menu
Check my site →

CLICK CODED · PRIVACY POLICY

What we collect, exactly

Last updated 2026-08-01. Written against our actual source code rather than from a template, which is why it names specific storage keys instead of saying "certain information."

This policy covers clickcoded.com and its subdomains, the free AI-visibility checker, and Pulse. The data controller is Brandon George, of [[BUSINESS ADDRESS — held pending a registered-agent/virtual address, decided 2026-08 not to use a home address]], trading as Click Coded. Reach us any time at [email protected].

The short version

1. What we collect on each surface

Reading clickcoded.com

The site is static files. No account, no cookie, no analytics script, no local storage. Our hosting providers keep standard server logs (see section 4), and your browser fetches fonts from Google.

Running the free checker

When you submit a URL, we process:

WhatWhere it livesHow long
The URL you submittedCached result, keyed by that URL — not linked to youShort-lived cache
Your IP addressCloudflare KV, key rl:<ip>:<minute>, used only to count requests per minute70 seconds, then auto-expires

That is the whole of it for an anonymous check. We do not build a profile, we do not log which person checked which site, and the cached result is keyed by the URL, not by you.

Giving us your email on the results page

This is optional and you have to type it. If you do, we store one record:

WhatWhere it livesHow long
Your email address, the URL you checked, the score it received, and the timestampCloudflare KV, one record keyed by your emailUntil you ask us to delete it (see section 6)

We also email a copy of that record to ourselves at [email protected] so a human sees it.

Subscribing to Pulse

Payment happens on our storefront provider's checkout, not ours (section 4). The provider tells us a sale happened and passes us your email and a subscription ID. We then store, in a Cloudflare D1 database:

WhatWhy
Your email addressTo send you the reports you are paying for
Your tier and report cadenceTo run the right checks on the right schedule
A random access tokenYour unguessable dashboard link — it is your key, so treat it like one
The URLs you monitor, plus a competitor URL on the Pro tierThey are the thing being checked
Every report generated for you: date, score, and the full check detailSo the dashboard can show change over time — that history is the product
Your subscription ID from the payment provider, and whether it was cancelled or refundedTo keep billing and access in sync

What we never receive

Your card number, CVV, or billing address never reach us. They go to the payment provider, which is the merchant of record for the sale. We see that a payment succeeded, your email, and a subscription ID.

2. What we deliberately do not collect

Stated positively so it is checkable: there is no Google Analytics, no Meta pixel, no advertising or remarketing tag, no session recording, no heatmap, no A/B testing script, no fingerprinting, and no cookie of any kind — including "essential" ones — on clickcoded.com or the tools. You can verify this by viewing the page source or opening your browser's network tab, which is the sort of thing we would rather you did than took our word for.

3. Why we are allowed to hold it

If you are in the UK or EU, these are our lawful bases under the GDPR:

4. Who else touches your data

We use these providers. We do not sell data to anyone, and none of these are advertising relationships.

ProviderWhat it doesWhat it sees
CloudflareCDN, our Workers, the KV and D1 storage described above, and outbound emailEverything in section 1, plus standard request logs including IP
GitHub (Pages)Hosts the static siteStandard web server logs, including IP
Google FontsServes the typefaces the site usesYour IP address and browser details, on every page load
Our storefront and payment providerSells our products as merchant of record, takes payment, handles taxYour payment details, billing info, and email — under its own privacy policy
The Google Fonts disclosure, since most policies leave it out.

Our pages request fonts from fonts.googleapis.com and fonts.gstatic.com. That request carries your IP address and user-agent to Google before you have interacted with anything. It is not tracking we chose to add — it is a consequence of loading fonts from Google's CDN rather than our own server — but the data flow is real either way, so it belongs in this table rather than in a footnote. A German court has treated exactly this as a privacy matter. If you would rather not make that request, a content blocker will stop it and the site will still work, just in a fallback typeface. We intend to self-host these fonts and remove the flow entirely; when that ships, this box gets replaced with the receipt.

Our providers are US-based and operate globally, so your data may be processed outside your country, including in the United States. Where transfers out of the UK or EEA happen, they rely on the providers' own safeguards, typically Standard Contractual Clauses.

5. How long we keep things

6. Your rights, and how to actually use them

Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, take it elsewhere in a portable format, and withdraw consent. If you are a California resident, you also have the right to know what we collect and to opt out of sale or sharing — noting that we do neither. We will not discriminate against you for exercising any of these.

How to exercise them: email [email protected] from the address you want us to act on, or tell us which address it concerns. There is no form and no portal. A human reads it. We aim to respond within 30 days, which is the GDPR deadline, and usually much sooner because we are small.

We may need to confirm you control the email address before we delete or hand over data, since an emailed request is the only identity we have.

If we get it wrong, you can complain to your data protection authority — in the UK, the Information Commissioner's Office. We would appreciate the chance to fix it first.

7. Security, stated honestly

Data is held on Cloudflare and GitHub infrastructure and travels over HTTPS. Access to our storage is limited to the operator. Your Pulse dashboard is protected by an unguessable token in its URL rather than a password, which is a deliberate trade: no password for you to manage, but anyone with that link has access, so do not paste it anywhere public. If you think your link has leaked, email us and we will issue a new one.

We are a very small operation. We do not hold a security certification, and no system is perfectly secure. If you find a vulnerability, email [email protected] — we will not send lawyers after anyone reporting a genuine issue in good faith, and we will credit you if you want it.

8. Children

The Services are for business use and are not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.

9. An AI processes this data

Click Coded is an AI-operated studio, disclosed everywhere. An AI system writes the code that handles your data, runs the audits, drafts the emails, and wrote this policy, all under human review. Your data is processed by that automated system in the ordinary course of delivering the Service.

We do not use your personal data to train AI models, and we do not sell it to anyone who does. No decision with a legal or similarly significant effect on you is made about you by automated means — the scores we produce are about your website, not about you as a person.

10. Changes

If we change this policy we update the date at the top. If a change materially affects how we handle data you have already given us, we will email you about it rather than relying on you to re-read the page.

11. Contact

Click Coded · [email protected]
Brandon George, [[BUSINESS ADDRESS — held pending a registered-agent/virtual address, decided 2026-08 not to use a home address]]

Don't trust this page either.

This policy names specific storage keys and retention periods so it can be checked rather than believed. If you find a claim here that our software does not actually honour — a field we collect but did not list, a deletion we did not perform, a third party we did not disclose — that is exactly the failure our whole product line exists to catch, and we want it on the record. Tell us and the correction goes on the receipts log with your catch attached.

Click Coded. AI-operated, human-reviewed, disclosed everywhere. See also the Terms of Service.