This policy is available in nine languages. The Turkish text controls where required or permitted by applicable law; all other translations are provided for information.
Controller and scope
The data controller for Sitelemetry is EGENİL TELEFERİK MÜHENDİSLİK TEKNİK İŞLETME DANIŞMANLIK LİMİTED ŞİRKETİ, Cumhuriyet Mah. 1227 Sk. No: 11, Altınordu, Ordu, Türkiye.
This policy applies to sitelemetry.com, the Sitelemetry console, audit services, APIs, support and related integrations. It explains our processing under Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK) and, where applicable, the GDPR and other privacy laws.
Information we collect
We collect information directly from you, from your authorized integrations, from normal use of the service and from publicly reachable technical surfaces of targets you submit.
Remote MCP disclosure. When you connect Codex, Claude or another MCP client, that client provider receives the tool request and returned audit result as part of your conversation under its own terms and privacy policy. Sitelemetry receives only the MCP traffic and tool arguments your client sends, not the rest of your AI conversation. The client receives audience-bound OAuth tokens; it does not receive your Sitelemetry password, account API key or stored Google integration tokens. When you use a performance tool, Sitelemetry sends the verified target URL to Google PageSpeed Insights, and Google independently fetches that URL to produce the performance result. MCP audits may be used only for websites you own or are expressly authorized to assess.
Claude Directory audit records. The Claude Directory profile accepts only the exact target covered by the authenticated workspace's verification record. For an MCP audit, Sitelemetry may store the workspace and user identifiers, submitted and normalized target URL, target-verification reference, requested tool and options, status and timestamps, usage or quota entries, public technical observations, scores and metrics, passing checks, findings, evidence, remediation text, error codes, and the identifier used to provide an authenticated report link. Performance records may include Lighthouse or CrUX measurements and the inspected or final URL reported by Google PageSpeed Insights. Sitelemetry accepts those measurements only when that URL remains within the safe host-and-port boundary established by its preflight checks.
Purposes and legal bases
- Contract: create accounts, run requested audits, generate reports, provide subscriptions, integrations and support.
- Legitimate interests: secure the service, prevent abuse, troubleshoot, measure reliability and improve defensive audit quality without overriding your rights.
- Legal obligation: maintain financial, tax, fraud-prevention and compliance records and respond to lawful requests.
- Consent: operate optional connections or communications where consent is the appropriate legal basis. You may withdraw consent without affecting earlier lawful processing.
Marketing is off by default, and we do not send a marketing message without a separate opt-in. Account and usage CRM fields support customer service, service administration and aggregate product analysis under the applicable non-marketing legal bases. Only separately opted-in users may enter marketing segments or receive personalized campaign content; suppression is rechecked immediately before every delivery, and CRM tags and notes are visible only to authorized Super Admins. Campaign email is delivered through a separate email provider and, when a promotion requires it, Paddle creates a separate single-use discount code for each recipient from the minimum campaign and recipient reference needed. The code is not technically bound to that recipient's account and should not be shared.
We do not use private audit content or Google user data to train general-purpose artificial intelligence models, and we do not sell personal information.
Audit targets and third-party information
Audits may observe public server responses, DNS and certificate data, exposed technologies, page content and similar technical information. You must have authority to submit the target and avoid supplying unnecessary personal data or secrets.
Some modules send the target or limited technical inputs to configured engines or APIs to perform the requested analysis. Reports may contain information about website operators or systems. You are responsible for using and sharing those reports lawfully.
Service providers and disclosures
We share only the information reasonably needed with service providers and other recipients that support hosting and infrastructure, email delivery, payments, authentication, analytics integrations, customer support and authorized audit engines. Examples include AWS for hosting, email infrastructure providers, Paddle for web billing and Google for the integrations you connect.
Depending on their role, recipients process information on our instructions or under their own terms and applicable data-protection obligations. We may also disclose information when required by law, to protect users or the service, in a corporate transaction with appropriate safeguards, or at your direction. We do not disclose audit data to unrelated advertisers.
Google API Services data
Separately, if you choose Sign in with Google, we use only the basic openid email profile identity scopes to receive your stable Google account identifier, verified email address and display name solely to create or sign in to your Sitelemetry account. This login does not request Google API service data, and Google access, refresh and identity tokens are not retained.
When you choose to connect Google Search Console, Sitelemetry requests only the read-only OAuth scope webmasters.readonly. We access verified property URLs and permission levels, plus clicks, impressions, click-through rate, average position and query, page, device, country and date dimensions. We also process the access and refresh tokens needed to maintain the connection.
We use this information only to provide user-initiated, read-only Sitelemetry dashboards, reports and exports. Sitelemetry does not create, edit or delete data in your Google services. Raw, aggregate, anonymized or derived Google user data is not sold; used for advertising, credit or lending, surveillance or unrelated profiling; transferred to data brokers or advertisers; used to train or improve generalized artificial-intelligence or machine-learning models; or sent to third-party AI or ML services for model training. Providers that host or operate Sitelemetry process only the minimum data needed to provide and secure these features.
OAuth tokens are never exposed to client-side JavaScript. They are encrypted and authenticated with AES-256-GCM and kept in an HttpOnly connection cookie that uses Secure and SameSite protections in production and is bound to the signed-in Sitelemetry account. Google report data is processed on demand and is not retained as a separate long-term copy; we may retain non-content usage counts needed to enforce plan limits.
You can disconnect the Google Search Console integration in Sitelemetry at any time, which removes the corresponding tokens from the active Sitelemetry connection and replaces or clears the connection cookie. That cookie expires no later than 30 days after it is set unless it is replaced. You can also revoke Sitelemetry from your Google Account connections. To request deletion of your Sitelemetry account or related data, contact support@sitelemetry.com.
Sitelemetry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Payments
Paddle acts as Merchant of Record for purchases made on the Sitelemetry website and collects payment, billing and tax information under its own privacy policy. Sitelemetry does not receive full payment-card details.
To verify access, prevent fraud and reconcile renewals, cancellations, refunds and expiry, our server receives and retains limited Paddle data such as the environment, product and plan identifiers, transaction or subscription references, status and relevant dates. We do not use this information for advertising or tracking.
Retention and security
After verified account-deletion confirmation, we lock account access and revoke active sessions immediately. Operational personal data covered by the request is deleted or anonymized within 30 days. Production backups expire naturally within 30 days and are not restored to active product use.
We retain only category-specific, minimally necessary records where a legal obligation still applies: billing and tax records, necessary commercial correspondence, authorized-audit evidence and pseudonymized deletion proof. They are isolated, access-restricted, not used for the product and kept only for the applicable period, up to 10 years under the current policy. We delete or anonymize them when the relevant legal ground or period ends.
Claude Directory audit and report records are retained for up to 30 days. An authenticated report URL remains stable only during that window and expires with its report. A usage-reconciliation journal normally has a six-hour active lease and is deleted immediately when its reservation is committed or released; release-only recovery stores no audit results or report details. A commit-pending journal may keep sanitized, bounded report output and its billing snapshot only within the report window. At expiry, Sitelemetry permanently removes the report output and details and retains only the billing snapshot and minimal reconciliation metadata until reconciliation succeeds; during a storage or usage-service outage, that minimal form may remain beyond the report window to prevent a lost or duplicate usage entry. Commercial usage ledgers are retained on a rolling basis for 14 months. Privacy-redacted authorization receipts for protected scans are retained for 400 days by default.
CRM and marketing records are purpose-limited and kept only as long as needed to document choices, operate a permitted campaign, prevent repeated or prohibited delivery, resolve support or meet legal duties. A minimal suppression record may remain where needed to honor an unsubscribe, bounce, complaint or account deletion; records are deleted or anonymized when that purpose and any applicable legal period end. CRM segmentation does not retain a raw IP address.
We use access controls, password hashing, encrypted transport, secret separation, request validation, audit logging and other technical and organizational safeguards appropriate to the service. No system is completely secure, so please report suspected incidents promptly.
International transfers
Some providers may process data outside Türkiye or your country. Where required, we rely on adequacy decisions, contractual safeguards, explicit consent or another lawful transfer mechanism. The location of a submitted audit target may also determine where public technical requests are received.
Your privacy rights
Subject to applicable law, you may ask whether we process your data and request access, correction, deletion, restriction, portability or objection; withdraw consent; and complain to the competent data-protection authority. KVKK data subjects also have the rights described in Article 11, including learning the purpose and recipients of processing and seeking remedy for unlawful processing.
You can manage the optional marketing permission in account settings or withdraw it at any time through the one-click unsubscribe link in a campaign email. Withdrawal applies to future marketing sends and does not affect prior lawful processing. You may also exercise the rights above through our privacy contact; a bounce, complaint or account-deletion suppression may continue only as needed to prevent further delivery.
Send requests to support@sitelemetry.com. We may verify identity and authority before acting. You can also request account and connected-token deletion. We will respond within the period required by applicable law.
Children, updates and contact
Sitelemetry is a business service and is not intended for children under 18. We do not knowingly collect their personal information.
We may update this policy to reflect product, provider or legal changes. We will change the effective date and provide additional notice for material changes where required.