sclawl / privacy
Privacy
DRAFT — not legal advice, verify with a qualified lawyer.
Operator and contact
Operator: Pending confirmation. Privacy contact: Pending confirmation.
What the service processes
A comparison processes two public URLs, your selected purpose and any optional clarification. Public pages are fetched and relevant excerpts are sent to Cloudflare Workers AI. Do not submit confidential information, signed URLs or access tokens. The service has no accounts and does not collect payments.
External services and requests
Cloudflare hosts the site and API and receives network metadata such as your IP address. Workers AI receives public excerpts, source URLs, the selected purpose, clarification and the proposed findings for a second review.
Cloudflare DNS-over-HTTPS receives the hostnames being checked. The Common Crawl index receives the submitted hostnames to discover archived policy URLs. Archived pages are not sent to the model as current evidence.
The websites you submit receive requests from Cloudflare infrastructure for public pages, robots.txt, sitemaps and security.txt. They receive requested paths and query strings, and the sclawl user agent. The application does not forward your browser cookies or your IP address to those sites.
When enabled, Cloudflare Turnstile checks the comparison form for automated abuse. Its widget connects to challenges.cloudflare.com and processes browser and network signals. Its response token is sent to the service for server-side verification.
Storage and deletion
The application keeps comparison inputs, retrieved content and results in request memory and in the open browser page. It does not write them to a server database or application logs. Closing or reloading the page removes the displayed report. This does not remove infrastructure records maintained by external providers.
The daily abuse-control counter stores only a UTC date and a number, without URLs, report content, purpose or a user identifier. Counter entries expire after two days. Provider infrastructure retention and international transfer arrangements are listed as release questions for legal review, so no universal deletion period is promised here.
Cookies and device storage
The application sets no cookies and contains no advertising or marketing analytics. Scan metadata is saved in localStorage only when you select “Remember this scan on this device”. It includes policy-page URLs, fingerprints, policy dates and the save time, not quotations or a full report. Up to 20 website snapshots are kept until you clear them, replace them with a later saved scan or clear browser data.
“Clear saved scans” removes these snapshots, including ones saved by earlier versions. The feature is local to this browser and device. Turnstile must be configured without pre-clearance cookies. Cloudflare security settings require a separate configuration check before publication.
Your requests
Contact the address above to ask about access, correction, deletion or other rights available under the law that applies to you. Do not send identity documents or confidential reports in your first message. Because comparison content is not stored by the application, we may be unable to locate a previous comparison. You can delete saved device metadata using “Clear saved scans”.
Legal review before release
The applicable legal bases, operator duties, notice requirements, user-rights procedures and international transfer safeguards must be finalized for the actual operator and intended markets. No consent or transfer mechanism is assumed by this draft.