Privacy policy
Last updated
We collect only what the service needs. We show no ads, we do not sell personal data, and analytics runs only if you accept it. This page explains the details, one activity at a time.
Read as Markdown ↗01 / Privacy policy
Who is responsible
The controller of your personal data is:
PawlicaWeb Mateusz Pawlicaul. Rolna 37/18, 43-100 Tychy, PolandPolish tax ID (NIP): 6472568432Email: [email protected]Phone: +48 572 645 250For anything about your data, email [email protected]. We have not appointed a data protection officer, because the law does not require one for a service of our size and kind.
02 / Privacy policy
Visiting the site
You can read the directory, reports and every public page without an account and without accepting cookies. Our own application does not keep logs of your visits. Cloudflare, which delivers the site and protects it from attacks, and our hosting provider process your IP address and the details of each request, such as the page, time and browser, for that purpose. Our fonts are served from our own domain, so reading a page sends nothing to a font service.
Legal basis: our legitimate interest in running a secure, working website (Article 6(1)(f) GDPR).
04 / Privacy policy
Scans and free tools
Starting a public scan may use Cloudflare Turnstile, which receives your IP address and browser signals to tell people from bots. We keep temporary scan counters using keyed hashes of your IP address, account and submitted domain for up to 24 hours. Shared browser-capacity counters last up to 30 days and contain no visitor identity. Public scan progress shows the submitted hostname and scan status, never who asked. Manual rescan allowances are calculated from retained scan records.
Our free tools work the same way: running one may use Turnstile, and we keep temporary counters using keyed hashes of your IP address and the checked domain for up to 24 hours. We do not store the result or who asked for it.
Legal basis: our legitimate interest in keeping a free service from being abused (Article 6(1)(f) GDPR).
05 / Privacy policy
Your account and claims
When you create an account, we store your name, email address and email-verification status. Resend delivers the sign-in links you request. Each link expires after 15 minutes, can be used once and is stored only as a hash. Requesting a link may use Cloudflare Turnstile, which receives your IP address and browser signals to tell people from bots.
Each signed-in session stores its timestamps, your browser information and your IP address when it is available from our trusted proxy. We delete a session’s record when you sign out, and otherwise within an hour of its expiry. Temporary abuse-prevention counters use keyed hashes and expire within an hour. The link-confirmation page does not load analytics.
When you claim a website, we store your verification method, domain, request dates, results and the account linked to the listing. Domain email verification sends a link to webmaster@ or hostmaster@ on that domain. The email shows your account’s email address so the recipient knows who is asking, and we store the recipient address. Email tokens are stored as hashes and expire after 15 minutes. Technical verification tokens are public; a request expires after seven days, and the token is kept for your account and that website so a published tag, file or record stays valid. Claim pages do not load analytics.
Reports never name a listing’s owner; they show only that a listing is claimed.
Legal basis: providing the account and the services you asked for (Article 6(1)(b) GDPR). Ownership records and account security rest on our legitimate interest in settling ownership disputes and preventing misuse (Article 6(1)(f)).
06 / Privacy policy
Purchases
Stripe Managed Payments handles purchases as merchant of record through Link. You enter payment and billing details in Stripe Checkout. Stripe controls the collection of billing details and tax IDs, handles taxes in supported countries, and provides receipts, invoices, fraud prevention and transaction support. It processes this data under its own responsibility, as the Stripe privacy policy explains. We never see or store your full card number.
We keep the billing details you give at checkout (name, email, billing address and any tax ID), what you bought and for which listing, amounts, payment status, receipt links and Stripe’s references for you, the payment and any subscription.
Legal basis: performing the contract (Article 6(1)(b) GDPR) and our tax and accounting obligations (Article 6(1)(c)). We keep these records while the purchase is active and then for as long as Polish tax law requires, generally five years from the end of the year in which the tax fell due. They stay even if you delete your account.
07 / Privacy policy
Emails we send
We send only emails that belong to the service. There is no newsletter and no marketing. Resend delivers them. Depending on what you use, they are:
- sign-in links and claim confirmations;
- monitoring alerts for listings whose plan includes them, when an automatic scan detects a score drop, lost bot access or restored access;
- one email with the result of a scan, when you ask for it on the scan’s progress page;
- payment, renewal, cancellation and failed-payment notices for your purchases;
- one availability email when a Featured place opens, if you joined the waiting list;
- a confirmation when a listing you asked us to remove has been removed.
We keep a copy of each notification with its recipient and delivery status, so we can retry reliably and know what was sent. The Featured waiting list keeps your account and the listing you chose until you leave it or start a purchase.
Legal basis: providing the service you asked for (Article 6(1)(b) GDPR).
08 / Privacy policy
Contact messages
When you use our contact form, we send your name, email address, selected subject and message through Resend to our support inbox so we can respond. We do not store the message in the website’s database or send an automatic reply. We keep the conversation in our mailbox for as long as we need it to deal with your message and any follow-up.
To limit spam, we keep temporary counters based on keyed hashes of your email address and, where available, your IP address. These counters expire after one hour. Your IP address is not included in the contact email.
Legal basis: our legitimate interest in answering you (Article 6(1)(f) GDPR), or performing a contract when you write about a purchase (Article 6(1)(b)).
09 / Privacy policy
Removal requests
When you request removal, we store the website address, your email, any additional information and the submission time. If you submit while signed in as the verified owner, we record that fact to help confirm your authority. Administrators review requests and keep private notes and an activity history.
We use these details to verify and process the removal, and Resend sends a completion email. Temporary spam counters use keyed hashes and expire after one hour. We keep the removed domain to prevent automatic relisting, and the request history to record the decision, for as long as the removal is in effect.
Legal basis: our legitimate interest, and yours, in carrying out the removal and keeping it in force (Article 6(1)(f) GDPR).
10 / Privacy policy
If your website is in the directory
Our reports are about websites, but a website can contain personal data, such as a name on a personal site or an email address in a file. This section is for the people behind the websites we scan.
GoodForBotsBot reads a site’s homepage and the public files that help bots understand it, such as robots.txt, llms.txt, sitemaps and files under /.well-known/, as Our bot lists. We keep the raw responses for 30 days to check and explain results. The published report, its history, the site’s logo and preview image, and excerpts of its files stay online for as long as the site is listed.
Google’s Gemini model writes the listing description, the “Through a bot’s eyes” section, the simulated quote and, for Pro listings, draft llms.txt and robots.txt files. It receives only content the scan collected from the website.
This data comes from the website itself. Legal basis: our legitimate interest in publishing an independent, technical assessment of how public websites work with AI tools (Article 6(1)(f) GDPR). You can object at any time: removing a listing is free and unconditional, and a robots.txt rule stops further scans.
11 / Privacy policy
Badge views
When a page shows a Good for Bots badge, the visitor’s browser fetches it from us. We count these views without cookies and without storing the visitor’s IP address or browser information. We read only the Referer header, cut down to the page’s origin and path. It tells us whether the badge is on the listing’s own site and which sites display it. Daily counters last eight days; daily totals and up to 50 referring hosts a day are kept as statistics for the listing.
Legal basis: our legitimate interest in counting badge views and verifying where the badge is shown (Article 6(1)(f) GDPR).
12 / Privacy policy
Who receives data
These providers help us run Good for Bots. Each processes data on our behalf, only for the purpose shown, except where it acts under its own responsibility as described above.
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Servers for the site, database and queues | EU (Germany or Finland) |
| Cloudflare | Delivering and protecting the site, Turnstile checks, storing listing images | Global network; US company |
| Stripe / Link | Managed Payments, billing details, taxes, receipts, invoices, transaction support and the billing portal | EU and US |
| Resend | Delivering our emails | US |
| Google Analytics 4, only with your consent; the Gemini API, for text written from public website content | EU and US | |
| Browserless | Loading public web pages for scans that need a browser; it receives page addresses, never data about our users | US |
Messages to [email protected] are also stored by the provider of our mailbox. We share data with our accountant for the tax records of purchases, and with courts or authorities when the law requires it. We never sell personal data or share it for advertising.
13 / Privacy policy
Transfers outside the EEA
Some of these providers are based in the United States or process data there. For a provider certified under the EU–US Data Privacy Framework, the transfer relies on the European Commission’s adequacy decision for that framework; otherwise it relies on the Commission’s standard contractual clauses. You can ask us for a copy of the relevant safeguards.
14 / Privacy policy
How long we keep data
| Data | How long |
|---|---|
| Account (name, email) | Until you ask us to delete the account |
| Sessions (IP address, browser) | Until you sign out or the session expires, then deleted within an hour |
| Sign-in links | 15 minutes, stored as hashes; deleted within an hour of expiry |
| Abuse-prevention counters | One hour; 24 hours for scan requests and free tool runs |
| Claims and ownership records | While you own the listing, then as long as needed to settle ownership disputes |
| Purchases and payments | While the purchase is active, then as long as tax law requires (generally five years from the end of the tax year) |
| Copies of notification emails | With the account, listing or purchase they concern |
| Featured waiting list | Until you leave it or start a purchase |
| Contact messages | As long as needed to handle your message and any follow-up |
| Removal requests | As long as the removal is in effect |
| Raw scan responses | 30 days |
| Reports and score history | As long as the site is listed |
| Badge statistics | Daily counters eight days; daily totals kept with the listing |
| Google Analytics | Event data up to 14 months; cookies up to two years |
When you ask us to delete your account, we delete its personal data except what we must keep: purchase records for tax purposes, and the record of any ownership or removal decision. An administrator verifies your request and deletes the account, sessions, unused sign-in links, claim tokens and stored notification copies. Your listings lose their account owner; deleting the account does not remove their reports or undo a previous listing removal. We resolve pending payments and stop subscription renewal as part of handling the request. Copies held by our service providers and support correspondence are reviewed separately.
15 / Privacy policy
Your rights
You have the right to access your data and get a copy, to correct it, to have it deleted, to restrict its use and to receive it in a portable format. You can object to processing based on our legitimate interest, including the directory listing of your website. Where we rely on your consent, you can withdraw it at any time; this does not affect what happened before.
Email [email protected] to use these rights. We reply within one month and may first ask you to confirm your identity or your authority over a website.
You can also complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or to the authority in the EU country where you live or work.
16 / Privacy policy
Automated scoring
Scores are produced automatically, but they assess websites, not people. We make no decisions based solely on automated processing that have legal or similarly significant effects on you.
17 / Privacy policy
Security
Everything travels over HTTPS. Sign-in links and email tokens are stored only as hashes, session cookies are HttpOnly, abuse counters use keyed hashes instead of raw addresses, and only verified administrators can open the admin workspace. No system is perfectly secure. If we learn of a breach that puts you at risk, we will tell you and the supervisory authority as the law requires.
18 / Privacy policy
Children
Good for Bots is not meant for children. You must be at least 16 to create an account, and we do not knowingly collect data from anyone younger.
19 / Privacy policy
Changes to this policy
When our practices change, we update this page and its date. If a change matters to account holders, we tell them by email before it takes effect.