Privacy

Privacy, in plain English.

Most of this runs in your browser and sends us nothing. Here’s the rest, in order of importance.

The audit sends us nothing

The crawl, the ninety checks, the scoring, the fixes, the schema, the briefs and the link plans all run in your browser and store their results in your browser. With no account, nothing about the site you audited reaches us at all. Closing the tab and clearing the site data removes it entirely, and there is no copy on our side to ask about.

That is not a privacy feature bolted on. It is how the product is built, and it is why the whole thing keeps working with every external account disconnected.

If you book a call

  • What you type into the form: your name, email, business, website, what you need help with and anything you add. Used to reply to you and to prepare for the call. Nothing else.
  • Where it goes: into our own database, and to our team’s inbox. We keep a one-way hash of the network address it came from, only to stop the form being flooded, and never the address itself.
  • Not a mailing list. Booking a call does not sign you up to anything. Ask on the call or by reply and the enquiry is deleted.

If you make an account

  • Your email address and name, from the sign-in you chose. Used to identify you and to send the reports and alerts you asked for. Nothing else.
  • Your workspace: the sites you added, the runs, the findings, the fixes and the approvals. A server copy of what your browser already holds, so scheduled work can happen while the tab is closed.
  • A hash of your session cookie, never the cookie. Only its SHA-256 is stored, so a copy of our database cannot be replayed as a login to your account.
  • An audit log of what each agent did and what you approved. This exists so you can check us, and it is the last thing we would remove.

Accounts you connect

Connecting Search Console, Analytics, a CMS or an advertising platform stores a token that lets us do the specific things the consent screen listed. Three things about those tokens:

  • They are sealed with a per-record key. Each token is encrypted with its own data key, which is itself wrapped by a deployment key held outside the database. A database copy on its own opens nothing.
  • No route ever returns one, in any form, including masked. A mask still confirms a value, so there is no screen and no API response anywhere in this product that shows any part of a stored secret.
  • You revoke them without us. Every platform lets you withdraw access from your own account settings, and doing so takes effect immediately whether or not you tell us.

We never ask you to paste an API key or a password for an advertising platform. You log in on the platform’s own site and approve a consent screen listing exactly what we may do. The paid ads page lists the scopes per platform and why each is needed.

Advertising data specifically

Where you connect an advertising account we read campaigns, spend, results and, with your permission, the leads your forms capture, so they can be passed to you and to your own systems. We write campaigns, creatives and budgets that you have approved.

Leads captured by an advertising platform belong to you. They are passed through and stored in your workspace so you can work them, and they are deleted with your workspace. They are never sold, never shared with another customer, and never used to train anything.

Where we send conversion events back to a platform to make measurement work, the personal identifiers in those events are hashed before they leave, as the platforms themselves require.

Model keys and drafting

Drafting uses your model provider key, relayed for that one request and never written down. We hold no model key of our own, on purpose: it means the platform keeps working with every external account disconnected, and it means your drafts do not pass through an account we control.

What we never do

  • Sell or rent anything about you or your customers, to anyone, for any purpose.
  • Use your data, your site, your adverts or your leads to train a model.
  • Show one customer’s data to another. Every scoped read puts your organisation in the query itself, and a request for somebody else’s row answers 404 rather than 403, because 403 would confirm the row exists.
  • Run advertising trackers on this site.

Deleting everything

Delete your workspace from your account settings and the server copy goes, along with the connected tokens, the audit log and any leads held for you. It is immediate rather than queued, and it is not reversible.

If you connected through a platform that offers its own deletion request, that request reaches us at /api/data-deletion and is honoured the same way, with a confirmation code you can use to check the status. You do not need to contact us to exercise this.

For anything else, including a copy of what we hold, write to the address on the security page. Thymesnow is operated from the United Kingdom and this site is thymesnow.com.

The short version

The audit sends us nothing. An account adds a server copy of your own workspace. Connected tokens are sealed per record and never returned by any route. You can delete all of it yourself, immediately.