Trust and data handling
Privacy
OpenForBots audits public website resources without requiring an account, email address, or advertising profile.
Last updated: .
Audit requests
When you run an audit, OpenForBots sends bounded requests to the public hostname and standard public resources you submit.
Audit report storage
Completed audits are stored so a future release can show you audit history for a site you've claimed. What's stored today: the hostname you submitted, the site's own final URL after any redirects it issued, the check timestamp, a status and finding/actionable count, and the full generated report. The index is kept in a Cloudflare D1 database; the report itself is kept as a file in a Cloudflare R2 bucket. Nothing beyond the hostname you submit and the report OpenForBots generates from public evidence is intentionally stored — do not submit URLs containing credentials, tokens, or other secrets (see Terms).
OpenForBots does not yet offer accounts or sign-in, so every stored audit today is anonymous and unclaimed. Anonymous audits are automatically and permanently deleted, index row and report file together, 30 days after the check completes; deletion is enforced by a scheduled process, not a manual step. When account-based history ships in a later release, this section will be updated to describe claimed-audit retention separately.
Information processed
The service processes the hostname you submit, public response metadata, bounded public response content needed for the audit, the generated findings, and routine technical metadata needed to deliver and secure the request.
Contact, feedback, partnership, and remediation messages
Contact, feedback, and partnership messages continue to use the same protected message path. If you choose to use any message form, including an audit remediation request, OpenForBots processes the fields you submit so the message can be reviewed, the product can be improved, and a reply can be sent where appropriate. Depending on the form, this may include your name, reply email, organization, role, organization website, selected topic, optional experience rating, message text, and for a remediation request bounded technical context such as remediation family, capability ID, and finding rule ID. The pre-filled remediation request link and message form do not intentionally place the audited hostname, evidence text, credentials, or fetched content into the message.
Public forms use Cloudflare Turnstile and Cloudflare-hosted request handling to reduce automated abuse. Turnstile and related infrastructure may process IP addresses, device or browser signals, timestamps, and security metadata needed to evaluate the request. Form notifications are delivered to a controlled OpenForBots inbox through Cloudflare email infrastructure. OpenForBots does not use submitted message content to build advertising profiles.
Do not submit credentials, private URLs, access tokens, customer data, confidential reports, unpublished vulnerability details, or other sensitive information through ordinary contact forms. Remediation access, backups, authorization, and rollback are agreed separately after a request is qualified. Security reports should follow the security-reporting guidance.
Messages and related email records may be retained for as long as reasonably needed to answer the enquiry, maintain a correction or support record, prevent abuse, or meet operational and legal obligations. OpenForBots does not currently promise a fixed deletion interval for ordinary correspondence.
Operational logs and infrastructure
OpenForBots is delivered through Cloudflare infrastructure. Cloudflare and related hosting systems may process IP addresses, timestamps, request paths, user agents, network diagnostics, security events, and error logs according to the service configuration and Cloudflare's applicable terms. OpenForBots does not currently promise a specific infrastructure-log deletion interval.
Cookies and analytics
OpenForBots does not currently use advertising cookies, browser storage, or visitor identifiers for analytics, and does not build cross-site marketing profiles. Essential security or delivery features provided by infrastructure services may use cookies or equivalent storage when technically required.
OpenForBots counts product usage in aggregate: for example, how often a tool or audit is started versus completed. Each event carries only a fixed, pre-approved set of coarse labels — which tool, which audit focus, success or failure, a general error category — and the day it happened; it is combined into daily counter totals, not stored as an individual record. Counting never includes the hostname or URL you submitted, page paths, IP address, user agent, referrer, cookies, or any account or visitor identifier, because none of those are collected at all. There is no way to reconstruct an individual visit or visitor from these counters.
Public results
Audit output reflects public evidence available at the time of the check. Results are displayed in your browser and are not a guarantee of indexing, citation, ranking, recommendation, traffic, or model use.
International processing
Cloudflare operates a global network, so routine request and security data may be processed in countries other than the one from which you use the service, subject to the provider's contractual and legal safeguards.
Your choices
Do not submit private hosts, credentials, URLs containing secrets, personal data that is not already intentionally public, or content you are not authorised to assess. Because the current release does not provide user accounts, there is no way to sign in, browse, or manually delete a saved-report record through the product yet — the 30-day automatic deletion described above is the only retention control today.
You do not need to use a web form to contact OpenForBots. Published support, feedback, partnership, and remediation email routes are available on the relevant pages.
Changes and questions
Material changes to this notice will update the date above. Use the published contact routes for privacy questions or corrections. Do not place sensitive security information in a public issue; use the private security-reporting route.