Privacy policy

Last updated: 2026-07-19

Who we are

DigestSEO is operated by Tomi Šeregi, based in Ljubljana, Slovenia. For privacy questions or requests, email info@tomiseregi.si. For product support, start on the support page.

This policy covers the digestseo.com website, the public Web Validator app, the free Site Audit, the DigestSEO workspace, the legacy waitlist endpoint, and any DigestSEO-hosted mcp-gsc endpoint. Open-source MCP servers can also be self-hosted. When you self-host, the operator of that deployment controls its data and must provide its own notices.

What data we collect

Do not submit credentials, payment-card information, health information, government identifiers, or other sensitive personal data to the Web Validator or Site Audit. Do not submit private URLs or content that you are not authorized to share. Cloudflare and upstream providers may still process network metadata, such as an IP address, to operate and secure their services.

Why we use the data

We process legacy waitlist details, where received, to provide the notification requested (GDPR Art. 6(1)(b)), and support or privacy requests to respond and protect the service (Art. 6(1)(b), 6(1)(f), or a legal obligation as applicable). Tool inputs are processed to return the report or validation result you requested and to prevent abuse (Art. 6(1)(b) and 6(1)(f)). Google Analytics is optional and is loaded only after your consent (Art. 6(1)(a) and the applicable e-privacy consent requirement). Account data is processed to create and secure your workspace, verify ownership of the email address, and prevent abuse (Art. 6(1)(b) and 6(1)(f)). We do not use tool inputs or account data to train AI models or for advertising.

How we store your data

Legacy waitlist submissions may be stored in a Cloudflare D1 database when that binding is enabled and are forwarded to Formspree for notification. If D1 is unavailable or not configured, Formspree is used as the fallback store. The public Web Validator does not write submitted content or results to an application database. Site Audit quota hashes are stored in Cloudflare KV for seven days and are not used for advertising. Hosted mcp-gsc tokens are encrypted before storage in the hosted worker's storage. Account records, password authentication, sessions, email verification, and social sign-in are handled by Clerk; DigestSEO does not receive or store user passwords. Cloudflare, Clerk, Google, GitHub, Formspree, Nu, and other upstream providers may retain operational logs under their own policies.

Third parties and transfers

Depending on the feature you use, data is shared with Cloudflare (Pages, Workers, D1, KV, and security), Formspree (legacy waitlist forwarding), Google (optional Analytics, PageSpeed Insights, OAuth, and Search Console APIs), Clerk (account authentication and verification), and GitHub when you choose GitHub sign-in, the Nu HTML Checker at validator.w3.org, and the host of a public page you explicitly ask us to audit. A Site Audit sends the fetched HTML to the Nu HTML Checker and the final public URL to PageSpeed Insights; local SEO and JSON-LD checks run in the DigestSEO Worker. Neither tool executes JavaScript, crawls a site, fetches linked CSS, or authenticates to private pages. Some providers may process data outside the EU/EEA using an adequacy decision, the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses and other safeguards.

How long we keep data

We keep legacy waitlist details only while the requested notification remains useful or until you ask us to delete them, subject to legal obligations and provider backups. We aim to remove application records within seven days of a valid deletion request. Web Validator inputs and results are not kept in an application database. Site Audit quota hashes expire after seven days. Hosted OAuth data is kept while the connection is active or until deletion is requested. Account data is kept while the account is active or until deletion is requested, subject to security logs and legal obligations. Google Analytics retention is controlled by the configured Google property and your consent choice.

Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw analytics consent at any time by choosing “Change analytics preference” below or clearing the consent cookie. Email info@tomiseregi.si to exercise a right or request deletion. You may also complain to the Slovenian Information Commissioner (Informacijski pooblaščenec) or another competent supervisory authority.

Cookies and analytics

The site stores one functional consent-preference cookie named digestseo-analytics-consent for up to one year so it can remember your choice. Google Analytics cookies are created only after you allow analytics; they are not used for advertising or ad personalization. Cloudflare may set strictly necessary security cookies or process request metadata to protect the site. The language picker stores your explicit language choice in browser localStorage under digestseo-locale-choice; that preference is not sent to our server and can be removed through your browser settings.

No profiling

DigestSEO does not make automated decisions about you or use the data described here for profiling.

Changes to this policy

We will post material changes here and update the last-updated date.

Contact

Email info@tomiseregi.si for privacy requests. For product support, use the support page or the relevant project issue tracker: Web Validator, mcp-gsc, or mcp-geo.