Privacy Policy
This is a translation provided for convenience. deeploupe is operated from Germany; in case of any discrepancy, the German version prevails.
This policy describes what happens to your data when you visit deeploupe.com or use the analysis tool. It was not produced by a generator but written from the source code: every service named below is genuinely called, and an automated test prevents this list from quietly going out of date.
If anything here is unclear, or if you believe a statement is wrong, write to us — the address is at the end.
Controller
The controller within the meaning of Art. 4(7) GDPR is Speakz Media GmbH, as named in the legal notice. We have not appointed a data protection officer; we are not required to do so under § 38 BDSG.
If you only browse the site
Merely opening a page causes your browser to transmit technically necessary data to our hosting provider: your IP address, date and time, the address requested, the previously visited page, and details about your browser and operating system. A website cannot be delivered without this.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technical operation and security of the service.
If you analyse a website
The analysis tools (quick scan, citation check, GPTBot check) primarily process data about a third-party website, not about you. What is processed about you is:
- The address you enter. It is stored so that a repeat request is faster and so we can show the result again.
- A hash of your IP address, used to cap the number of free analyses per day. The IP address itself is not stored. The hash is computed as HMAC-SHA256 with a server-side secret that resides solely in our operating environment and is never stored alongside the hashes. It is therefore pseudonymised, not anonymous; without that secret it is practically infeasible to recover the original address.
Results that become publicly visible
Some per-domain results are published as publicly accessible pages (e.g. under /check/…) and may be indexed by search engines. What is shown concerns the website analysed, not the person who requested the analysis: whoever starts a check is not named there and cannot be inferred from the page.
If you operate a domain shown there and would rather it were not, an informal message to us is enough; we will take it down.
If you create an account
An account requires an email address and a password. We store the password only as a cryptographic hash, never in plain text. Alternatively you can sign in with a Google account; Google then provides us with your email address and basic profile data, and Google learns that you are signing in with us.
The legal basis is Art. 6(1)(b) GDPR — the processing is necessary to perform the contract.
If you buy something
Payments are handled by Stripe. You enter your payment details directly there — we neither see nor store card numbers or billing addresses. What stays with us is your Stripe customer reference, the product purchased and the details we need for accounting and invoicing.
The legal basis is Art. 6(1)(b) GDPR and, for retaining accounting records, additionally Art. 6(1)(c) GDPR together with German commercial and tax retention periods (§ 147 AO, § 257 HGB — six and ten years respectively).
Audience measurement
We measure which pages are viewed and where users abandon the flow, in order to improve the service. We use PostHog and Vercel Analytics for this. Session recording and autocapture of individual clicks are switched off.
Nothing is placed on your device in the process: the identifier that groups individual views into a session exists solely in your browser’s memory and disappears as soon as you leave or reload the page. We set no cookie for it and do not use local storage. That is why we need no consent banner — and you need not dismiss one.
The price is that we will not recognise you on a later visit. That is intentional: we want to know where our flow breaks down, not who you are.
Who receives your data
We share data only as far as operating the service requires. This list is complete — it is bound to the source code and is necessarily updated whenever a new service is added.
Where providers act as processors on our behalf, the agreements required by Art. 28 GDPR are in place.
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA
Third country- Purpose
- Hosting, content delivery and execution of the server functions.
- Data
- IP address, date and time of the request, requested URL, referrer, browser and device identification (server logs). When you use the analysis features, additionally the domain you entered.
- Location
- Page content is delivered from Frankfurt am Main; the server functions currently run in Washington, D.C., USA.
PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA
Third country- Purpose
- Product analytics: which pages are viewed and which steps of the flow are reached, in order to improve the service.
- Data
- A random identifier that exists only in your browser’s memory and disappears when you leave or reload the page, plus pages viewed, timestamps and — for the analysis steps — the domain you entered. Nothing is stored on your device: no cookie, no local storage. Session recording and autocapture are switched off.
- Location
- USA.
Supabase, Inc., 970 Toa Payoh North #07-04, Singapur 318992
- Purpose
- Database and user accounts (sign-up, sign-in, session management).
- Data
- Email address, password hash, sign-in timestamps, account data and all content stored in the database (see “What we store”).
- Location
- Frankfurt am Main, Germany (region eu-central-1).
Fly.io, Inc., 2261 Market Street #4990, San Francisco, CA 94114, USA
- Purpose
- Operation of the analysis server that actually loads and renders the website under test.
- Data
- Only the address to be analysed. No account data, no IP address and no session data are transmitted.
- Location
- Frankfurt am Main, Germany (region fra).
Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Irland
Third country- Purpose
- Processing of payments and subscriptions.
- Data
- Email address, your user ID, the purchased product and the scanned domain. Payment details (card and billing data) are entered directly with Stripe — we neither see nor store them.
- Location
- Ireland; Stripe also transfers data to the USA (Stripe, Inc.).
Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA
Third country- Purpose
- Sending of notification and system emails (e.g. monitoring alerts).
- Data
- Recipient address, subject and content of the respective message.
- Location
- USA.
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland
Third country- Purpose
- Sign-in with a Google account — only if you actively choose this option.
- Data
- Google shares your email address and basic profile data with us. In doing so, Google learns that you are signing in to deeploupe.
- Location
- Ireland; Google also transfers data to the USA.
Google Ireland Limited (Gemini), OpenAI Ireland Ltd., Anthropic PBC (USA), Perplexity AI, Inc. (USA)
Third country- Purpose
- Core of the analysis: we put a market question to these answer engines and record which providers they name — that is what shows whether a website gets cited.
- Data
- Only a generically phrased market question (e.g. “best bike shop in Berlin”). Neither your IP address nor your account data nor your session are transmitted. To determine the relevant industry, the publicly available page title and meta description of the analysed website are additionally transmitted.
- Location
- Ireland and USA.
Google Ireland Limited (PageSpeed Insights), Gordon House, Barrow Street, Dublin 4, Irland
Third country- Purpose
- Measurement of the load performance of the analysed website.
- Data
- Only the address to be analysed.
- Location
- Ireland; transfer to the USA possible.
DataForSeo LLC, 1209 Mountain Road Pl NE, Albuquerque, NM 87110, USA
Third country- Purpose
- Retrieval of public search engine results for the visibility analysis.
- Data
- Only the search term queried and the target search region.
- Location
- USA.
What is stored in your browser
Some of it is technically necessary — without those entries you could not sign in. The rest serves audience measurement and is dispensable.
Authentication cookies (sb-…)
technically necessaryKeep you signed in and protect the session. Only set once you create an account or sign in.
Appearance setting (theme)
technically necessaryRemembers whether you chose the light or dark appearance.
Transfers to third countries
Some of the providers listed above are based in the USA or transfer data there. For those transfers we rely on the European Commission’s standard contractual clauses and, where the providers are certified, on the EU-US Data Privacy Framework.
You should know what that means in practice: in the USA, authorities may under certain conditions access data without your having a remedy equivalent to the European one. That is a residual risk which contractual measures cannot fully eliminate.
Where we can avoid it, we do: our database and analysis server are located in Frankfurt am Main. Our server functions currently still run in the USA; we are working on moving those to Frankfurt as well.
How long we store data
Account data is stored for as long as your account exists. If you delete it, we remove the associated data unless a statutory retention obligation applies; accounting and invoicing records must be kept for six and ten years respectively.
For the technical caches we now delete automatically: the usage-limit counters after 30 days and the cached analysis results of third-party domains after two days. Some further history (such as the log of ongoing website monitors) is not yet removed automatically; it is no longer used once it expires, and we are rolling out automatic deletion step by step. Your right to erasure under Art. 17 GDPR applies at all times: ask us and we delete.
Your rights
You have the following rights against us:
- Access to the data we process about you (Art. 15 GDPR).
- Rectification of inaccurate data (Art. 16 GDPR).
- Erasure (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Portability of your data in a transferable format (Art. 20 GDPR).
- Objection to processing based on a legitimate interest (Art. 21 GDPR).
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
Complaints
You may lodge a complaint with a data protection supervisory authority at any time without contacting us first. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany.
Changes
We update this policy when our processing changes. The date below shows the current version. We notify registered users of material changes by email as well.
Last updated: