legal / legal

Privacy

No account, no advertising profile, and everything a run produces is deleted after seven days.

Last updated 10 September 2026.

who is responsible

Next Marketing Technology Ltd is the data controller for geo.new, registered in England and Wales under number 14384054, at Flat 1, 25 Daleham Gardens, London, England, NW3 5BY. This policy is written under the UK GDPR and the Data Protection Act 2018.

Questions, requests and complaints go to [email protected] and are read by a person.

controller
Next Marketing Technology Ltd
registered office
Flat 1, 25 Daleham Gardens, London, England, NW3 5BY

what a run collects

Five things, and this is the whole list.

Your address is hashed at the edge of the application, before anything is written down. What the database holds is a keyed HMAC-SHA256 digest used to count requests; the address itself is never stored in it.

the URL
the address you submit, and the report produced from it
a cookie
geo_session — httpOnly, SameSite=Lax, seven days. It is how a report knows it is yours. There is no second cookie.
your IP
kept only as a keyed hash, for rate limits and abuse counters
an API key
if you create one: stored as a hash, with the count of audits it has run
your theme
light or dark, in your own browser’s storage. It is never sent to us.

what it does not collect

No name, email address, postal address, phone number or payment details. There is no account to hold them in and nothing to buy with them.

No advertising cookies, no cross-site trackers, no fingerprinting, no data brokers, no marketing list. Nothing here is sold or shared for marketing, at any price.

Audited URLs, query strings, page content and model prompts are deliberately kept out of our application logs.

why we hold it

To run the audit you asked for and to show you the report afterwards. That is the service you requested, and the URL and the session cookie are what make it possible.

To keep the tool standing: our legitimate interest in preventing abuse and staying inside the cost ceilings a free service has. The hashed address and the request counters do that and nothing else.

To know whether it is used at all: our legitimate interest in aggregate counts — audits per day, keyed against keyless. No profile of a person is built, and none could be.

how long any of it lasts

Expiry is enforced by the database on a schedule, not applied by hand when someone remembers.

reports
seven days from the run — the report, its evidence, its screenshot and any share made from it
sessions
seven days, and no longer than the reports attached to them
admission records
twenty-four hours (hashed address, hashed target)
request counters
one hour
API keys and usage
while the key exists. Revoke it, or ask us, and it goes.

analytics

One script, from TinyAnalytics, counts which pages get opened. It is cookieless and sets no identifier that follows anyone to another site.

It is configured to skip every path that carries an audited URL, to mask report and share addresses to a bucket, and to ignore query strings. The analytics record cannot say what anybody audited, because it is never told.

who else touches it

The text extracted from an audited page is sent to Cloudflare’s Workers AI to write the interpretation section of the report. It is sent for that one call. We do not train anything on it and we pass it to nobody else.

Two lookups leave our network about the audited brand rather than about you: public entity records at Wikidata and Wikipedia, and, for the brand-search check, a search-result probe through scrape.do. Neither carries anything about the visitor who started the run.

Processing happens on infrastructure inside and outside the United Kingdom. Where a transfer leaves the UK it relies on the standard contractual clauses and the UK addendum in each provider’s terms.

Cloudflare
hosting, the edge network, the job queue, the browser that takes the screenshot, and the model that writes the interpretation
Neon
the PostgreSQL database the reports live in, over verified TLS
TinyAnalytics
cookieless page analytics

when somebody audits a page you own

Any public page can be audited, and pages get audited by people who do not own them. The report then holds that page’s own public content, including whatever personal information its author chose to publish there.

If you operate a page and want a report about it removed, write to [email protected] with the address. It will be deleted — and it would have been deleted within seven days regardless.

To keep GeoNewBot away altogether, disallow it in robots.txt. The audit reads robots.txt first and stops there when it is told to.

your rights

You may ask for access to your data, correction of it, erasure, restriction or portability, and you may object to processing we base on legitimate interests.

There is no account here, so identifying “your” data usually means telling us a report id or a share token. Ask at [email protected]; the answer comes within a month, normally much sooner.

You can also complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk. We would rather you told us first and gave us the chance to fix it.

how it is kept

Session tokens and share tokens are stored as hashes and never in the clear. Reports are served no-store and are excluded from indexing. The database connection uses certificate-verified TLS.

The code that touches raw page HTML runs isolated from everything else and may return only a bounded, structured summary, so a hostile page has nothing to reach.

No system is airtight. What this one offers is a small surface and a short retention: little is collected, and what is collected does not stay.

children

This is a developer tool and it is not directed at children. We do not knowingly collect anything from a child under thirteen.

changes to this policy

The date at the top of this page is the date of this version. If what we do with data changes, this page changes first.

Anything unclear on this page is a defect in it. Write to [email protected] and it gets rewritten.

[email protected] · Terms of Use

run a free auditOne URL. No signup.