Privacy policy.
Effective July 2026
01. Who we are
SilentStork is a website-health tool: you add a site, we read its pages and write you a short, prioritised reading. For anything in this policy, write to hello@silentstork.com — a person answers.
02. What we collect about you
Your account email, your name if you give one, and a hashed password (never the password itself). If you pay, billing is handled by Paddle (Paddle.com Market Limited), acting as Merchant of Record — Paddle processes your payment details under its own privacy policy, and we never see or store full card numbers.
03. What we collect about your sites
When you add a site and run a reading, we crawl its publicly reachable pages and store what we find — URLs, titles, headings, status codes, page content — so we can write your reading and track changes over time. We only crawl sites you add yourself.
04. Google Search Console
If you connect Search Console, we request exactly one scope: https://www.googleapis.com/auth/webmasters.readonly — read-only access to your Search Console data, used only to show your own query, click, and index-coverage data next to your pages. We can never write or change anything in your Google account. Sign-in with Google uses only the openid, email, and profile scopes. That is the full list. The access tokens are encrypted at rest, and you can disconnect at any time from the app, which deletes the tokens.
05. AI features
Readings, the action plan, and co-pilot answers are generated with large language models. To do that, we send relevant excerpts of your crawl data and your questions to OpenAI, acting as our sub-processor. Under our agreement, this data is not used to train their models.
06. Sub-processors
We keep the list short: our hosting and database provider (EU region), OpenAI for AI features, a transactional email service for account emails, Paddle (Paddle.com Market Limited) for billing, as Merchant of Record, and — only if you accept analytics cookies — Google (Analytics and Tag Manager). Write to us for the current named list.
07. Cookies and analytics
One session cookie, so you stay signed in — that one is essential and always on. Beyond that, the only optional cookies are Google Analytics (loaded through Google Tag Manager) to count visits and understand which pages help. They are off by default: nothing analytics-related loads until you accept it in the cookie banner, and you can change or withdraw that choice anytime from the privacy-settings button. We use no advertising trackers and no remarketing pixels.
08. How long we keep data
Account data is kept while your account is active. Crawl data is kept for the retention window of your plan, then deleted. If you delete your account, we remove your personal data and your crawl data within 30 days, except what the law requires us to keep (such as invoices).
09. Your rights
Under the GDPR you can ask for a copy of your data, ask us to correct or delete it, or ask us to export it in a portable format. Email hello@silentstork.com and we handle it within 30 days. You can also complain to your local data-protection authority.
10. Security
Data is encrypted in transit and at rest. Integration tokens are additionally encrypted at the application level. Access inside the team follows least privilege, and we do not sell or rent your data to anyone, ever.
11. Legal basis
We process your account data to provide the service you signed up for (contract), and minimal usage data to keep the service reliable and secure (legitimate interest). Nothing is processed for advertising.
12. Children
SilentStork is not directed at children and is not intended for anyone under 16.
13. Changes to this policy
If we change this policy in a way that matters, we will email account holders before it takes effect. The current version is always on this page.
14. Contact
hello@silentstork.com — for privacy requests, questions, or anything this page left unclear.