Legal
Privacy Policy
Last updated: May 25, 2026
What we collect
- Account data: email, display name, hashed password (if you sign up with email/password).
- OAuth profile: name, email, and avatar from Google when you sign in with Google.
- Audit data: URLs you submit, crawl results, findings, AI-generated summaries.
- Usage metadata: IP address, request timestamps, basic device info for abuse prevention and rate limiting.
- Billing: handled by Stripe. We store your Stripe customer ID and subscription status, never card numbers.
How we use it
To run the audits you ask for, deliver reports and alerts, secure the platform, bill paid plans, send transactional email, and improve the product. We do not sell your personal data, ever.
Sub-processors
We rely on a small number of vendors to operate the Service:
- Lovable Cloud (Supabase): hosting, database, authentication, storage.
- Stripe: subscription billing, invoices, tax calculation.
- Firecrawl: JS-rendered page crawling for audits.
- Resend: transactional email delivery.
- OpenAI / Google (via Lovable AI Gateway): AI-generated summaries and recommendations.
Public audits
By default, audit reports are public and shareable via link. They appear in our public gallery. Paid plans can mark reports private. Private reports are visible only to the owner.
Retention
Account data is kept while your account is active. When you delete your account, we remove personal data within 30 days, except where law requires us to retain billing records. Public audits remain visible (anonymized) unless you delete them first.
Your rights (GDPR / CCPA)
You can access, export, correct, or delete your data at any time. Email privacy@sightline.app and we'll respond within 30 days.
Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to authorized engineers. We use row-level security policies on every user-data table.
Cookies
We use first-party cookies to keep you signed in. We don't use third-party advertising or tracking cookies. If you sign in with Google, Google may set cookies under its own policy.
Children
Sightline is not intended for users under 16. We don't knowingly collect data from minors.
Changes
We'll update this page when our practices change. Material changes will be announced in-app or by email at least 14 days in advance.