Skip to main content

Privacy Policy

This is a translation provided for convenience. deeploupe is operated from Germany; in case of any discrepancy, the German version prevails.

This policy describes what happens to your data when you visit deeploupe.com or use the analysis tool. It was not produced by a generator but written from the source code: every service named below is genuinely called, and an automated test prevents this list from quietly going out of date.

If anything here is unclear, or if you believe a statement is wrong, write to us — the address is at the end.

Controller

The controller within the meaning of Art. 4(7) GDPR is Speakz Media GmbH, as named in the legal notice. We have not appointed a data protection officer; we are not required to do so under § 38 BDSG.

If you only browse the site

Merely opening a page causes your browser to transmit technically necessary data to our hosting provider: your IP address, date and time, the address requested, the previously visited page, and details about your browser and operating system. A website cannot be delivered without this.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technical operation and security of the service.

If you analyse a website

The analysis tools (quick scan, citation check, GPTBot check) primarily process data about a third-party website, not about you. What is processed about you is:

  • The address you enter. It is stored so that a repeat request is faster and so we can show the result again.
  • A hash of your IP address, used to cap the number of free analyses per day. The IP address itself is not stored. The hash is computed as HMAC-SHA256 with a server-side secret that resides solely in our operating environment and is never stored alongside the hashes. It is therefore pseudonymised, not anonymous; without that secret it is practically infeasible to recover the original address.

Results that become publicly visible

Some per-domain results are published as publicly accessible pages (e.g. under /check/…) and may be indexed by search engines. What is shown concerns the website analysed, not the person who requested the analysis: whoever starts a check is not named there and cannot be inferred from the page.

If you operate a domain shown there and would rather it were not, an informal message to us is enough; we will take it down.

If you create an account

An account requires an email address and a password. We store the password only as a cryptographic hash, never in plain text. Alternatively you can sign in with a Google account; Google then provides us with your email address and basic profile data, and Google learns that you are signing in with us.

The legal basis is Art. 6(1)(b) GDPR — the processing is necessary to perform the contract.

If you buy something

Payments are handled by Stripe. You enter your payment details directly there — we neither see nor store card numbers or billing addresses. What stays with us is your Stripe customer reference, the product purchased and the details we need for accounting and invoicing.

The legal basis is Art. 6(1)(b) GDPR and, for retaining accounting records, additionally Art. 6(1)(c) GDPR together with German commercial and tax retention periods (§ 147 AO, § 257 HGB — six and ten years respectively).

Audience measurement

We measure which pages are viewed and where users abandon the flow, in order to improve the service. We use PostHog and Vercel Analytics for this. Session recording and autocapture of individual clicks are switched off.

Nothing is placed on your device in the process: the identifier that groups individual views into a session exists solely in your browser’s memory and disappears as soon as you leave or reload the page. We set no cookie for it and do not use local storage. That is why we need no consent banner — and you need not dismiss one.

The price is that we will not recognise you on a later visit. That is intentional: we want to know where our flow breaks down, not who you are.

Who receives your data

We share data only as far as operating the service requires. This list is complete — it is bound to the source code and is necessarily updated whenever a new service is added.

Where providers act as processors on our behalf, the agreements required by Art. 28 GDPR are in place.

  • Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA

    Third country
    Purpose
    Hosting, content delivery and execution of the server functions.
    Data
    IP address, date and time of the request, requested URL, referrer, browser and device identification (server logs). When you use the analysis features, additionally the domain you entered.
    Location
    Page content is delivered from Frankfurt am Main; the server functions currently run in Washington, D.C., USA.
  • PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA

    Third country
    Purpose
    Product analytics: which pages are viewed and which steps of the flow are reached, in order to improve the service.
    Data
    A random identifier that exists only in your browser’s memory and disappears when you leave or reload the page, plus pages viewed, timestamps and — for the analysis steps — the domain you entered. Nothing is stored on your device: no cookie, no local storage. Session recording and autocapture are switched off.
    Location
    USA.
  • Supabase, Inc., 970 Toa Payoh North #07-04, Singapur 318992

    Purpose
    Database and user accounts (sign-up, sign-in, session management).
    Data
    Email address, password hash, sign-in timestamps, account data and all content stored in the database (see “What we store”).
    Location
    Frankfurt am Main, Germany (region eu-central-1).
  • Fly.io, Inc., 2261 Market Street #4990, San Francisco, CA 94114, USA

    Purpose
    Operation of the analysis server that actually loads and renders the website under test.
    Data
    Only the address to be analysed. No account data, no IP address and no session data are transmitted.
    Location
    Frankfurt am Main, Germany (region fra).
  • Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Irland

    Third country
    Purpose
    Processing of payments and subscriptions.
    Data
    Email address, your user ID, the purchased product and the scanned domain. Payment details (card and billing data) are entered directly with Stripe — we neither see nor store them.
    Location
    Ireland; Stripe also transfers data to the USA (Stripe, Inc.).
  • Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA

    Third country
    Purpose
    Sending of notification and system emails (e.g. monitoring alerts).
    Data
    Recipient address, subject and content of the respective message.
    Location
    USA.
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland

    Third country
    Purpose
    Sign-in with a Google account — only if you actively choose this option.
    Data
    Google shares your email address and basic profile data with us. In doing so, Google learns that you are signing in to deeploupe.
    Location
    Ireland; Google also transfers data to the USA.
  • Google Ireland Limited (Gemini), OpenAI Ireland Ltd., Anthropic PBC (USA), Perplexity AI, Inc. (USA)

    Third country
    Purpose
    Core of the analysis: we put a market question to these answer engines and record which providers they name — that is what shows whether a website gets cited.
    Data
    Only a generically phrased market question (e.g. “best bike shop in Berlin”). Neither your IP address nor your account data nor your session are transmitted. To determine the relevant industry, the publicly available page title and meta description of the analysed website are additionally transmitted.
    Location
    Ireland and USA.
  • Google Ireland Limited (PageSpeed Insights), Gordon House, Barrow Street, Dublin 4, Irland

    Third country
    Purpose
    Measurement of the load performance of the analysed website.
    Data
    Only the address to be analysed.
    Location
    Ireland; transfer to the USA possible.
  • DataForSeo LLC, 1209 Mountain Road Pl NE, Albuquerque, NM 87110, USA

    Third country
    Purpose
    Retrieval of public search engine results for the visibility analysis.
    Data
    Only the search term queried and the target search region.
    Location
    USA.

What is stored in your browser

Some of it is technically necessary — without those entries you could not sign in. The rest serves audience measurement and is dispensable.

  • Authentication cookies (sb-…)

    technically necessary

    Keep you signed in and protect the session. Only set once you create an account or sign in.

  • Appearance setting (theme)

    technically necessary

    Remembers whether you chose the light or dark appearance.

Transfers to third countries

Some of the providers listed above are based in the USA or transfer data there. For those transfers we rely on the European Commission’s standard contractual clauses and, where the providers are certified, on the EU-US Data Privacy Framework.

You should know what that means in practice: in the USA, authorities may under certain conditions access data without your having a remedy equivalent to the European one. That is a residual risk which contractual measures cannot fully eliminate.

Where we can avoid it, we do: our database and analysis server are located in Frankfurt am Main. Our server functions currently still run in the USA; we are working on moving those to Frankfurt as well.

How long we store data

Account data is stored for as long as your account exists. If you delete it, we remove the associated data unless a statutory retention obligation applies; accounting and invoicing records must be kept for six and ten years respectively.

For the technical caches we now delete automatically: the usage-limit counters after 30 days and the cached analysis results of third-party domains after two days. Some further history (such as the log of ongoing website monitors) is not yet removed automatically; it is no longer used once it expires, and we are rolling out automatic deletion step by step. Your right to erasure under Art. 17 GDPR applies at all times: ask us and we delete.

Your rights

You have the following rights against us:

  • Access to the data we process about you (Art. 15 GDPR).
  • Rectification of inaccurate data (Art. 16 GDPR).
  • Erasure (Art. 17 GDPR).
  • Restriction of processing (Art. 18 GDPR).
  • Portability of your data in a transferable format (Art. 20 GDPR).
  • Objection to processing based on a legitimate interest (Art. 21 GDPR).
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR).

Complaints

You may lodge a complaint with a data protection supervisory authority at any time without contacting us first. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany.

Changes

We update this policy when our processing changes. The date below shows the current version. We notify registered users of material changes by email as well.

Last updated: