Home / Privacy Policy
Privacy Policy
Last updated: 30 July 2026
This policy explains what personal data Lantad collects, why, who we share it with, and the rights you have. We keep data collection to the minimum needed to run a free scanning tool. Plain-English summaries sit next to the detail so you can see exactly what happens to your information.
Contents
1. Who we are
Lantad ("Lantad", "we", "us", "our") is an AI-visibility scanning service operated from the United Kingdom. The incorporation of Lantad Ltd in England and Wales is in progress; until it completes, the individual operating Lantad is the data controller for the purposes of the UK GDPR and the Data Protection Act 2018, and the company will assume that role on incorporation. You can reach us at hi@lantad.co, which is also the address for any privacy request or formal notice.
2. What we collect
Information you give us
- URLs and robots.txt you submit. The pages, domains, or robots.txt text you ask us to scan, compare, or test. Submitting a URL is a request for us to fetch and analyze that page.
- Email address (optional). Only if you provide one, so we can send you a report link, monitoring alerts you opted into, or a reply to a fix request.
- Fix-request details. If you contact us through the services form: your name (optional), email, website, timeline, and message.
- Marketing preference. If you tick the optional consent box, we treat that as your consent to occasional product findings and updates.
Information collected automatically
- IP address. Used to enforce rate limits, prevent abuse, and keep the service secure. We do not use it to build a profile of you.
- Basic request and log data. Standard technical information such as timestamps and the endpoints called, kept short-term for security and reliability.
- Human-verification (Turnstile). We use Cloudflare Turnstile to tell humans from bots. It is designed to be privacy-preserving and does not track you across other websites.
- Which sections people click. When you click a tracked element we record two things: a short label for that element (for example
pricing:proof-storefront) and the path of the page you were on. Nothing else. We set no cookie and store nothing on your device. Your IP address is available to us on every request and is deliberately not stored with this data; we keep only the country, which comes from our network rather than from you. Query strings are removed before storage, because that is where personal data would otherwise leak in. This runs as our own first-party counter on our own infrastructure, and since 30 July 2026 the same label and path are also sent to Google Analytics, described under Site analytics below.
We do not use advertising or cross-site tracking cookies, and we run no advertising or remarketing. Google Analytics is configured with consent denied by default, so it stores nothing on your device and creates no identifier for you unless you are ever asked and agree.
Site analytics
Most of our analytics runs on our own infrastructure, and that part shares nothing with anyone. Since 30 July 2026 we also use Google Analytics 4, which is a third-party script. We never sell analytics data.
What Google Analytics receives, and what it does not. Google Analytics starts with storage switched off, so on an ordinary visit it sets no cookie and creates no identifier for you. It sends Google a measurement with no identity attached: the page address, the referring site, and coarse device and country information.
The page address it sends is redacted before it leaves your
browser wherever the address itself is a secret. Report,
comparison, account and tool-result links carry a key in the path that
works as a password for that page, so Google is sent
/r/:1 rather than the real link, and never sees the query
string. This is the same redaction our own analytics uses, applied by the
same code, so neither can see more than the other.
-
What we record about each request. The path of the
page, the status code, how long our server took to answer, the general
class of client (a browser, a search-engine crawler, an AI crawler, or
an automated tool), coarse browser and device families (for example
"chrome", "windows", "mobile"), your country and region as reported by
our network, your browser's first preferred language, and the referring
site's hostname. We do not record the page you came from beyond its
hostname, and we never record query strings, which is where things like
tokens and email addresses appear in URLs. If a link brings you here
with
utm_source,utm_mediumorutm_campaigntags we keep those three values and nothing else from the address. - Secrets in our own addresses. Some of our links carry a secret in the path rather than the query string: your account link, a report link and every tool result link are unguessable URLs, and holding one is what grants access to it. Those path segments are replaced with a placeholder before anything is stored, so what we record is that a report page was viewed, never which report.
- The visitor number. To count daily visitors without cookies we derive a short pseudonymous key: a truncated SHA-256 hash of a secret salt, the current UTC date, your IP address and your browser's user-agent string. Your raw IP address is never stored. The date is part of what is hashed, so the key for the same person changes every UTC day and nothing in the stored data links one day's key to the next: from the records alone we can tell that 40 visits came from 12 visitors today, but not whether any of them also came yesterday. If the salt is ever absent, no key is derived at all rather than a weaker one.
- The honest limit of that. The salt is a long-lived secret that we hold. Anyone holding it, which means us, could take a specific IP and user-agent and recompute that person's key for a past day, and so join their visits within the roughly 90 days of raw records. We do not do this and no feature does it. What the design guarantees is that the stored data is not linkable across days by anyone who does not hold the salt, which includes every reader of a dashboard and anyone who obtained the records alone. It does not make us incapable of it, and we would rather say so than claim an impossibility our code does not deliver.
- Sessions. A session is the visitor key plus a 30-minute clock window, because measuring inactivity would need the very long-lived identifier we decline to keep. A visit spanning a window boundary counts as two sessions, so our session counts overcount slightly by design. We would rather say that than invent precision.
- In your browser. Our pages send small beacons of two kinds. When you leave a page or switch away from the tab, one summary beacon reports how far you scrolled, how long the page was visible, and standard page-speed measurements. Separately, if a script error occurs, one beacon is sent at that moment rather than on leaving, carrying the error message with any query string or fragment removed before it leaves your browser, up to three per page view. So a page view sends between one and four beacons. None sets a cookie, reads storage, or creates an identifier. Where your browser cannot measure something we record "not measured" rather than zero, so an unmeasurable page is never averaged in as a fast one.
- Crawlers and bots. We classify each request's user-agent against the same published list of AI crawlers our scanner checks. A user-agent is a claim, not an identity: anything can call itself GPTBot, so our AI-crawler figures are counts of requests claiming to be those crawlers. We say it here because we say it on our own dashboards too.
- Retention. Raw request records live in Cloudflare Analytics Engine, which retains them for roughly 90 days. Each night we also store daily aggregate totals, requests per page per client class and hits per claimed crawler, in our own database. Those aggregates contain no visitor keys, no IP-derived values and no per-request rows, and we keep them indefinitely as the site's historical traffic record.
- What this counter does not do. It shares nothing with anyone, including Google: it is separate from the Google Analytics measurement described above, and no third party receives what it records. We run no advertising scripts and do no cross-site tracking. We never sell analytics data of any kind. No cross-day visitor profiles are built from the stored data, subject to the limit stated above. No first-touch attribution, because the stored data holds no identifier that survives a day, so we only ever know the last site that referred you. City-level location is not recorded, only country and region.
Content within the pages you scan
When you submit a URL, we fetch that page and process its content to produce your result. If a page you submit happens to contain personal data, we process it only transiently to generate your report and do not reuse it. Two features send the text extracted from the page you submit to an AI model (see subprocessors below): the "What AI says about you" tool, which generates the comparison, and the "AI opportunity" analysis on the paid dashboard, which suggests example prompts and keyword angles for that page. Only submit pages you are entitled to have us fetch (see our Terms).
3. Why we use it, and our legal bases
- To provide the service you asked for (running a scan, comparison, multi-page scan, tool, or sending your report link). Legal basis: performance of a contract, or steps taken at your request before entering one.
- To keep the service secure and prevent abuse (rate limiting, blocking attacks). Legal basis: our legitimate interests in protecting the service and other users.
- To respond to your enquiries and, where relevant, discuss our paid fix service. Legal basis: legitimate interests, or steps before a contract.
- To send marketing only where you have opted in. Legal basis: your consent, which you can withdraw at any time.
- To see which parts of our own site are useful so we can improve them. Legal basis: our legitimate interests in understanding how our site is used. We rely on legitimate interests rather than asking for consent because this counter stores nothing on your device and creates no identifier, so it cannot build a profile of you or follow you anywhere.
4. Who we share it with (subprocessors)
We do not sell your personal data. We share it only with the providers we need to run the service:
- Cloudflare, Inc. Hosting, content delivery, edge compute, storage, security and human-verification (Turnstile), page rendering, and the AI model that powers the "What AI says about you" check. Data may be processed on Cloudflare's global network.
- Google LLC (Google Analytics 4). Receives a measurement of each page view with no identifier attached, for us to understand which pages are useful. Addresses that work as a password for a page are redacted before they are sent. Data may be processed outside the United Kingdom and the EEA.
- Resend (email delivery). Used only to send the report link, monitoring alerts, or replies you asked for.
- Stripe (payments). If you buy a paid plan, checkout and billing run entirely on Stripe. Your card details go to Stripe directly and never touch our systems; we receive only your email, the plan you bought, and a customer reference.
These providers act as our processors under contract and may only use the data to provide their service to us. We may also disclose data if required by law or to protect our rights, users, or the public.
5. International transfers
Our providers operate globally, so your data may be processed outside the United Kingdom and the European Economic Area, including in the United States. Where it is, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or a valid adequacy decision.
6. How long we keep it
- Scan results and artifacts are kept for up to 18 months, after which they are deleted or made inaccessible. Result links are not intended to be permanent.
- Email addresses are kept until you unsubscribe or ask us to delete them, or until the purpose ends.
- Security logs are kept short-term.
- Site analytics are kept as raw per-request records for roughly 90 days, and as daily aggregate totals indefinitely. The aggregates hold no visitor key and no per-request row. See Site analytics above for exactly what each contains.
7. Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to our processing;
- data portability;
- withdraw consent at any time (for anything based on consent); and
- complain to the Information Commissioner's Office (ico.org.uk) if you think we have mishandled your data.
To exercise any of these, email hi@lantad.co. We aim to respond within one month.
California residents. Under the CCPA and CPRA you have the right to know, delete, and correct your personal information, and to opt out of its "sale" or "sharing". We do not sell or share your personal information for cross-context behavioural advertising, and we will not discriminate against you for exercising your rights. Contact us at the same address to make a request.
8. Children
Lantad is a tool for website owners and professionals and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
9. Security
We use reasonable technical and organisational measures to protect your data, including a serverless architecture, transport encryption, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Cookies
We set two cookies, and only after you deliberately sign in. Both are strictly necessary: signing in does not work without them, which is why there is no consent banner to click through.
-
lantad_session, set when you sign in to your account. It holds a random session reference, nothing about you. Expires after 30 days. -
lantad_admin, the equivalent for our own staff dashboard. You will never receive this one.
Both are HttpOnly, Secure and
SameSite=Lax, so they cannot be read by scripts and are not
sent to other sites. Cloudflare Turnstile, the human-check on our forms,
may also set a short-lived cookie of its own to remember that a check
passed; that is part of keeping the forms usable and is also strictly
necessary.
We set no advertising or cross-site tracking cookies. Google Analytics is configured with consent denied by default, so on an ordinary visit it stores nothing on your device and creates no identifier. If we ever ask for analytics consent, it will be an explicit choice you make, not a pre-ticked box, and declining will keep the site working exactly as it does now.
11. Changes to this policy
We may update this policy as the service evolves or the law changes. The date at the top shows the latest version, and we will flag material changes where we reasonably can.
12. Contact
Questions or requests about your data: hi@lantad.co. See also how our scanner behaves in the crawler conduct policy and the Terms and Conditions.