Privacy policy
Last updated: 2026-07-19
Who we are
DigestSEO is operated by Tomi Šeregi, based in Ljubljana, Slovenia. For privacy questions or requests, email info@tomiseregi.si. For product support, start on the support page.
This policy covers the digestseo.com website, the public Web Validator app, the free Site Audit, the DigestSEO workspace, the legacy waitlist endpoint, and any DigestSEO-hosted mcp-gsc endpoint. Open-source MCP servers can also be self-hosted. When you self-host, the operator of that deployment controls its data and must provide its own notices.
What data we collect
- Name and email address submitted through the legacy waitlist endpoint, plus the optional form intent and source/referrer metadata used to understand which page led to the request.
- When you create a DigestSEO account, the email address, profile details, provider identifier, verification state, and session/security metadata needed to authenticate you and operate the workspace.
- Optional Google Analytics measurements, such as page views, referrer, and coarse browser/device information. Analytics is not loaded until you choose “Allow analytics”.
- When you use the public Web Validator, the HTML or CSS you explicitly submit, any authorized public-page URL or optional base URL, fetched public HTML, and the resulting validation messages are processed to complete that request.
- When you use the free Site Audit, the public URL, one bounded fetched HTML document, and the resulting PageSpeed, Nu HTML Checker, SEO, accessibility, and JSON-LD results are processed to return the report. A one-way hash of the connecting IP address enforces the seven-day quota; the raw IP is not persisted by the audit function.
- When you use a DigestSEO-hosted mcp-gsc endpoint, the Google OAuth account identifier, encrypted refresh token, Search Console requests, and returned Search Console data needed for the requested tool call are processed.
Do not submit credentials, payment-card information, health information, government identifiers, or other sensitive personal data to the Web Validator or Site Audit. Do not submit private URLs or content that you are not authorized to share. Cloudflare and upstream providers may still process network metadata, such as an IP address, to operate and secure their services.
Why we use the data
We process legacy waitlist details, where received, to provide the notification requested (GDPR Art. 6(1)(b)), and support or privacy requests to respond and protect the service (Art. 6(1)(b), 6(1)(f), or a legal obligation as applicable). Tool inputs are processed to return the report or validation result you requested and to prevent abuse (Art. 6(1)(b) and 6(1)(f)). Google Analytics is optional and is loaded only after your consent (Art. 6(1)(a) and the applicable e-privacy consent requirement). Account data is processed to create and secure your workspace, verify ownership of the email address, and prevent abuse (Art. 6(1)(b) and 6(1)(f)). We do not use tool inputs or account data to train AI models or for advertising.
How we store your data
Legacy waitlist submissions may be stored in a Cloudflare D1 database when that binding is enabled and are forwarded to Formspree for notification. If D1 is unavailable or not configured, Formspree is used as the fallback store. The public Web Validator does not write submitted content or results to an application database. Site Audit quota hashes are stored in Cloudflare KV for seven days and are not used for advertising. Hosted mcp-gsc tokens are encrypted before storage in the hosted worker's storage. Account records, password authentication, sessions, email verification, and social sign-in are handled by Clerk; DigestSEO does not receive or store user passwords. Cloudflare, Clerk, Google, GitHub, Formspree, Nu, and other upstream providers may retain operational logs under their own policies.
Third parties and transfers
Depending on the feature you use, data is shared with Cloudflare (Pages, Workers, D1, KV, and security), Formspree (legacy waitlist forwarding), Google (optional Analytics, PageSpeed Insights, OAuth, and Search Console APIs), Clerk (account authentication and verification), and GitHub when you choose GitHub sign-in, the Nu HTML Checker at validator.w3.org, and the host of a public page you explicitly ask us to audit. A Site Audit sends the fetched HTML to the Nu HTML Checker and the final public URL to PageSpeed Insights; local SEO and JSON-LD checks run in the DigestSEO Worker. Neither tool executes JavaScript, crawls a site, fetches linked CSS, or authenticates to private pages. Some providers may process data outside the EU/EEA using an adequacy decision, the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses and other safeguards.
How long we keep data
We keep legacy waitlist details only while the requested notification remains useful or until you ask us to delete them, subject to legal obligations and provider backups. We aim to remove application records within seven days of a valid deletion request. Web Validator inputs and results are not kept in an application database. Site Audit quota hashes expire after seven days. Hosted OAuth data is kept while the connection is active or until deletion is requested. Account data is kept while the account is active or until deletion is requested, subject to security logs and legal obligations. Google Analytics retention is controlled by the configured Google property and your consent choice.
Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw analytics consent at any time by choosing “Change analytics preference” below or clearing the consent cookie. Email info@tomiseregi.si to exercise a right or request deletion. You may also complain to the Slovenian Information Commissioner (Informacijski pooblaščenec) or another competent supervisory authority.
Cookies and analytics
The site stores one functional consent-preference cookie named
digestseo-analytics-consent for up to one year so it can
remember your choice. Google Analytics cookies are created only after you
allow analytics; they are not used for advertising or ad personalization.
Cloudflare may set strictly necessary security cookies or process request
metadata to protect the site.
The language picker stores your explicit language choice in browser
localStorage under digestseo-locale-choice; that
preference is not sent to our server and can be removed through your
browser settings.
No profiling
DigestSEO does not make automated decisions about you or use the data described here for profiling.
Changes to this policy
We will post material changes here and update the last-updated date.
Contact
Email info@tomiseregi.si for privacy requests. For product support, use the support page or the relevant project issue tracker: Web Validator, mcp-gsc, or mcp-geo.