Privacy Policy
Last updated: August 5, 2026
This policy covers geoready.dev, the public website: the free audit, the tools, the guides, and the emails you can ask us for. The signed-in application has its own policy at app.geoready.dev/privacy, because it processes different data.
Data controller
Juan Camilo Auriti
Email: juancamilo.auriti@gmail.com
Write to that address to exercise any of the rights below; we answer within one month, as the GDPR requires. For bugs and technical issues, an issue on GitHub is faster.
What we process, and why
1. URLs you submit for audit
When you run an audit we fetch the publicly available pages of the URL you submit, analyse them and return a score. We do not log into your site and read nothing that is not publicly served. The report is generated for you; we do not build a profile of you from it.
The report is stored for 24 hours, held against a single-use token rather than against you, so that you can claim it into an account if you decide to create one. It contains the URL, the score and the analysis — no name, no email, no IP address. After 24 hours the token stops working and the report is no longer retrievable.
A URL is normally a company address rather than personal data, but it can be personal data — a personal domain, or a URL containing a name. Treat it as such and submit only URLs you are entitled to submit.
Legal basis: performance of the service you requested, or steps taken at your request before a contract (GDPR art. 6(1)(b)).
2. Aggregate benchmark statistics
To publish aggregate research on how sites score, we record one row per audit containing a keyed hash of the domain (not reversible to the domain by a third party), the top-level domain, the score and the date. Published figures are aggregate only: no individual domain or score is identifiable in them.
Legal basis: legitimate interest in measuring and publishing aggregate research on AI search visibility (GDPR art. 6(1)(f)). You can object — see “Your rights”.
3. Email address, when you ask for something by email
There are three places you can give us an email address, and all three are optional:
- The full audit report by email. After an anonymous audit you can have the complete eight-category report sent to you. We store the address so the report can be sent and so we can recognise a repeat request.
- The GEO Readiness Manual. We send a download link valid for 24 hours. On that form, marketing updates are a separate checkbox: leave it unticked and you get the manual and nothing else. If you would rather give no address at all, the free three-chapter preview requires none.
- The newsletter. The State of GEO report and occasional findings, when you subscribe from a guide or resource page.
In each case we store the address, which page it came from, and the date and content of your consent — the last of these because we have to be able to demonstrate it (GDPR art. 7(1)). Every email has a one-click unsubscribe link. We do not sell, rent or share your address.
Legal basis: performance of your request for the report or manual (GDPR art. 6(1)(b)); consent for marketing updates and the newsletter (art. 6(1)(a)), withdrawable at any time.
4. Analytics — only with your consent
If you accept analytics, Google Analytics 4 records which pages you visit, which buttons you use and where you arrived from, so we can tell what is worth building. Until you accept, the tag is not loaded at all: no request goes to Google and no analytics cookie is set. Google Signals and advertising features are off, and IP addresses are truncated and not retained for visitors in the EU.
This is a change from an earlier version of this page, which said analytics was configured but not active. It is active, subject to consent — the Cookie Policy lists exactly what it sets. That is also why the banner asked you again.
The Analytics property is linked to Google Ads, which means conversion events measured with your consent — such as requesting the manual — are imported into that advertising product so we can see which campaigns work. This changes nothing about what is stored on your device: no advertising cookie is set, no advertising tag is loaded, and no remarketing audience is built. If you decline analytics, or decline marketing, Google receives the corresponding signals as denied and measurement is limited accordingly.
Legal basis: consent (GDPR art. 6(1)(a); ePrivacy Directive art. 5(3)). Withdraw it at any time from the cookie preferences panel — the button at the bottom left of every page.
5. Cookie and privacy choices
Your consent choices are kept in localStorage on your device with a 6-month expiry, or until the policy version changes. This never leaves your device and is not sent to any server.
Legal basis: technical necessity — recording your choice is what makes it possible to honour it and to demonstrate compliance (GDPR art. 7(1)); exempt from consent under the ePrivacy Directive.
6. Abuse prevention
The audit and the email endpoints are rate-limited per IP address, so one visitor cannot exhaust the service or use it to send mail to strangers. Those counters are held in memory only, for the length of the rate-limit window, and are never written to a database or used for anything else.
Legal basis: legitimate interest in keeping the service available and preventing abuse (GDPR art. 6(1)(f)).
7. Log files you upload for analysis
The log-analysis endpoint accepts a server log file and reports which AI crawlers visited your site. The file is written to a temporary file, parsed, and deleted immediately afterwards — it is never stored and never used for anything else. Server logs typically contain visitor IP addresses, so you are the controller of that data: upload only logs you are entitled to process, and be aware that the request travels to our server.
Legal basis: performance of the analysis you requested (GDPR art. 6(1)(b)); we act as processor for the contents of the file.
8. Server logs
The infrastructure logs IP addresses, request paths, response codes and timestamps, as any web server does, to investigate errors and abuse. These are not used for profiling.
Legal basis: legitimate interest in operating and securing the service (GDPR art. 6(1)(f)), and art. 32 security obligations.
Who else processes your data
A small number of providers, each acting as a processor under a data processing agreement.
| Provider | Purpose | Where |
|---|---|---|
| Resend | Delivering the reports, manual links and newsletter you request | United States |
| Google Ireland Limited | Google Analytics 4 — only with your consent | Ireland / United States |
| Google Ads | Receives aggregate conversion measurements imported from Analytics, to attribute results to campaigns — only with your consent | Ireland / United States |
| Launchpadly | Serves the directory badge image in the footer | Outside the EU |
| Hosting provider | Servers, database, backups, server logs | European Union |
We do not sell personal data, and we do not share it with data brokers. One sharing arrangement does exist and is worth stating plainly: the Google Analytics 4 property is linked to Google Ads, so aggregate conversion measurements collected with your analytics consent are made available to that advertising product to tell us which campaigns produce results. No advertising cookie is set on this site, no advertising tag is loaded, and no audience or remarketing list is built from your visit. Links to GitHub, PyPI and other external sites in the footer are plain links: nothing is sent to them unless you click.
One exception worth naming: the Launchpadly badge in the footer is an image loaded from launchpadly.co, so displaying it sends your IP address and browser type to that provider, as any remote image does. It sets no cookie and builds no profile. The guides are published from the Sanity content platform, but the pages are generated at build time — your browser makes no request to Sanity when you read them.
Transfers outside the EU
The site, its database and its logs are hosted in the European Union. Some providers are established in the United States, so a transfer can occur for those services. Where it does, it relies on:
- the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023 (decision 2023/1795), where the provider is certified under it — Google states it is, for both Analytics and Ads; and
- the European Commission’s Standard Contractual Clauses, together with the UK Addendum where relevant, as the fallback mechanism.
Ask us at the address above and we will tell you which mechanism applies to a given provider.
How long we keep it
- Audit results: stored 24 hours against a single-use claim token, then no longer retrievable. Not linked to your identity — on this site you do not have one.
- Benchmark rows: retained indefinitely in hashed, aggregate form, as research data.
- Email addresses: kept until you unsubscribe or ask us to delete them. The record that you consented is kept for as long as we could be asked to prove it.
- Uploaded log files: deleted as soon as the analysis finishes — seconds.
- Rate-limit counters: in memory only, for the length of the window.
- Analytics data: retained by Google under the retention setting on the property; we use the shortest available. Conversion measurements imported into Google Ads follow that product's own conversion windows.
- Server logs: rotated, typically kept 14–30 days.
- Consent choice: on your device for 6 months, or until the policy version changes.
Your rights
Under the GDPR you have the right to:
- know what we hold about you and get a copy of it (art. 15);
- have inaccurate data corrected (art. 16);
- have data erased (art. 17);
- restrict processing while a dispute is resolved (art. 18);
- receive your data in a portable, machine-readable format (art. 20);
- object to processing based on legitimate interest, including the benchmark statistics (art. 21);
- withdraw consent at any time, without affecting processing already carried out lawfully (art. 7(3));
- not be subject to solely automated decisions with legal or similarly significant effects (art. 22) — we make none.
If you believe we have handled your data wrongly you can complain to your national data protection authority. In Italy that is the Garante per la protezione dei dati personali.
Children
GeoReady is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Cookies and local storage
Only necessary storage is active without consent; analytics is off until you accept. For the full inventory — every cookie and storage key, its purpose, provider, legal basis and duration — see the Cookie Policy.
Changes to this policy
We update this policy when what we actually do changes, and the date at the top says when. If a change affects what you consented to, the cookie banner asks again rather than assuming your previous answer still applies.