Security & your data

Plain statements you can check. We don't hold a SOC 2 or ISO certificate yet and we won't pretend otherwise — here is what is true today, by design.

What the tag does

  • Records what happens after an ad click on your site: timing, scroll and mouse movement, repeat visits, the advertising click ID, and technical characteristics of the visit (IP address, browser, device).
  • Loads asynchronously and fails open. If our servers are unreachable, blocked by an ad blocker, or refused by your content-security policy, your page renders exactly as it did before.
  • Under 30 KB, first-party, zero third-party runtime dependencies — every byte is ours and auditable.

What the tag never does

  • Never reads form fields, page text, names, emails, addresses or payment details. Interaction metadata only.
  • Never sets tracking cookies for advertising, never tracks visitors across other websites, never sells or shares data with advertisers.
  • Never modifies your page, overrides your other scripts, or runs in the critical rendering path.
  • Never retries in a loop if delivery fails — losing telemetry is our problem, slowing your site is never acceptable.

Where your data lives

  • Application and database hosted in London (UK) — Fly.io and Neon (AWS eu-west-2). Edge network and TLS by Cloudflare.
  • Encrypted in transit (TLS 1.2+, HSTS) and at rest by our hosting providers.
  • Sub-processors are listed in our Privacy Policy.

How long we keep it

  • Raw click telemetry is kept for 90 days — Google's ~60-day claim window plus a buffer — then deleted. Aggregates that identify nobody may be kept for reporting.
  • Close your account and we delete your telemetry within 30 days.

What access we ask for

  • Your website: one tag, which you can remove at any time.
  • Google Ads: read-only at first. Blocking and claim filing each need a separate permission you grant explicitly, when you're ready.
  • Sign-in: no passwords stored — one-time email links or Google sign-in.
  • Payment: nothing during early access. No card on file.

Your visitors, wherever they are

  • We process visitor data as your processor under UK and EU GDPR, and handle it to the same standard for visitors in the US, Canada or anywhere else.
  • Guidance for your own privacy notice is in our Privacy Policy.

Found something?

We'll add certifications here when we have them, not before. Last updated 14 September 2026.