Legal
Privacy Policy
Last updated: September 21, 2026
TrustTraffic (“TrustTraffic,” “we,” “us”) runs trusttraffic.net and the TrustTraffic dashboard, and publishes the @trusttraffic/tracker package that site owners install on their own servers. This policy explains what we collect across all of that, why, and the choices you have. It applies to (a) visitors and account holders on trusttraffic.net itself, and (b) the crawler-traffic data our customers send us from their own websites.
The short version: we don’t track your website’s human visitors. The tracker only reports requests that identify themselves as a known AI crawler (GPTBot, ClaudeBot, PerplexityBot, and similar) via their User-Agent string — it runs server-side, ships no script to browsers, sets no cookies on your visitors, and does no fingerprinting.
1. Information we collect
Dashboard accounts. You create an account with an email address and a password, or by signing in with Google — in which case Google tells us only your email address and that it’s verified; we never see your Google password or contacts. Passwords are stored only as a salted scrypt hash. We store your email, account-creation date, onboarding status, plan, and your email preferences (notifications on/off, marketing opt-in). Password recovery sends a signed link (valid 15 minutes) to your email address.
Sites you add. For each site you connect, we store the domain and a randomly generated tracker token used to authenticate hits from that site.
AI-crawler hit data. Once you install the tracker on your own site, it sends us one record per detected AI-crawler request: the request path, the crawler’s name/vendor/category, the HTTP status code, the crawler’s User-Agent string and IP address, and a timestamp. This is traffic data about bots hitting your server, not data about your site’s human visitors.
Opt-in human count. If you enable the human-traffic comparison, the tracker sends only an aggregate count of non-bot page views per day — no path, no User-Agent, no IP, no per-visitor record of any kind.
Citation checks (paid plans). The search queries, engines, schedule and competitor domains you configure are saved against your site. When a check runs, each query is sent — as plain search terms, with nothing that identifies you or your account — to the AI providers you selected (OpenAI, Perplexity, and Google AI Overviews via SerpApi), and the list of cited domains they return is stored with your site, along with a record of the tokens each check used.
robots.txt checker. The public “which AI bots does this site allow” tool on our homepage fetches the robots.txt of whatever domain you enter and reports which crawlers it permits. We don’t store the domains you check.
Log & technical data. Like most web services, our servers see the IP address and request metadata of anyone using trusttraffic.net. We use this transiently for abuse prevention (rate limiting) and don’t build visitor profiles from it.
2. Cookies and analytics
We set only functional cookies — no advertising or cross-site tracking cookies. One further value lives in your browser’s local storage (not a cookie) to remember that you’ve seen the cookie notice.
| Name | Purpose | Lifetime |
|---|---|---|
ttfc_session | Keeps you signed in to the dashboard | 30 days |
ttfc_in | Lets the public pages show that you’re signed in (holds no account data) | 30 days |
ttfc_oauth_state, ttfc_oauth_next | Set only while you sign in with Google, to tie Google’s reply to your browser | 10 minutes |
ttfc_theme | Remembers your light/dark preference | 1 year |
ttfc_consent (local storage) | Remembers your cookie-notice choice | Until you clear site data |
Analytics. We may measure site usage with Plausible, a cookieless, privacy-focused analytics service that records page views (including in the dashboard) without identifying individual visitors. It sets no cookies.
3. How we use information
- Operate the dashboard and show you your own crawler-traffic data
- Authenticate requests from your installed tracker and your dashboard session
- Notify you about material changes to the service
- Send you product updates and offers — only if you opted in, and you can untick it in Settings any time
- Prevent abuse of public endpoints (rate limiting, fraud/spam prevention)
- Debug and improve the service
We do not sell personal information, and we do not use your data to serve you or anyone else advertising.
If you’re in the UK or EEA, our legal bases are: performance of a contract for running your account, your sites, your crawler data and your citation checks; legitimate interests for keeping the service secure and working (rate limiting, abuse prevention, debugging, aggregate usage measurement), balanced against your privacy; consent for product-update and offer emails, which you can withdraw at any time in Settings; and legal obligation for keeping payment and tax records.
4. Who we share it with
We use a small number of service providers to run TrustTraffic, each acting on our behalf under their own terms:
- Resend — sends password-recovery links and, on paid plans, your daily alert digest.
- Google — only if you choose “Continue with Google”: Google’s sign-in service confirms your email address to us.
- Supabase — hosted database for account, site, hit, and citation data.
- Stripe — processes payments on paid plans. You enter your card details on Stripe’s own checkout page; we never see or store them. Stripe tells us which plan you bought and a customer id so we can apply it to your account, and handles renewals and cancellations through its billing portal.
- OpenAI, Perplexity, SerpApi — receive the search queries you configure for citation checks (plain search terms only; no account or personal data), each under its own terms.
- Plausible — cookieless site usage measurement, as described in Section 2.
- Our hosting/infrastructure provider, to run the application itself.
We don’t share your data with anyone else, except where required to comply with the law, enforce our Terms, or protect the rights, property, or safety of TrustTraffic or others.
5. Data retention
We keep account and site data for as long as your account exists. Deleting a site from the dashboard deletes its stored crawler-hit history, citation configuration and citation results immediately; the record of how many tokens were used, and the query text of each check, stays on your account’s usage ledger for as long as your account exists — it’s what your allowance is counted from. Payment records are kept for as long as tax and accounting law requires. Deleting your account deletes the ledger with it. You can request deletion of your account and associated data at any time — see Section 7.
6. Security
Session cookies and recovery links are signed, HTTP-only, sent only over HTTPS, and verified with a constant-time comparison to resist timing attacks. Passwords are stored only as salted scrypt hashes. Public endpoints are rate-limited. No method of transmission or storage is 100% secure — see the Terms for what that means about warranties.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent you have given. If you’re in the UK or EEA you can also complain to your local data protection authority (in the UK, the ICO at ico.org.uk) — we’d rather you told us first so we can fix it. To exercise any of these, email us at hello@trusttraffic.net — we’ll respond within a reasonable time.
8. Children
TrustTraffic is a website-analytics tool intended for businesses and developers. It is not directed at, and we do not knowingly collect information from, children under 16.
9. International transfers
We and our service providers may process data in countries other than the one you live in, including the United States. Where personal data leaves the UK or EEA, those transfers rely on the providers’ Standard Contractual Clauses or their certification under the EU–US Data Privacy Framework — email us and we’ll point you at the relevant terms for each provider.
10. Changes to this policy
We’ll update the “Last updated” date above when this policy changes, and post the revised version here. Material changes will be flagged more prominently where appropriate.
11. Contact
Questions about this policy or your data: hello@trusttraffic.net.