form, which are the only steps on this site that send identifying contact information anywhere.
Where this is operated from
ReadableByAI is operated from the United States, by Alex Bouchard. If you reach us from outside the US, your information is processed in the US by us and by the processors listed above.
Changes to this policy
If this policy changes, we'll update this page and move the "last updated" date at the top rather than edit it silently. We don't expect that to happen often — this is a small service that collects very little.
This is a plain-English policy, not legal advice; it has not been reviewed by counsel.