TMOD LogoTMOD

Privacy Policy

Last updated: July 31, 2026

1. Who we are

TMOD is an automated website audit tool. You give it the address of a website, it reads the public pages of that site, and it returns a report saying what would stop the site being approved for Google AdSense and how to fix it.

The controller of the personal data described here is WEBEST LLC, 30 N Gould St Ste N, Sheridan, WY 82801 USA. If you are in the European Economic Area or the United Kingdom, that means we decide why and how your data is processed, and the obligations of the GDPR apply to us in respect of it.

We have no establishment in the EEA or the United Kingdom. Where Article 27 GDPR requires a local representative, we will appoint one and name them here. In the meantime you can reach us directly at contact@tmod.net, and we answer requests from EEA and UK residents on the same terms as everyone else.

This policy covers this website and the audit service on it. It does not cover the websites you choose to scan, which belong to whoever runs them.

2. The short version

This document is long because being precise about data takes room. The substance of it is short:

  • You can run a scan without giving us a name, an email or an account.
  • We only read pages that are already public on the site you submit, at a polite rate, and we change nothing.
  • We keep the report so you can look at it again. Reports from a scan you did not sign in for delete themselves after seven days.
  • To judge your content, the text of your pages goes to an AI provider. It is not used to train anything.
  • There are no analytics on this site, no advertising trackers and no cross-site tracking. Your data is never sold or shared for advertising.
  • Your IP address is never written down. What is stored is a keyed hash of it that expires within the hour.
  • Your account and your reports are stored in the European Union, on servers in Paris, France, wherever in the world you are.
  • If you do have an account, you can export everything and delete everything yourself, from your settings page, without asking us.

3. What we collect

3.1 When you run a scan without an account

  • The URL you submit and the scan options you chose.
  • The public pages we fetch from that site, and the report built from them: the result of every check, category scores, and a written content-quality judgement produced by an AI model. A report describes a website rather than a person, but because a website can be one person's work we treat it as your data and give you rights over it.
  • An anonymous id in a first-party cookie, so one visitor cannot run unlimited free scans by clearing state. See section 5.

3.2 When you create an account

  • Your name and email address, and a hashed password if you signed up with one. We never hold the password itself.
  • If you sign in with Google or GitHub, we receive your name, your email address and your profile picture from them. We do not receive your password, and we ask for nothing beyond your basic profile and email.
  • Whether your email is verified, and when the account was created and last changed.
  • Your scan history, meaning the reports and roadmaps attached to your account.

3.3 Automatically, from your requests

  • A keyed hash of your IP address, used for rate limiting and burst-abuse counters. The address itself is never stored. See section 10 for exactly what this means and how long the keys live.
  • Your browser's user-agent string and ordinary server request logs, for security and debugging.

3.4 When you email us

Your address, your message and anything you attach, kept as long as needed to deal with the matter and to show how we dealt with it.

3.5 Personal data inside the sites you scan

A crawled page may contain personal data about other people: an author name, a byline, a contact address published on the site. We process that only to produce the report and we do not seek it out, index it, or build profiles from it. When you submit a site you are asserting that you are entitled to have it scanned, which is a term of the Terms of Serviceand matters here too: where you are the controller of that site's data, you are responsible for the lawfulness of asking us to read it.

4. Why we use it, and our legal basis

If you are in the EEA or the UK, the GDPR requires us to have a legal basis for each purpose, and to tell you which one.

What we doUsingLegal basis
Run the scan you asked for and show you the reportThe URL, the crawled pages, the reportPerformance of a contract, Art 6(1)(b). You asked for this specific thing and we cannot do it without them
Run your account, sign you in, verify your addressName, email, hashed password, verification statePerformance of a contract, Art 6(1)(b)
Stop one visitor running unlimited free scans, and stop bursts of automated requestsAnonymous id cookie, keyed hash of your IP addressLegitimate interests, Art 6(1)(f): keeping a free service affordable enough to exist. It is limited to counting, it never profiles you, and the keys expire in minutes or hours
Reuse a fresh report to answer another visitor's scan of the same URLThe report only, which carries nothing about who ran itLegitimate interests, Art 6(1)(f): this is the cost control that keeps the tool free. See section 8
Keep the service secure and debug failuresRequest logs, user-agent, hashed IP keysLegitimate interests, Art 6(1)(f): security of the service
Answer your emailYour address and messageLegitimate interests, Art 6(1)(f), or performance of a contract where it concerns your account
Meet legal obligations and defend legal claimsWhatever the obligation or claim concernsLegal obligation, Art 6(1)(c), and legitimate interests

Where we rely on legitimate interests we have weighed them against your rights and freedoms, and you can object at any time under section 12.

5. Cookies

This site sets two cookies. Both are first-party and strictly necessary, and neither is used for advertising, profiling or cross-site tracking.

CookieWhat it doesLifetime
tmod_anonA random id, minted by our server, that lets us count scans from one visitor. It is httpOnly, so page JavaScript cannot read it, and SameSite=Lax. It holds no personal information and is never accepted from the client30 days
Session cookieKeeps you signed in after you log in. Set only if you have an account30 days, or until you sign out

Under the ePrivacy rules, consent is required for cookies that are not strictly necessary for a service the user asked for. Both of ours are necessary: one keeps you signed in, the other is the mechanism that makes a free scan possible at all. That is why this site shows no cookie banner. If we ever set a cookie that is not strictly necessary, a consent mechanism will appear before it does, and this section will change first.

6. Advertising

There is no third-party advertising on this site today. No ad network script runs here, no advertising cookie is set, and nothing about you is sold or shared with advertisers.

If that changes, we expect to serve ads through Google AdSense, and this section will be updated before the first ad appears. At that point: third-party vendors including Google would use cookies to serve ads based on your prior visits to this or other websites; you would be able to opt out of personalised advertising in Google Ads Settings or at aboutads.info; we would name the vendors and ad networks serving those ads and link to the opt-out each of them offers; and visitors in the EEA, the UK and Switzerland would be asked for consent through a Google-certified consent management platform integrated with the IAB Transparency and Consent Framework before any such cookie was set.

7. Who else receives it

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We are not in the business of doing either. Data reaches the following categories of recipient, and no others:

RecipientWhat they receive and whyWhere
Featherless AIPrimary AI inference. Receives the text of pages crawled during a scan so the content-quality and policy judgements can be produced. Featherless states that it does not log prompts or completions and that requests are processed in real time rather than stored.United States
Cloudflare R2Object storage for images uploaded to the blog by our own editors. No visitor or scan data is stored here.United States (Cloudflare, Inc.), stored on its global network
HostingerRuns the application servers, the database and the cache, so it processes everything described in this policy as an infrastructure provider.France (Paris data centre). Hostinger International Ltd is established in the EU
Titan MailDelivers account email: address verification and password resets. Receives your email address and the message.United States

Each of them acts as our processor: they may use the data to provide their service to us and for nothing else. Follow the links above for what each of them publishes about its own handling, and write to us if you want to know which processing terms apply to a particular one.

On AI inference specifically, because that is where your page text goes. We do not use your content to train models, and it is sent only to produce the judgement for that one scan. Our provider states that it does not log prompts or completions and that requests are processed in real time rather than stored. No other inference provider receives your content. The software supports a fallback provider, and it is switched off: it holds no credentials and is never called.

Beyond that list, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or where a business is sold or merged, in which case the buyer is bound by this policy and you will be told before anything changes.

8. How a report can answer someone else's scan

A report stays fresh for 24 hours. If anyone else scans the same URL with the same settings inside that window, we show them the report your scan produced instead of crawling the site again. This works in both directions: many scans are answered from a report someone else's scan produced. It is the single thing that makes a free audit affordable to run.

A report holds findings about the website: check results, scores, and the AI-written content judgement. It holds nothing about who ran the scan. No account, no cookie id, no IP address, no hash of one. We only ever crawl pages that are already public. If you would rather a URL's report were not reusable this way, do not scan that URL here.

9. Where your data goes

Our application servers, database and cache run in Paris, France. That is where your account and your reports are stored, wherever in the world you are.

We are established in the United States, so we reach those systems from there, and some of the processors in section 7 are American: page text goes to AI providers in the United States to produce the content judgement, account email is delivered through a provider there, and blog images sit on a network operated from there.

If you are in the EEA, the UK or Switzerland, both of those are international transfers even though your data sits in the EU at rest, because access from a third country counts as a transfer. For each of them we rely on the European Commission's standard contractual clauses, the UK international data transfer addendum where the UK GDPR applies, or another safeguard permitted by Chapter V of the GDPR, together with encryption in transit. Ask us and we will tell you which safeguard covers a particular transfer.

10. How long we keep it

DataWhereKept for
Anonymous id cookie, and the matching server-side countersYour browser, and our cache30 days
Keyed hash of your IP address, burst-abuse counterCache, keyed by the hash. The address is never written down1 hour
Keyed hash of your IP address, request-rate limiterCache, keyed by the hash. The address is never written down2 minutes
Reports from a scan you ran without signing inDatabase7 days, then deleted automatically by the database itself. If you later sign in and claim the scan, it becomes an account-linked report and the row below applies
Reports and roadmaps attached to your accountDatabaseUntil you delete them or delete your account
The 24-hour reuse window for a reportDatabase, looked up by URL and scan settings24 hours from the scan that produced it
Account record: name, email, hashed passwordDatabaseUntil you delete the account, which removes it and every report attached to it
Sign-in sessionA signed token in your browser30 days, or until you sign out
Email we exchange with youOur mailboxAs long as needed to handle the matter, and to show how it was handled

About those IP hashes. The abuse counters never store your IP address. What they store is an HMAC-SHA-256 of it, computed with a secret that exists only on our servers and truncated to a short key; for IPv6 we hash the /64 network prefix rather than your full address. Someone reading that cache, a backup or a stolen copy of the database cannot turn a key back into an address without also holding the secret. To be precise about what this is: it is pseudonymisation, not anonymisation. We could still take a known address and compute its key, so it remains personal data under the GDPR and every right in section 12 applies to it.

Backups are kept for a short operational window and overwritten on a rolling basis. A deletion request is applied to live systems immediately and works through backups as they cycle.

11. How we protect it

  • Traffic to this site is encrypted in transit.
  • Passwords are stored only as bcrypt hashes. Nobody here can read your password, and a database copy does not reveal it.
  • Sessions are signed tokens, and the anonymous id is never client-supplied.
  • IP addresses are pseudonymised with a keyed hash before they reach any store, as described above.
  • The crawler refuses private, internal and loopback addresses, so the service cannot be pointed at a network it should not reach.
  • Administrative areas are restricted to accounts we have granted that role.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If we discover a breach affecting your personal data we will notify the relevant supervisory authority and, where the law requires it, you.

12. Your rights

Wherever you live, you can ask us to do all of the following, and two of them you can do yourself without asking:

  • Get a copy of your data. If you have an account, Export my data in your settings gives you everything we hold, immediately.
  • Delete it. Delete account in the same place removes your account and every report and roadmap attached to it. This cannot be undone.
  • Correct anything inaccurate, including your name or email.
  • Object to processing we base on legitimate interests, and ask us to restrict it while we consider your objection.
  • Withdraw consent where we ever rely on it, without affecting what was done before you withdrew it.
  • Receive your data in a portable format, which the export above provides.

To exercise any of these by email, write to contact@tmod.net. Tell us which right you are exercising, and give us the account email address, or the exact URL and approximate time of the scan if you never signed in, so we can find the right records. We may need to verify who you are before acting, and we will not ask for more information than that verification needs.

We answer within one month, and will tell you if a complex request needs longer. Exercising a right costs nothing and we will not treat you differently for it.

If you are in the EEA or the UK and you think we have handled your data badly, you can complain to your national supervisory authority as well as to us. We would rather you told us first, but that right is yours regardless.

13. California residents

Under the CCPA as amended by the CPRA, the categories of personal information we have collected in the past twelve months are: identifiers (name, email address, an anonymous cookie id, a pseudonymised IP key), internet and network activity (the pages we fetched at your request, the reports produced, request logs and user-agent), and account credentials in hashed form. We collect them from you directly, from your browser as you use the site, and from Google or GitHub if you choose to sign in that way. We use them for the business purposes set out in section 4, and we disclose them to the service providers listed in section 7.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past twelve months, and that includes the personal information of anyone we know to be under 16.

California residents have the right to know what we collect and why, to request deletion, to request correction, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. We collect no sensitive personal information as that term is defined, and since we neither sell nor share, there is no opt-out to operate. The other rights work exactly as described in section 12, through the same self-serve controls or the same address. An authorised agent may make a request on your behalf with written proof that you authorised them.

14. Automated decisions

The audit is automated, and its verdict is a machine judgement about a website. It has no legal effect on you and no similarly significant effect: it does not decide whether you get credit, a job, a service or a price, and nobody but you receives it. It is not a decision within the meaning of Article 22 GDPR, and nothing here is a decision by Google.

Because the judgement comes partly from a language model, it can be wrong. If you think a finding about your site is inaccurate, write to us and we will look at it, and correct the engine if you are right.

15. Children

This service is for people running websites and is not directed at children. The Terms of Service set the minimum age at 16, and we do not knowingly collect personal data from anyone below it. If you believe a child has given us personal data, write to contact@tmod.net and we will delete it.

16. Sites you scan, and sites we link to

Scanning a site does not put us in a relationship with whoever runs it, and this policy does not govern what that site does with data. The same goes for any site we link to from an article or a report. When you follow a link out of here, the other site's policy applies, not ours.

17. Changes to this policy

We update this page when the product changes. The date at the top always shows when the current version took effect, and material changes to what we collect, why, or how long we keep it will be described here rather than slipped in. If a change requires your consent, we will ask for it before the change applies to you.

18. How to reach us

Privacy questions and requests: contact@tmod.net. Anything else, including reports of someone scanning a site they have no right to scan, is on the contact page.

WEBEST LLC
30 N Gould St Ste N, Sheridan, WY 82801 USA