The short version
We sell plain English, so here is this document in plain English. The detail below says the same things more carefully.
- We use no advertising, and no analytics unless you say yes. If you decline the cookie banner, or simply never answer it, no third party is told that you visited — with one exception: if you go to buy a plan, the checkout page loads Stripe’s payment form, so Stripe knows you are on that page. If you accept, this site loads Google Analytics so we can see which pages are worth writing more of. Nothing else on this website loads anything from anybody else, and everything stored on your device is listed on the cookie page.
- You can scan a website without telling us who you are. We record the address you scanned and your IP address, and nothing else.
- We only email you if you ask us to. Product updates are a separate tick-box that starts unticked.
- We never sell your data, and we do not use it for advertising.
- One paragraph of a paid report is written by an AI, and it is labelled as such. It gets a summary of the problems found and the address of the site, and never the list of affected pages. Everything else in a report is produced by our own software and sent nowhere.
- We delete the raw evidence from a scan after 90 days and remove IP addresses from our records after 12 months.
Who we are
Keslo is a trading name of No Fear Tech Ltd, a company registered in England and Wales. We are the “data controller” for the information described here, which means we decide what is collected and why, and we are responsible for it.
- Company number: [company number]
- Registered office: [registered address]
- ICO registration number: [ICO registration number]
- Email: hello@keslo.co.uk
What we collect
When you run a scan
- The website address you asked us to check. This is usually a business, but it can identify a person if the site is a personal one.
- Your IP address. We record it against the scan so we can spot misuse. Keslo points automated traffic at whatever address it is given, and without this record it would be a free reconnaissance service. We have no way to see who you are from it.
You do not need an account, an email address or a name to run a scan.
When you ask for your report by email
- Your email address, so we can send you that report.
- Whether you opted in to product updates. This is a separate tick-box which starts unticked. Asking for your own report is not treated as agreeing to marketing.
- The IP address and time you gave that consent, as the record that you did.
When you use the contact form
Your name, your email address and whatever you write in the message.
When you create an account
We hold your email address and a hashed version of your password — a one-way scramble that cannot be turned back into the password you chose. We will never be able to tell you what your password is, only let you set a new one.
Alongside that, an account records:
- When you signed up, when you last signed in, and whether you have confirmed your email address.
- Which plan you are on, any add-ons, and how many scan credits you have left.
- Your Stripe customer and subscription reference, if you have ever paid us — see below. Never a card number.
- The sites you have verified, the scans you have run, and any schedules, monitors, API keys or webhooks you have set up.
- A session cookie while you are signed in, listed on the cookie page.
You can download all of it, or close the account, from your own account settings — no need to ask us. See your rights.
What closing an account does, precisely. Your email address and password are erased, every sign-in session ends, and any Google connection is revoked and its credentials destroyed. The scans you ran are unlinked from you rather than deleted, and their reports stay reachable at the addresses they already have. That is deliberate: a report is a page people forward to a developer or a client, and deleting one months later would break a link somebody else is relying on. Once unlinked, nothing connects those reports to you — and the raw evidence behind them expires on the usual 90 days regardless. If you want a specific report taken down as well, email us and we will do it.
Data on the sites we scan
This one is unusual and worth spelling out, because most privacy policies have no reason to mention it.
To check a website we download its pages and take screenshots, and we keep that copy so we can re-examine it later without troubling the site again. If a page contains personal information — staff names, photographs, direct email addresses, a phone number — then our copy contains it too.
We do not go looking for it, we do not index it, we do not extract it and we never use it for anything except producing the report for that scan. It is deleted with the rest of the raw evidence after 90 days. We only ever fetch pages that are already published for anyone to read, and we respect the instructions a site publishes in its robots.txt file.
If your website has been scanned and you want our copy of it removed sooner, email us and we will do it.
Why we are allowed to (lawful bases)
| What | Lawful basis | In plain terms |
|---|---|---|
| Running the scan you asked for, and emailing you the report | Contract | You asked us to do a thing; we cannot do it otherwise. |
| Recording your IP address against a scan | Legitimate interests | To stop Keslo being used to attack or survey other people’s websites. We judged this to be in the interests of those site owners as well as ours, and it is the least we can record and still spot a pattern. |
| Product update emails | Consent | Only if you tick the box. You can withdraw at any time and every email has an unsubscribe link. |
| Replying to your message | Legitimate interests | You contacted us and presumably want an answer. |
| Copying the pages of a site being scanned | Legitimate interests | We cannot report on a website without reading it. We keep the copy only as long as the report can still be re-checked against it. |
Google Search Console data
If you connect a Google account so we can read Search Console, this section applies. If you have not, none of it does.
What we ask for
One permission and no others: read-only access to Search Console (webmasters.readonly). We cannot change anything in your Google account, submit or delete sitemaps, or alter your website. There is no code path in our software that writes to Search Console, and the permission we hold would refuse it if there were.
What we read, and what we do with it
- Your list of properties — so you can choose which one speaks for which site.
- Search performance figures — how often your pages were shown, clicked, and their average position.
- Google’s indexing verdict on individual pages — whether it indexed a page, and if not, what it says about why.
- Your sitemap records — what has been submitted and whether Google could read it.
All of it is used for one thing: producing the findings in your own reports. We do not use it to build advertising or marketing profiles, we do not sell it, we do not transfer it to anyone else except the infrastructure providers listed below who host it on our behalf, and no human at Keslo reads it except where you have asked us to look at something and we have said so.
Limited Use
Keslo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How it is stored
The token that lets us read your account is the only value in our database that is encrypted at rest. It cannot be hashed, because we have to use it, so it is encrypted with a key held separately from the database — and it is never written to a log, an error message or a report.
Getting rid of it
Disconnecting from your Search Console settings revokes our access at Google and deletes everything we hold from it immediately— the property list, the search figures and the indexing results, whatever their age. You can also remove our access from your own Google account’s permissions page, which has the same effect at Google’s end and leaves us to delete our copy on our next sweep.
Even without disconnecting, raw Google data is deleted after 90 days — the same window as everything else we collect, so there is one number rather than two. Findings already written into a report stay, because a report is a document you may have sent to somebody else; they describe a website rather than a person.
How long we keep it
| What | How long | Then what |
|---|---|---|
| Raw evidence from a scan (pages, screenshots, headers) | 90 days | Automatically deleted. |
| Raw Google Search Console data | 90 days, or immediately on disconnect | Deleted. Disconnecting does not wait for the 90 days — see Google Search Console data. |
| The findings and report produced from it | Indefinitely | Kept so you can compare a site over time. These describe a website, not a person. |
| IP addresses | 12 months | Removed from the record automatically. The rest of the entry stays, without anything identifying. |
| Your email address | Until you ask us to remove it | Deleted on request, or when you close your account. |
| Contact form messages | [decide: suggest 24 months] | Deleted. |
These are enforced by software that runs automatically, not by somebody remembering to do it.
Who else sees it
A very short list. We do not sell data, share it with advertisers, or allow anyone to use it for their own purposes.
| Who | What for | Where |
|---|---|---|
| Resend | Delivering report emails and contact form messages | United States |
| Anthropic | Writing the “where to start” plan on a paid report — see below for exactly what is sent | United States |
| Stripe | Taking payments, and only if you buy something — see paying for a plan | United States |
| netcup | Hosting the servers everything runs on | Germany |
| Wasabi | Storing the evidence behind a report — the page contents, screenshots and timings a finding is based on | United Kingdom |
If you decline the cookie banner, or never answer it: there is no analytics provider, no advertising network, no tag manager and no social media tracking on this website, and none of these pages loads anything from anybody else. The photographs are served from our own servers rather than fetched from a third party by your browser, so nobody else is told which pages you looked at. Declining is not a preference we record and work around — the Google script is never requested at all, which you can check in the network tab of your own browser.
If you accept: this site loads Google Analytics, which sets the two cookies named on the cookie pageand tells Google which of our pages you looked at and roughly where in the world you are. We use it to see which guides are worth writing more of. You can change your mind whenever you like by clearing this site’s storage in your browser, which brings the banner back.
There is one further exception, and it is the checkout page. If you go to buy a plan, that page loads Stripe’s payment form, which means Stripe’s software runs on it and Stripe knows you are there. No other page on this website does that, you cannot arrive at it by accident, and it happens whatever you chose about analytics — a payment cannot be taken without a payment processor. What that involves is set out below.
Paying for a plan
We use Stripe to take payments. This section applies only if you buy something; if you have not, none of it does.
We never see your card
The payment form on our checkout page is Stripe’s, shown inside our page rather than on their website. Your card number is typed into Stripe’s form and goes straight to Stripe — it does not pass through our servers, is not stored by us, and is not something we could show you or anybody else if we wanted to. What we are told afterwards is that a payment succeeded, which plan it was for, and the last four digits and expiry so your billing page can show you which card is on file.
What Stripe is told
Your email address, what you are buying and what it costs, and the technical details of the payment itself. Stripe also collects information about the device you are using to check the payment is not fraudulent — that is what the two cookies described on the cookie page are for, and they are set only on the checkout page.
Why the form is on our page rather than theirs
So that buying something does not send you off to a different website halfway through. The card fields are still Stripe’s own, sealed off from the rest of the page, which is what keeps the arrangement above true: moving the form did not move where the card number goes.
If something on your connection blocks Stripe — an ad blocker or a company network, which does happen — the page says so and offers to send you to Stripe’s own checkout instead, which does not need it.
Sending data outside the UK
Resend and Anthropic are both based in the United States, so emails we send you pass through there, and so does the short summary of findings described below. Both transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which is the arrangement UK law provides for exactly this. Our servers are in Germany, which the UK recognises as offering equivalent protection, and the evidence behind your reports is stored in the United Kingdom, which leaves the country it started in not at all.
Cookies
This website sets no advertising cookies of any kind, and no analytics cookies unless you accept the banner. The rest is what makes the site work: a login cookie if you have an account, a note of whether you asked for the light or dark version, a short list of the reports you have opened so the start page can offer them back, and — on the checkout page only — Stripe’s two fraud checks. None of those needs your consent, because none of them is used to recognise or measure you. The cookie page is the complete list, generated from the same declaration the site itself uses, and it says how long each one lasts and where to find it in your own browser.
Your rights
Under UK data protection law you can ask us to:
- Show you what we hold about you, and give you a copy.
- Correct it if it is wrong.
- Delete it.
- Stop using it for a particular purpose, or restrict what we do with it while a disagreement is sorted out.
- Give you a portable copy in a standard machine-readable format, so you can take it elsewhere.
- Stop sending you marketing, which you can also do from any email we send.
Two of these you can do yourself, immediately. If you have an account, your account settings have a button to download everything we hold about you as a machine-readable file, and another to close the account — no request, no waiting. What closing it does is set out above.
For anything else, email hello@keslo.co.uk and we will respond within one month. These rights are free to use. If you ask us to delete something we are required to keep, we will tell you what and why rather than quietly keeping it.
One limitation: if you scanned a site without giving us an email address, we have no way to connect that scan to you, so we cannot find it on request. You will need to tell us the address you scanned and roughly when.
How we protect it
- Everything travels over an encrypted connection.
- Passwords are hashed and never stored in a readable form.
- Access to the servers is limited to named people using cryptographic keys, not passwords.
- Data that is no longer needed is deleted automatically rather than accumulating.
If we ever suffer a breach that puts you at risk, we will tell the ICO within 72 hours and tell you without undue delay.
Automated scoring
Keslo produces a score for a website automatically. This is a judgement about a website, not about a person, and it has no legal effect on anybody and does not decide anything about you. Every finding shows the evidence behind it, and you are welcome to disagree with us — tell us and we will look at the rule.
The “where to start” plan
A paid report can carry a short plan at the top of the findings list, saying which of the problems are really the same problem and what order to tackle them in. That paragraph is written by Anthropic’s Claude, which means a small amount of information about the scan leaves our servers. Everything else in a report — every finding, the score, and every written fix — is produced by our own software and is sent nowhere.
What is sent: the address of the website scanned, and for each problem found, its name, how serious it is, the sentence explaining why it matters, and how many places on the site it affects.
What is not sent, deliberately: the list of affected page addresses. It is the most identifying part of a scan and it is not needed to answer the question being asked, so it never leaves our servers — the model is told that four hundred pages are affected, never which four hundred. Nothing about you as a person is sent: no name, no email address, no account details. If you are not logged in, or your report is a free one, nothing is sent at all.
The plan is stored on our servers and reused for any later scan that finds exactly the same problems, so a site that has not changed does not send anything a second time. We use Anthropic’s commercial API, whose commercial terms say the data sent is not used to train their models.
Children
Keslo is a business tool and is not directed at children. We do not knowingly collect information about anyone under 18. If you believe we have, tell us and we will delete it.
Changes to this policy
When we change this page we will change the “last updated” date at the top. If a change matters — a new recipient of your data, a new purpose, a longer retention period — we will say so prominently rather than relying on you noticing a date.
If you want to complain
Please tell us first, so we get the chance to put it right. You also have the right to complain directly to the UK regulator, the Information Commissioner’s Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to come to us first.