Privacy Policy

Last updated: June 23, 2026

1. Introduction

OriAudit ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard information when you use our website auditing service. We process the minimum amount of data necessary to provide the Service.

2. Information We Collect

2.1 Information You Provide

  • Website URLs: The URLs you submit for auditing. These are used solely to perform the requested audit.

2.2 Automatically Collected Information

  • Browser Fingerprint: A non-identifying hash generated client-side, used exclusively for rate limiting. This is not a tracking mechanism and cannot be used to identify you personally.
  • IP Address: Your IP address may be logged in standard server logs for security and abuse-prevention purposes.
  • Usage Data: Basic request metadata (timestamps, audit IDs) needed to operate the Service.

2.3 Information We Do NOT Collect

  • We do not require account creation, email addresses, names, or any personal identifiers.
  • We do not use third-party analytics or advertising trackers.
  • We do not collect payment information (the Service is free).

3. How We Use Information

We use the collected information exclusively to:

  • Perform website audits you request.
  • Enforce rate limits to ensure fair usage.
  • Maintain and improve the Service.
  • Prevent abuse and ensure security.

4. Data Retention

  • Audit results are stored temporarily in a local database and may be automatically purged. They are not stored permanently.
  • Rate-limiting data (fingerprint hashes) is stored only for the duration of the rate-limit window (currently one hour) and then discarded.
  • Server logs containing IP addresses are retained for a reasonable period for security purposes and then deleted.

5. Data Sharing

We do not sell, rent, or share your data with third parties, except in the following limited circumstances:

  • Legal obligations: If required by law, regulation, or legal process.
  • Service providers: Hosting and infrastructure providers that process data on our behalf under strict confidentiality agreements.

6. Cookies

OriAudit does not use tracking cookies or advertising cookies. We may use essential, strictly necessary cookies or local storage for the basic functioning of the Service (such as rate-limit enforcement). For more details, see our Cookie Policy.

7. Third-Party Websites

When you submit a URL for auditing, our Service accesses that website to analyze its publicly available content. We only access information that is publicly available to any web browser. We do not access password-protected areas, submit forms, or interact with the audited website beyond standard HTTP requests.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request deletion of your data.
  • Object to or restrict processing of your data.
  • Data portability.
  • Withdraw consent at any time (where processing is based on consent).

Since we collect minimal data and do not require accounts, most of these rights are satisfied by design. To exercise any of these rights, contact us at [email protected].

9. GDPR Compliance (EEA Users)

If you are located in the European Economic Area (EEA), we process your data under the following legal bases:

  • Legitimate interest: Processing necessary to provide the Service you requested (performing the audit).
  • Legal obligation: Where required by law (security logging).

You have the right to lodge a complaint with your local data protection authority if you believe your data is being processed unlawfully.

10. CCPA Compliance (California Users)

If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information. Since we do not collect personal identifiers beyond what is described above, most CCPA requirements are satisfied by default.

11. Children's Privacy

The Service is not directed at children under 13. We do not knowingly collect information from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.

12. Security

We implement reasonable technical and organizational measures to protect data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet is 100% secure.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.

14. Contact

For privacy-related questions or requests, contact us at [email protected].