Skip to content
Healthy URL healthyURL
Privacy

Privacy policy

Last updated: 21 July 2026

Who we are

Healthy URL is built, owned and operated in England, and is the data controller for the information described here. Contact us at hello@healthyurl.co.uk.

Where your data is stored

On servers in London, United Kingdom. It leaves only when processed by the suppliers listed below, which are used to provide the service and never for advertising or marketing. We do not sell, rent or share your personal data. We use no tracking cookies, no advertising networks and no third-party analytics.

What we collect

  • Account information: your name, email address and a hashed password.
  • Scans: the addresses you submit and the results. Scans run without an account are deleted automatically after 24 hours.
  • Payment information: handled by Stripe. We never see or store your card details — only your Stripe customer reference and the date your access runs to.
  • Google Search Console: if you connect it, we store an access token, encrypted, with read-only permission. We cannot change anything in your Google account. Disconnecting deletes the token.
  • Free tools: which tool was used and whether it worked. We do not record what you looked up.
  • Emails we send you: the subject, the address and whether it sent — not the contents.
  • Technical data: IP address and request details, for rate limiting and to prevent abuse.

Aggregate statistics

We count how often each problem occurs across all sites scanned — for example, how many sites are missing image descriptions, and how long that fix typically takes. These counts contain no addresses and no account details, and cannot be traced back to a person or a site. We keep them indefinitely and use them to improve the checks and to write about what we find.

How we use your data

  • To run scans and produce reports.
  • To manage your account and process payments.
  • To send transactional email — results, change alerts, account notices.
  • To protect the service against abuse.

Cookies

Only what is needed for the site to work: a session cookie to keep you signed in, and a token protecting forms from being submitted by other sites. Your light or dark theme preference is kept in your browser's local storage, not a cookie. There is nothing to consent to, which is why you are not being asked.

Suppliers

  • Stripe — payments.
  • Resend — transactional email.
  • DigitalOcean — hosting, London, United Kingdom.
  • Google PageSpeed Insights — performance measurement. Addresses you submit are sent to Google's API.
  • Anthropic — AI-written explanations. Findings from a scan are sent for analysis.

How long we keep it

Scans run without an account: 24 hours. Everything tied to your account: for as long as the account exists. If you delete your account, the associated data is permanently deleted within 30 days. Anonymous aggregates, as described above, are kept indefinitely.

Your rights

Under UK GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to how it is processed, or provide it in a portable form. Email us and we will do it. You may also complain to the Information Commissioner's Office.

Changes

If this policy changes, the date at the top changes with it and account holders are told by email where the change is material.