Skip to main content

Bozarth Software LLC

SiteBrief Privacy Policy

Effective date:
August 27, 2026
Last updated:
August 27, 2026

This Privacy Policy explains how Bozarth Software LLC (“Bozarth Software,” “we,” “us,” or “our”) collects, uses, discloses, and retains information when you use SiteBrief, our websites, reports, accounts, and related services (collectively, the “Service”).

1. Information we collect

Information you provide: Account information (email address, display name, authentication records, and account preferences); submitted website information (the sanitized website address, normalized origin, and hostname you submit for evaluation); authorization confirmation that you own, manage, or have permission to evaluate the submitted website, together with the date, user, and applicable Terms version; purchase and entitlement information including selected offer, purchase status, Stripe customer and transaction identifiers, access allowance, usage period, complimentary-access status, grant reason, expiration, and revocation (we do not receive or store full payment-card numbers); and communications, support requests, feedback, and information you choose to include.

Information created through a scan: scan identifiers, status, timing, version, completeness, limitations, consumption status, and expiration target; short factual observations from the publicly accessible home page, such as response status, content type, title, meta description, canonical address, language declaration, viewport metadata, robots metadata, and heading count; deterministic findings, priorities, explanatory text, recommended actions, confidence labels, and evidence references; and records of sites and reports associated with your account.

SiteBrief is designed not to store page bodies, raw response headers, website credentials, authentication tokens, submitted query strings, URL fragments, cookies from the submitted website, or private form data. The scanner does not sign in to submitted websites or execute page JavaScript.

Information collected automatically: We and our service providers may collect limited operational information, such as IP address, browser or device type, timestamps, authentication/session identifiers, request identifiers, error and security events, and service-performance logs. Infrastructure providers may also record network destinations necessary to route and secure requests.

2. How we use information

We use information to create and authenticate accounts; validate, perform, and record authorized website scans; generate and display reports; process purchases and administer paid, owner, beta, or complimentary access; enforce scan, rate, concurrency, payment, and security limits; provide support and service communications; diagnose failures, secure the Service, prevent fraud and abuse, and protect users and third parties; maintain, analyze, and improve reliability, checks, prioritization, and report presentation; comply with law, enforce our agreements, and establish or defend legal claims; and create aggregated or de-identified operational information for internal analysis.

We do not use customer scan data to train a general-purpose artificial-intelligence model. We do not use AI to generate SiteBrief findings. We will not introduce materially different AI processing of submitted websites or customer information without updating our disclosures and obtaining consent where required.

3. Service providers and disclosures

We may disclose information to service providers that perform services for us. Current providers may include:

  • Lovable for application development/deployment and managed project infrastructure;
  • Supabase / Lovable Cloud for database and authentication services;
  • Railway for the bounded website-retrieval worker;
  • Stripe for payments and transaction processing;
  • Zoho Mail for business email and support/privacy communications; and
  • Cloudflare for domain/DNS and related infrastructure services.

Providers receive information only as reasonably necessary to perform services for us and are subject to their own terms and privacy commitments. We may change providers as the Service evolves.

We may also disclose information for legal and safety reasons when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, users, third parties, or the Service; in a business transaction involving financing, merger, acquisition, reorganization, sale of assets, or a similar transaction, subject to appropriate protections; and with your direction or consent.

The retrieval worker that contacts a submitted public website does not receive a SiteBrief database credential, payment credential, or your account password. The destination website and its infrastructure may nevertheless observe a request from SiteBrief’s retrieval service, including ordinary network information and the requested public origin.

4. No sale, cross-context behavioral advertising, or targeted advertising

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use SiteBrief information to target advertisements based on activity across unrelated websites or services.

5. Cookies and similar technologies

SiteBrief may use cookies, browser storage, or similar technologies that are necessary for authentication, session continuity, security, preferences, and core functionality. We do not currently use cross-site behavioral advertising trackers.

Because we do not sell or share personal information for cross-context behavioral advertising, browser “Do Not Track” signals do not change our practices. If legally required, we will process applicable opt-out preference signals, such as Global Privacy Control, consistent with law.

6. Retention and deletion

We retain information only as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining security and transaction records, resolving disputes, and meeting legal obligations.

Account and profile information generally remains while your account is active and for a reasonable period afterward when needed for legal, security, or operational purposes.

Each scan receives an expiration target of 90 days after creation.

SiteBrief runs a scheduled cleanup process that removes expired terminal scan records in bounded batches. Related scan observations and findings are deleted through database relationships when the scan is removed.

Site records may remain in your account after an expired scan is removed. You may delete eligible sites or your account through available controls.

Payment, order, entitlement, accounting, fraud-prevention, dispute, and legal records are not deleted merely because a scan expires and may be retained as reasonably necessary for those purposes.

Operational and security logs may be retained for a shorter or longer period depending on security, diagnostic, provider, and legal needs.

Information may persist temporarily in encrypted backups or provider systems until normal rotation or deletion processes complete.

7. Security

We use administrative, technical, and organizational safeguards designed to protect information. These include authenticated accounts, server-side authorization, row-level database access controls, restricted service credentials, encrypted network transport, rate and concurrency limits, destination filtering, bounded retrieval, and service-to-service authentication.

No system is completely secure. You are responsible for protecting your account credentials and should contact us if you suspect unauthorized access.

8. Your choices and privacy requests

Depending on where you live, you may have rights to request access, correction, deletion, or information about our use and disclosure of personal information, and to appeal or complain about certain decisions.

You may submit a request to [email protected]. We may need to verify your identity and authority before completing a request. We will not unlawfully discriminate against you for exercising an applicable privacy right.

Although Bozarth Software may not currently meet every threshold that makes a business subject to the California Consumer Privacy Act, we use reasonable efforts to honor verified access, correction, and deletion requests consistent with our obligations, security needs, and the rights of others.

9. Children

The Service is intended only for adults age 18 or older and is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact [email protected] so we can investigate and take appropriate action.

10. United States processing

Bozarth Software operates in the United States. If you access the Service from another country, your information may be processed in the United States and other locations where our service providers operate, which may have different data-protection laws.

11. Third-party links and submitted websites

Our Service may contain links to, or retrieve public information from, third-party websites. Their privacy practices are governed by their own policies, not this Privacy Policy.

12. Changes to this Policy

We may update this Privacy Policy as the Service and legal requirements change. We will post the updated version and revise the “Last updated” date. We will provide additional notice or obtain consent when required by law.

13. Contact us

Privacy questions and requests may be sent to Bozarth Software LLC, California, United States, [email protected]. General support questions may be sent to [email protected].

Questions: [email protected].