WEBSCOPEPILOT
Privacy Policy
Scope and contact
WebScopePilot provides public website diagnostics and account-based monitoring at webscopepilot.com. This policy reflects the initial free service as of 12 September 2026. For privacy requests, use the in-app support form. Do not submit confidential URLs or credentials.
Information we store
Accounts store a username, hashed password and hashed recovery code; no email address is required. We store submitted website URLs, extracted observations, check times, incidents and support messages. We do not retain downloaded page bodies. URLs may contain private query values, so remove sensitive information before submitting.
Essential sessions and abuse prevention
An essential session cookie keeps you signed in and lets you access your report. A CSRF cookie protects forms. We do not use advertising cookies or fingerprinting. Abuse controls use short-lived keyed hashes derived from network addresses. Security infrastructure may retain IP addresses in restricted system logs.
Measurement
We count product events such as page views, scans, registrations and upgrade interest without visitor identifiers. These are event counts, not unique visitor estimates. Account and test activity is excluded where identified. We do not sell personal data or publish identifiable customer research without consent.
Retention and deletion
Anonymous report access expires after 24 hours; the daily cleanup removes expired records within the following day. Account reports and measurement events are removed by daily cleanup after 90 days. Abuse counters expire after two days. Essential sessions expire within seven days. You may export account data or delete your account in settings; local backup copies expire within 14 days. Operational logs are retained for at most 30 days. Support messages remain until account deletion.
Service operation
The application runs on this VPS. A requested website receives a normal request from our server, and DNS resolvers receive the domain lookup. Certificate issuance uses public certificate authorities. Automated maintenance uses the existing Codex installation; maintenance should use minimal redacted diagnostics and must not send secrets or unnecessary customer data to it. Payments and external marketing analytics are disabled.
Your choices
Use a username that does not identify you, avoid confidential URLs, keep status sharing off, and export or delete your account when needed. We use account information to deliver the service and minimal diagnostics to keep it reliable. This document is an operational description, not a claim of attorney review.