← Back to Home

What We Collect

Your email, display name, and hashed password. The URLs you submit for auditing. The audit results we generate from those URLs. Basic usage logs (IP address, browser, timestamps). Payment records if you purchase a paid plan.

What We Don’t Collect

We don’t collect content from password-protected or private pages. We don’t collect Social Security numbers, financial account details, health information, or biometric data. We don’t store your payment card number — that’s handled entirely by our payment processor.

What Happens When You Run an Audit

We crawl the publicly available web pages at the URL you provide. The visible text from those pages is sent to Google Gemini’s API for analysis. We use paid API tiers where Google’s terms prohibit using your input for model training. The text being analyzed is already public — we’re reading what any visitor to that website would see.

What We Store

Your account information, the URLs you submitted, and the scores, evidence, and recommendations generated by the audit. Server logs are deleted after 90 days. We do not retain the raw text sent to the LLM beyond the duration of the API request.

What We Share

Nothing, with three exceptions: our infrastructure providers (hosting, payment processing) who are contractually bound to confidentiality; law enforcement if compelled by valid legal process; and aggregated, de-identified benchmarking data that cannot identify you or your organization.

We don’t sell data. We don’t run ads. We don’t do behavioral tracking. We don’t share your information with third parties for marketing.

Benchmarking

We use de-identified, aggregated audit scores to compute peer benchmarks (e.g., average score for cities of similar size). Your organization is never named in benchmarking data without your explicit written consent.

Retention

Account data and audit results are retained while your account is active. If you delete your account, everything is deleted within 30 days except payment records we’re legally required to keep for tax purposes (7 years). Aggregated benchmark data that can’t identify you may be retained indefinitely.

Security

Your Rights

You can view, export, correct, or delete your data at any time. Free-tier users can request a data export by email. Pro and Enterprise users can export directly from the dashboard. Account deletion is available in settings or by emailing enterprise@gpt.us.org. We respond to all data requests within 30 days.

Children

The service is for professional use by adults. We don’t knowingly collect data from anyone under 18.

Changes

We’ll update this policy as the product evolves. Material changes get an in-app notification. Continued use after a change means you accept it.

Questions? Contact Dick Lakey at enterprise@gpt.us.org or 240-429-3987.