Skip to content
NessFlow
Menu

Privacy

This document describes what the platform actually does. It is short because we process very little personal data.

Last revised:

  • No IP address is kept

    Your server logs are parsed as a stream, on our infrastructure. No IP address is written to a database, and none is passed to a third party or to a model.

    How the platform is held together

  • No analytics cookie

    The public site and its sign-up screen count page views without a cookie and without a persistent identifier. That is why it shows no consent banner: there is nothing to consent to. Once you are signed in, nothing is measured.

  • What leaves is written down

    We do not claim that nothing leaves: we say what leaves, to whom, and under which condition. The categories of recipients are rank and authority measurement, language-model interpretation, hosting, payment and email delivery. The named list is annexed to the contract, and any change is notified to you before it happens.

    What binds you, and what binds us

  • The durations are the ones in the code

    The table below is read from the purge commands the scheduler runs. It is not transcribed, so it cannot drift away from the product.

Account data

Name, email address, team membership, and the technical records authentication requires: open sessions, access keys. Kept for the lifetime of the account.

We buy no contact data and enrich no profile. What we know about you is what you wrote to us.

Audit data

The pages, links and measurements collected from the sites you audit. This is public web data, attached to your team and readable by that team alone.

A public page can carry personal data: a signature, a name inside an address. We do not look for it and we derive nothing from it, but it is part of the crawled content, and saying so is more honest than the alternative.

Uploaded server logs

Analysed as a stream, with no IP address stored in the database or passed to a third party. Uploaded files are deleted once processed; what survives are hourly and then daily aggregates.

That is the substantive difference from platforms that ship your logs off to an analysis service: here the file never leaves the infrastructure that reads it, and it does not stay there either.

Demo requests

What you type into the demo form is used only to reply to you. It is sold to nobody and feeds no third-party prospecting tool.

Where your visit came from is recorded without third-party cookies and without a persistent identifier: we know a campaign worked, we do not know what else you read.

Your rights

Access, correction, erasure, portability, objection. Email us: we reply within a month, and usually well before.

Export does not depend on us: every results screen carries its own exhaustive export, available for as long as the account exists. Getting your data back requires no request, no delay and no negotiation.

Retention periods

Every duration below is the one the scheduler actually applies: it is read from the matching purge command rather than transcribed into this page. A missing duration is not zero: it means no automatic purge, and the row says so.

Data Retention
Account, team and billing No automatic purge (kept for as long as the account exists)
Demo requests No automatic purge (kept for as long as the account exists)
Uploaded log files 24 hours
Hourly log aggregates 90 days
Daily log aggregates 400 days
Search Console records 480 days
Detailed ranking records 180 days
AI assistant answer excerpts 180 days
Notifications 90 days
Security signals 400 days
Usage events 400 days

A question about a specific processing activity, or need our contractual documents? Write to us through the demo form