Privacy Policy
How SiteRevenue (GigaSolo LLC, Wyoming) handles emails, sessions, public page capture, Stripe, xAI, Cloudflare, and Email Sending.
Last updated: 2026-08-25
Product: SiteRevenue (siterevenue.ai)
Controller: GigaSolo LLC, a Wyoming limited liability company (“GigaSolo”, “we”, “us”, “our”), operating the SiteRevenue service
Contact: hello@siterevenue.ai
This Privacy Policy describes how we collect, use, store, and share personal data when you use SiteRevenue (the “Service”), including our website, free mini audits, paid full reports, account surfaces, magic-link recovery, share links, and the Agent API (where enabled).
1. Who we are
SiteRevenue is a product of GigaSolo LLC, a Wyoming limited liability company. We provide automated revenue-oriented audits of public web pages you submit. Support and privacy requests: hello@siterevenue.ai.
2. Scope
This policy covers personal data processed in connection with:
- Marketing pages (for example home, pricing, sample, agents, legal pages)
- Free teaser audits and paid full reports
- Optional job-wizard answers, operator notes, competitor URLs, and optional ad or email copy you paste
- Park/Agent URL watch (public-page hash + optional change email)
- Browser workspace sessions and multi-site audit history
- Email-based recovery (“magic links”) and transactional messages
- Read-only share links for full reports
- Payments and subscriptions via Stripe
- Account / API key management for Agent plan users
- Infrastructure and security logs on Cloudflare
It does not cover third-party sites you ask us to analyze, or processors’ own privacy practices except as summarized under Processors.
3. Data we collect
3.1 Data you provide
| Category | Examples | When |
|---|---|---|
| Contact email | Unlock / checkout email, magic-link recovery email, optional workspace binding | Pay flow, recovery, account-related actions |
| Site URLs & audit inputs | URL, optional desired outcome, optional competitor URLs, optional ad or email copy you paste, optional operator notes / job-wizard answers (who / get / money click) | Teaser and full audits, re-runs, watch |
| Support messages | Emails you send to hello@siterevenue.ai | Support |
| API key metadata | Key display prefix, optional name (raw key shown once at create) | Agent account surfaces |
We do not ask for passwords for SiteRevenue login (session + magic link model). We do not request Google Ads or other ad-platform OAuth credentials for the core page or funnel audit path.
3.2 Data collected automatically
| Category | Examples | When |
|---|---|---|
| Session identifiers | Signed workspace session cookie sr_sid | Most app and cash-path interactions |
| Short-lived flash cookie | sr_share_flash (one-shot share URL handoff) | After minting a share link in-browser |
| Technical / security data | IP address, user agent, timestamps, rate-limit counters, request paths | Abuse prevention, reliability, Cloudflare edge |
| Product analytics (PostHog, when configured) | Pages viewed, events (for example audit started, checkout started, purchase), device/browser, referring URL, feature-flag/exception payloads. If your session is email-bound, we also send workspace id and that email so events can be linked across visits. | Browser snippet on marketing and app HTML |
| Payment references | Stripe customer id, Checkout session id, subscription/entitlement status | After pay or portal use (not full card numbers) |
See the Cookie Policy for browser storage details.
3.3 Data derived from public pages you submit
When you submit a URL, we fetch publicly reachable page content to produce an audit. That may include:
- HTML/text extract and page title of the URL you submitted
- Optional competitor public pages whose URLs you listed (full reports only; fail-open if a rival URL does not load)
- Optional screenshot evidence (full-mode; fail-open if capture is unavailable)
- Structured model outputs (grade, findings, inferred page job, Markdown/JSON/PDF artifacts)
- For Park/Agent watch: periodic public-HTML hash of a URL you enabled, which may enqueue a mini audit and a transactional email when the hash changes
We do not intentionally log into private authenticated areas of your site, bypass paywalls, or access non-public admin interfaces. Analysis is limited to public pages and content returned without your private credentials.
3.4 Data we do not collect (current product)
- Full payment card numbers (handled by Stripe Checkout; Stripe may set
__stripe_mid/__stripe_sidon the pay page — see Cookie Policy) - Government ID or KYC documents (not part of this product)
- Google Analytics (GA4/gtag) measurement cookies, Google AdSense, or other advertising pixels (not implemented;
GA4_MEASUREMENT_IDstays unset) - Content from private authenticated app areas via user credentials we store
Light/dark appearance is stored only in your browser (localStorage key sr-theme). Product-analytics identity reset uses sr-posthog-workspace-id in localStorage when PostHog is configured. Neither is a SiteRevenue session secret. See the Cookie Policy.
4. How we use data (purposes)
| Purpose | Legal basis | Data involved |
|---|---|---|
| Provide free teaser and paid full audits | Contract / steps prior to contract | URLs, page capture, model outputs, workspace |
| Process payment and fulfill digital deliverables | Contract | Email, Stripe ids, entitlements, job records |
| Maintain multi-site history and versions in your workspace | Contract / legitimate interests | Site keys, job versions, results |
| Session continuity across browser visits | Legitimate interests / contract | sr_sid session |
| Magic-link recovery of paid audits | Contract / legitimate interests | Email, short-lived auth tokens, session |
| Share read-only report links you create | Contract / legitimate interests | Share token hashes, job id, short flash cookie |
| Agent API authentication and usage metering | Contract | API key hashes, usage |
| Transactional email (magic links, report-ready notices, optional watch-change notices when configured) | Contract / legitimate interests | Email, message content |
| Security, rate limiting, fraud/abuse prevention | Legitimate interests | IP, UA, counters, logs |
| Support and legal compliance | Legitimate interests / legal obligation | Support correspondence, relevant records |
| Product improvement (aggregated/de-identified where practical) | Legitimate interests | Operational metrics — not sale of personal data |
| Product analytics and funnel measurement (PostHog, when configured) | Legitimate interests | Pageviews, in-product events, optional email on identify |
We do not sell your personal data. We do not use personal data for cross-context behavioral advertising as a current product feature.
5. AI processing (xAI)
To generate audits we send public page text and related audit context (for example URL, desired outcome, optional ad or email copy you paste, operator notes, job-wizard answers, and competitor page excerpts we fetched from URLs you listed) to our model provider xAI (Grok models configured for the Service). Model outputs become part of your audit artifacts.
Do not submit secrets, private credentials, or non-public personal data of third parties in free-text fields (desired outcome, notes, job wizard, etc.). Treat model outputs as analytical estimates, not professional advice (see Terms). Inferred “page job” text is not a product-market-fit score.
6. Tokens, sessions, and lifetimes
Approximate product defaults (subject to change for security):
| Mechanism | Typical lifetime | Notes |
|---|---|---|
Browser session cookie sr_sid | Up to 90 days | HttpOnly, signed; embeds expiry |
| Magic-link recovery session | Up to 30 days | After successful magic consume |
| Magic-link token (email) | About 20 minutes | Single-use style; hash stored at rest |
| Share link token | About 14 days | Revocable; hash stored at rest; multi-view until exp/revoke |
Share flash cookie sr_share_flash | About 120 seconds | One-shot handoff of share URL; not a permanent tracker |
| API keys | Until revoked | Hash at rest; raw key shown once |
7. Processors and subprocessors
We use service providers to operate the Service. Typical categories:
| Provider / platform | Role | Data typically involved |
|---|---|---|
| Cloudflare | Hosting (Workers), DNS/edge, D1 database, R2 object storage, Email Sending (transactional: magic links, report-ready / failed notices), optional Browser Rendering for screenshots, optional Web Analytics (cookieless pageviews) | Request metadata, stored app data, artifacts, recipient email and message content when Email Sending is configured |
| Stripe | Payments, Customer Portal, webhooks | Email, customer/subscription ids, payment status — card data on Stripe |
| xAI | Model inference for audit generation | Public page text and audit prompt context; model outputs returned to us |
| PostHog | Product analytics, session tooling, and exception capture when PUBLIC_POSTHOG_PROJECT_TOKEN is set. Snippet loads from the configured ingest host (currently PostHog US Cloud). PostHog US Cloud also fetches config and exception-autocapture from https://us-assets.i.posthog.com. Not Google Analytics. | Event payloads, device/browser, pages; workspace id + email only after the session is email-bound |
| Self-hosted type (Inter, JetBrains Mono) | Display and body type served from this origin (/fonts/inter/, /fonts/jetbrains-mono/). We do not load Google Fonts (no fonts.googleapis.com / fonts.gstatic.com). | Font file request to our host only; no Google font IP lookup |
| Optional screenshot API | When SCREENSHOT_API_URL (and related keys) are configured, an external screenshot provider may capture public page images for full-report evidence | Target public URL and returned image bytes; fail-open if unset or unavailable |
Providers process data under their terms and our configuration.
8. Retention
We retain data for as long as needed to:
- Provide reports, version history, downloads, and account features you use
- Complete payments, prevent fraud, enforce the Acceptable Use Policy, and meet legal obligations
- Support recovery of paid audits via email when you request it
In practice:
- Audit jobs and artifacts remain available while your workspace retains them for product use
- Auth and share tokens expire as above; expired/revoked tokens are not valid for access
- You may request deletion or export of personal data associated with your email/workspace by contacting hello@siterevenue.ai
We may retain limited records (for example billing references, security logs, dispute materials) as required for legitimate interests or law, even after a content deletion request.
9. Sharing
We share personal data only:
- With processors listed above, to run the Service
- When you create a share link, with anyone who has the link (read-only report content for that job)
- If required by law, regulation, or valid legal process
- In connection with a merger, acquisition, or asset transfer (with appropriate notice where required)
- With your direction (for example support investigation)
We do not sell personal data.
10. Security
We use industry-typical controls appropriate to a small SaaS audit product, including:
- HTTPS in production
- HttpOnly session cookies with SameSite=Lax (Secure in non-local environments)
- Signed session payloads with embedded expiry
- Hashing of magic, share, and API secrets at rest (raw secrets not stored where the design uses hashes)
- Workspace isolation for private report routes (IDOR-sensitive paths)
No method of transmission or storage is 100% secure. Report suspected vulnerabilities to hello@siterevenue.ai.
11. International transfers
Infrastructure may process data in the United States and other locations where Cloudflare, Stripe, xAI, PostHog, or our operators run. Where required by applicable law for transfers from the EEA, UK, Switzerland, or other regions with transfer restrictions, we implement appropriate safeguards.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. To exercise rights, email hello@siterevenue.ai with enough detail to locate your workspace (email used at checkout, job ids if known).
We may need to verify control of the email address. We will not discriminate against you for exercising privacy rights where prohibited by law.
California / similar US state laws: We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined in current product behavior. Categories of collection are described above. Authorized agents may contact us at the support email.
EEA/UK: Where GDPR applies, legal bases are summarized in §4; supervisory authority complaints may be available in your country of residence.
13. Children
The Service is directed to business users and website operators. It is not intended for children under 16 (or higher age if required locally). We do not knowingly collect personal data from children.
14. Changes
We may update this policy. The Last updated date at the top will change. Material changes may be highlighted on the site or by email where appropriate. Continued use after the effective date constitutes acceptance where permitted by law.
15. Contact
Privacy & support: hello@siterevenue.ai
Controller: GigaSolo LLC (Wyoming, United States)
Site: https://siterevenue.ai
Related: Cookie Policy · Terms of Service · Acceptable Use Policy