Ian Nuttall operates ian.is. This policy explains what the site collects, why, how long it keeps it, and how you remove it. It covers the website, your ian.is account, and the tools you use while signed in.

Your ian.is account

You can sign in with Google or GitHub. We do not use passwords. When you sign in, we store:

  • your name, email address and profile picture from the provider you chose;
  • the provider’s account ID, so the same account signs you in next time;
  • a session record with the time, IP address and browser user agent of the sign-in; and
  • a small cookie that remembers whether you last signed in with Google or GitHub, so the sign-in page can mark it. This cookie lasts 30 days and holds only the provider name.

A session lasts 7 days and renews while you use the site. Signing out ends the session at once.

If you sign in with GitHub, we ask GitHub only for your profile and email address. We do not access your repositories.

Google data we can access

A plain Google sign-in asks only for your name, email address and profile picture. Some tools need more. They ask for it separately, and only when you choose to use them:

  • Search Console (read only). We list the Search Console properties you can already access and read their search performance data. For the index monitor, we also ask Google’s URL Inspection API whether each of your pages is indexed.
  • Google Analytics (read only). We list the Google Analytics accounts and properties you can already access and read report data such as sessions, users and key events.

Google shows you each permission on its consent screen before you approve it. Both permissions are read only. We cannot change, add or delete anything in your Search Console or Google Analytics accounts.

We use this data only to show you your own data inside the tools you use on ian.is. Google Analytics data is requested when you open a tool or run a report and shown to you. We do not keep a copy of your Analytics data, only the reports you run: when you run an Analytics tool, such as AI referral traffic, its finished report (totals, sources, landing pages and days) is kept with your other reports.

When you add a Search Console property to your sites, we store some of its search performance data so the SEO tools can find work for you and measure the changes you mark done:

  • daily clicks, impressions and position for the whole site and for each page, for up to 16 months;
  • daily clicks, impressions and position for each query on each page, for the last 56 days;
  • for Content decay, each page’s clicks and impressions over the same 56 days a year earlier, as two totals, replaced on each run; and
  • the results of each tool run, which include queries and their numbers, and the items you mark done or dismiss.

This data is kept on Cloudflare, separately for each site you add, and is used only for your tools on ian.is.

When you start an index monitor on a Search Console property, we store, for each URL in that property’s sitemaps or with Search Console impressions: which sitemap lists it and its Search Console clicks and impressions in the last 28 days, Google’s URL Inspection answer (indexed or not, Google’s reason, when Google last crawled it, the canonical you set and the one Google chose, whether robots.txt blocks it, and up to five pages Google says link to it), when we checked it, and each change Google made since the last check. For a URL Google cannot find or read that no sitemap lists, we fetch it from your site with ianbot and keep only what your site answered (its status and where it redirects). We also keep the list of sitemaps we read and a daily count of indexed URLs. This is kept separately for each monitor and used only for that monitor on ian.is.

“Send feedback” on a report emails Ian your note with your email address, your account id, the report and item it is about, and your browser and window size. We keep the note with your account until you delete it.

“Copy for agent” on a tool run makes a secret link to that run’s report, so an AI agent can read it. Anyone with the link can read that report without signing in, while the run keeps its live report and for 90 days after the link was made. “Reset link” turns the old link off at once.

The tools also fetch the public pages of your site that appear in a tool’s results, with ianbot, to check which of their searches each page mentions. We keep only the result of that check, not the page.

To sort a tool’s results by what searchers want (to learn, to compare, to buy, or to reach a site), we send TypeSafe the words of the searches in those results and your site’s domain, without their numbers. We keep the label for each search for up to 180 days, so a search is sent only once.

To check whether a page answers the questions people search for (the AI answer check), we send TypeSafe the words of those question searches, without their numbers, with the page’s address, title, headings and the opening sentences under each heading. We keep only the result. The same check asks for your home page once in the name of each AI crawler, to see whether your firewall lets it in. Before you see its steps, a final check sends Cloudflare Workers AI each step with its search, the page’s address, title and H1, to ask yes or no whether the search is a real question and the step fits the page. Cloudflare says it does not store this unless we choose to, and does not use it to train models. We keep only its yes or no answers. Cannibalisation sends its steps to the same check.

To sort the results of Content gaps, we send TypeSafe each search in the results with its variants, and the address, title, H1 and headings of the page Google shows for it. Jev answers what each search wants and the kind of page to write. We keep only those answers.

To group your searches by what people want, Quick wins and Content gaps first build a map of your site’s needs, at most once a week. We send DataForSEO the words of your top searches (up to 60) and of your top pages’ main searches, without their numbers, to get Google’s top 10 results for each in the United States, and those searches’ words to get their monthly search volume. We send TypeSafe the words of up to 200 searches, and your pages’ addresses with their main searches, to ask which searches want the same thing and how close each is to a page’s own topic. We keep the results and answers for 30 days (the top 10 and volumes) or until the map is rebuilt.

To decide whether pages that compete for the same searches meet the same need, Cannibalisation sends TypeSafe each page’s address, title, H1, meta description, headings and a short part of its text, with the searches the pages share and their impressions. We keep only its answer.

Translation opportunities reads your site’s impressions by country for the run, and keeps them in that run’s results. To find the language of your searches, it sends TypeSafe their words and your site’s domain. To turn them into the words people use in other languages, it sends Cloudflare Workers AI your top pages’ searches, those pages’ addresses and your domain. It then sends DataForSEO only the translated searches, with a language and a country, to get their search volumes: never your site, your numbers or who you are. We keep each search’s volume for 30 days and reuse it for anyone who checks the same search, without a record of which site or person asked.

To keep your access working without asking you again, we store the OAuth tokens Google gives us. The tokens are encrypted before they are saved in our database on Cloudflare, and only the ian.is application can decrypt them.

Limited Use

ian.is’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • we use Google user data only to provide and improve the features you see in ian.is tools;
  • we do not sell Google user data or use it for advertising;
  • we do not use Google user data to train general-purpose AI or machine learning models; and
  • no person reads your Google user data unless you ask us to (for example, for support), it is needed for security or abuse investigation, or the law requires it.

Remove ian.is’s access to your Google account

You can remove ian.is’s access at any time. You do not need to contact us.

  1. Go to Third-party apps & services in your Google Account. Sign in to the Google account you connected if Google asks.
  2. Find ian.is in the list and select it.
  3. Select Delete all connections you have with ian.is.
  4. Confirm.

Google then stops all ian.is access to Search Console, Google Analytics and your profile at once. Our stored tokens stop working. Tools that need Google data will ask you to connect again if you want to use them.

To also delete the tokens and your account from our database, delete your account.

Remove ian.is’s access to your GitHub account

  1. Go to Authorized OAuth Apps in your GitHub settings.
  2. Find ian.is and select Revoke.
  3. Confirm.

Delete your account

You can delete your account yourself, at any time: go to Settings, select Delete account and type your email to confirm. It happens straight away.

We delete:

  • your account, sessions and settings
  • your Google and GitHub connections and their tokens. We also revoke our access with Google and GitHub.
  • your sites, their Search Console data, your index monitors and the URL Inspection data they keep, your runs, reports and agent links
  • your credits. Any credits left are lost, not refunded.
  • a monthly plan, if you have one. We cancel it straight away, with no refund.

We keep:

  • Invoices, in Stripe, because tax law says we must keep them. The Stripe customer record they belong to stays with them.
  • Your newsletter subscription, which is separate from your account. The dialog offers to unsubscribe you at the same time, and every issue has an unsubscribe link.

How we protect your data

We treat your Google user data, OAuth tokens and account details as sensitive data and protect them as follows.

  • Encrypted in transit. Every connection to ian.is uses HTTPS (TLS). Our servers talk to Google and to the service providers named in this policy over HTTPS only.
  • Encrypted at rest. We store data only on Cloudflare: in D1 (our database), Durable Objects (each site’s Search Console data and each index monitor’s URLs) and R2 (files). Cloudflare encrypts all of it at rest with AES-256.
  • OAuth tokens encrypted by us as well. Before we save a Google or GitHub token, ian.is encrypts it with XChaCha20-Poly1305, using a key kept in Cloudflare’s encrypted secret storage. Only the ian.is application can decrypt it. Tokens are never shown on a page, sent by email or written to logs.
  • Only what a tool needs. We ask Google for read-only access, and only for the tools you use. We never write to your Google account.
  • Your data stays yours. Each site’s Search Console data is kept separately and can only be read through your signed-in account. Pages that show your data are private and are not indexed by search engines. We block requests that try to act on your account from other websites.
  • Limited staff access. ian.is is run by one person. Only he can reach the production systems, through accounts protected by two-factor authentication, and the admin tools need a separate secret key. He does not read your Google user data except as described under Limited Use.
  • If something goes wrong. If we learn of a security incident that affects your data, we will fix it, tell you without undue delay, and tell Google and the authorities where the law requires it.

How long we keep data

  • Account and tokens: until you delete your account, then deleted at once. If you remove access in your Google Account, the tokens stop working at once, and we delete them with your account.
  • Sessions: until they expire, 7 days after your last visit, or until you sign out.
  • Google Analytics data: not stored, except in the reports you run (below).
  • Search Console data for your sites: until you remove the site or delete your account, when it is deleted straight away, or until the Google account that reads a site is removed from your ian.is account, when it is deleted within 7 days.
  • Index monitor data: until you delete the monitor or your account, when it is deleted straight away. The changes Google made to each URL are kept for 400 days. A URL no longer in your sitemaps or Search Console is kept, but not checked again.
  • Reports: every report a tool makes for you is kept until you delete your account, so you can open it again from your Reports page. Only you can open them. Removing a site deletes that site’s reports straight away. They stay if Google access for the site expires or you disconnect Google. Deleting your account deletes all of them at once.

Email updates

If you subscribe, we store your email address, delivery frequency, subscription status and the time zone Cloudflare infers from your browser request. Emails are delivered by Postshiba.

Messages contain an image and signed links that record opens and clicks. This helps measure which subjects and posts are useful, although email privacy tools can make open counts approximate. You can change frequency or unsubscribe from any email. Delivery failures, spam complaints and opt-outs are kept as suppression records so those addresses are not contacted again.

The internal links tool crawls the public site you enter, while you are signed in. Each run is kept with your account: the site address, the page limit, its credits and the report. The pages it crawled are deleted after 30 days; the report is kept until you delete your account, and only you can open it. Reports from before sign-in was needed stay at their private link for 7 days and are then deleted.

The sitemap health tool

The sitemap health tool reads the robots.txt, sitemaps and public pages of the site you enter, while you are signed in, with ianbot. It reads only the head of each page. Each run is kept with your account: the site address, the URL limit, its credits and the report. The report is kept until you delete your account, and only you can open it.

The index monitor

The index monitor reads the sitemaps of the Search Console property you pick, from Search Console and the site’s robots.txt, with ianbot, and the pages with impressions in Search Console. It then asks Google’s URL Inspection API about each URL through your own Search Console access, read only, up to Google’s daily limit for each property, and again every day while the monitor runs. It never asks Google to index a page and never changes your Search Console. Unless you turn them off on the monitor, we email you the addresses of pages Google dropped or that turned blocked or broken. What it keeps is described above, under the Search Console permission. Only you can open a monitor.

The pSEO ideas tool

The pSEO ideas tool sends the seed keywords you enter, with the country you pick, to DataForSEO for search data and sample results pages. Search phrases and results from that data (not your account details) go to TypeSafe’s Jev to sort them, and the domains that rank go to Ahrefs for their Domain Rating. Your seeds are kept only with the run’s report, which only you can open, until you delete your account. They are never logged or put in site analytics. Each seed’s result is kept for 30 days under a one-way code made from the seed, so anyone who runs the same seed in the same country gets it again without us fetching it twice; nobody can see which seeds were run. Surprise me picks its topic from public search data and never uses anyone’s seeds. If you add your site, ianbot reads its robots.txt and sitemaps to list your pages; the list is used for that run only. A run on your own Search Console searches reads the data already stored for your site and sends only search phrases to Jev.

The backlink finder reads your home page with ianbot, following robots.txt, and uses its own title, H1 and meta description as your product’s description when you do not write one. It sends your domain to DataForSEO for the searches your site ranks for, and up to five of them for the sites Google ranks for them, reads the home pages of the sites found, and sends their first part with your description to TypeSafe’s Jev, which judges which are competitors. The competitors are kept for 30 days for anyone, without who asked. It then sends your competitors’ domains to DataForSEO for the sites that link to them, kept for 7 days for anyone, and your domain for the sites that link to you; the linking sites’ hosts to DataForSEO and their domains to Ahrefs for their rank and Domain Rating, kept for 30 days. ianbot reads each linking page, and checks a competitor’s linked page again when the data says it is broken, and a directory’s pages for its submission form. To judge each lead, it sends Jev your product description with what it read on the linking page: its address, title, H1, meta description, headings, the competitor’s link and the sentences around it. No AI model writes anything for you. We keep only the report. It lists the contact pages each site publishes, never an email address it found. Your description is kept only with the run’s report, which only you can open, until you delete your account, and is never logged or put in site analytics.

Site analytics

We record signed-in tool use, credits, payments and provider costs to check our prices, without seeds, search queries, page addresses or page text. We keep raw use events for 180 days and keep daily totals after that. After account deletion, we keep these records with your account ID removed and credit notes cleared.

We use Clicky to count visits and see which pages people read. Clicky receives normal browser and request information such as the page, referrer, device and IP address. This is separate from any Google data you connect. Our site analytics never include your Search Console or Google Analytics data.

Cloudflare hosts the site and may process normal request data, such as IP address, user agent, requested path and time, to deliver and protect it.

Sharing and sale

We do not sell personal information. We share it only with the service providers named in this policy that help run the site (Cloudflare, Postshiba, Stripe and Clicky, and for the tools DataForSEO, TypeSafe and Ahrefs), when the law requires it, or when needed to protect the site and its users.

Changes to this policy

We update this policy when what we collect, how we use it or how long we keep it changes. The date at the top shows the last change.

Contact

You can delete your reports, sites or whole account yourself in your account settings, without asking. For any other privacy question, press Send feedback on any report, or reply to any email ian.is has sent you, such as your welcome email, a report email or a newsletter issue. Both come straight to me.