self-serve ~24 h sold never training never

Privacy.

Short, because little happens here.

Analytics

Pages load a pageview counter on Umami, self-hosted on infrastructure we operate at analytics.playkeg.com. Playkeg is another project by the same one-person operation; the analytics instance is ours, not a vendor’s. It sets no cookies and keeps no cross-visit identifiers.

Named interaction events also fire, with no form contents and no scanned page text: tool_start when you start a scan or when you click or copy the queue address. Event names, page URLs, and a coarse interaction label (which form or button fired the event) only. Never email addresses or anything from a scanned site.

Self-serve scans

When you run a scan at /scan/, your URL is used to crawl and review the site. The report lives at an unguessable link and is kept for about 24 hours, then deleted. The link is unguessable but not access-controlled: to keep the free tier simple, a repeat scan of the same domain inside that window is handed the same report, so anyone who scans your domain that day sees it. Accounts will close that gap and bring persistent history across runs. Non-public and internal addresses are refused. The crawl is passive.

Separately from that 24-hour report, we keep a durable operator log of each scan attempt: the hostname and path you submitted (query strings stripped), whether it was accepted, reused, rejected, completed, or failed, how many pages were captured, token counts, and a cost we compute from those tokens. No page contents, no emails, no cookies, no raw IP addresses. We use this to see what people scan and what it costs. We do not sell it.

Your browser also keeps a local record of your last scan — its id, URL, and report link, under slopguard:lastScan — for about 24 hours, so the scan pages can offer to resume it. It never leaves your browser.

Queue submissions

When you submit a site to the roast queue, your URL is used to run the report and your email address to reply to you. Your submission email stays in the inbox you wrote to and is deleted on request. A run keeps more than the report: the rendered snapshot of each page and the behavior we observed are stored as your run history, so a later run can be compared against this one and an unchanged URL need not be re-crawled. That history is yours: private unless you publish it, never sold, never used to train anything, and deleted on request.

Reports belong to the site owner. Publishing to the queue needs your OK after you have read yours. A report you keep private stays private.

Nothing else

No accounts. No ad tech. No third-party trackers. We do not sell your data.

Questions: hello@hexento.com.