Privacy policy
Last updated October 2, 2026.
The short version. We help companies measure and improve their growth. We look at public websites, and, when a client connects them, the client's own tools. We act on our clients' behalf for their customers' data, we use it only to do the work they hired us for, never for another client, and never to train AI models. Deletion requests are handled within seven days.
Who we are
This service is run by Lee Flannery Consulting LLC. Questions about privacy go to hello@leeflanneryconsulting.com.
Two kinds of data
Data about our clients. When your company works with us, we hold the email addresses of the people on your team who sign in, and a record of what they do in the app (for example, marking a finding fixed or sharing a report by link). We are responsible for this data.
Data about our clients' customers. When a client installs our site tag or connects a source such as Stripe, we process data about that client's own customers on the client's behalf. The client decides what is collected and why, we follow their instructions. If you are a customer of one of our clients, that company is responsible for your data and is the first place to ask about it. We will help them answer you.
What we collect and why
- Public web pages. We read public, logged-out pages of a client's website and related public sources to produce a report. We never read pages behind a login.
- Sign-in details. Your email address, used to send you a sign-in link. There are no passwords. If we invite you, the invitation holds your email address. We delete the invitation 90 days after it is accepted, cancelled or expires.
- Read requests. When you ask for a free read of your website, we keep your email address and the website address so we can send the read and set up your account.
- Email updates. If you leave the box ticked when you ask for a read, or switch it on in Your data, we keep that choice, the date and the wording you saw, and send occasional product news. Switch it off in Your data at any time, or use the unsubscribe link in any update.
- Security log. We record sign-in attempts so we can spot misuse. The log holds a hashed form of your user id and IP address, not the address itself.
- Use of the app. We record which screens and features your team uses, under a hashed user id, to find what is confusing or broken. The app loads no third-party analytics or advertising scripts.
- Notes and error logs. We keep notes your team adds in the app (for example, why a finding was set aside) and our own notes on the work. When something fails, we log the page, the error and the time, with email addresses and keys removed before the message is stored.
- Site tag events. The tag keeps its identifiers in first-party cookies on the client's own site for 90 days. It sets no third-party cookies and does no fingerprinting. It sends nothing when someone only browses. When a visitor buys or signs up, it sends one record of that conversion, with ad-click identifiers and hashed contact details, so the client can see which channels bring customers. It does nothing for a browser that sends Global Privacy Control. What the site tag collects.
- Connected sources. When a client connects Stripe, Google Analytics, Google Ads, Meta or Google Search Console, we read what the connection allows (read-only where the platform offers it) to answer the checks in their report. Keys are stored encrypted and are never shown back. Search Console is read through a Google sign-in, read only; we keep your search queries and page figures, and you can disconnect in Connections, which removes our access at Google.
- Customer records a client shares. Used to match results to real customers. When we send data to an ad platform on a client's behalf, we send only hashed identifiers, and only for people who bought or opted in.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Search Console data for advertising.
We do not buy data about people who have not transacted with or opted in to our client, and we do not build profiles of individuals from community or social posts.
Services we use
We use a small number of providers to run the service. Supabase (database and sign-in), Anthropic (AI models that draft and check reports), Railway (hosting), Resend (sending team invitations), and, only when a client connects them, Stripe, Google and Meta. Each provider receives only what it needs for its part of the work.
How long we keep data
- A client's customer records: for the engagement and 90 days after it ends. When an account is closed, we delete its customer records (orders, leads, contact hashes and the people built from them) 90 days later, unless the client asks for an export first. Reports keep their figures but lose the links to those records, and we keep a log of the deletion that holds counts only.
- Site tag events that never matched a customer: 90 days.
- Records of what we sent to an ad platform: kept with the account. When a person is deleted, the record keeps the fact that a send happened and loses the link to that person.
- Team sign-in details: while your company works with us. When someone is removed from the team or the account closes, we delete their sign-in, unless they belong to another account with us.
- Read requests: until the account closes or you ask us to delete them.
- App usage records, the security log and error logs: 90 days.
- Notes, the history of each finding, shared link records and our log of changes to the account: kept as the account's history, including after the account closes.
- Public web observations: kept as a dated history, since they describe companies, not private individuals.
Your rights
You can ask to see, correct or delete personal data we hold about you. If you are a client's customer, you can ask the client or write to us, we act on a deletion within seven days across our store, and send deletion requests to the ad platforms where their tools allow. We log that a deletion happened, not what was deleted. Depending on where you live (for example California or the EU), you may have further rights, write to hello@leeflanneryconsulting.com and we will answer.
Changes
If we change this policy in a way that matters, we will tell clients before it takes effect.