The short version
We sell plain English, so here is this document in plain English. The detail below says the same things more carefully.
- We use no advertising, and no analytics unless you say yes. If you decline the cookie banner, or simply never answer it, no third party is told that you visited — with one exception: if you go to buy a plan, the checkout page loads Stripe’s payment form, so Stripe knows you are on that page. If you accept, this site loads Google Analytics so we can see which pages are worth writing more of. Nothing else on this website loads anything from anybody else, and everything stored on your device is listed on the cookie page.
- You can scan a website without telling us who you are. We record the address you scanned and your IP address, and nothing else.
- We only email you if you ask us to. Product updates are a separate tick-box that starts unticked.
- We never sell your data, and we do not use it for advertising.
- One paragraph of a paid report is written by an AI, and it is labelled as such. It gets a summary of the problems found and the address of the site, and never the list of affected pages. Everything else in a report is produced by our own software and sent nowhere.
- You can let us read your site’s Google Search Console, and nothing happens unless you do. It is read-only, it is used only to write your own reports, and disconnecting deletes everything we read from it straight away. Reading Google Analytics is built but not switched on yet — it needs Google’s approval first, and will be a separate choice.
- We delete the raw evidence from a scan after 90 days and remove IP addresses from our records after 12 months.
Who we are
Keslo is a trading name of No Fear Tech Ltd, a company registered in England and Wales. We are the “data controller” for the information described here, which means we decide what is collected and why, and we are responsible for it.
- Company number: [company number]
- Registered office: [registered address]
- ICO registration number: [ICO registration number]
- Email: hello@keslo.co.uk
What we collect
When you run a scan
- The website address you asked us to check. This is usually a business, but it can identify a person if the site is a personal one.
- Your IP address. We record it against the scan so we can spot misuse. Keslo points automated traffic at whatever address it is given, and without this record it would be a free reconnaissance service. We have no way to see who you are from it.
You do not need an account, an email address or a name to run a scan.
When you ask for your report by email
- Your email address, so we can send you that report.
- Whether you opted in to product updates. This is a separate tick-box which starts unticked. Asking for your own report is not treated as agreeing to marketing.
- The IP address and time you gave that consent, as the record that you did.
When you use the contact form
Your name, your email address and whatever you write in the message.
When you create an account
We hold your email address and a hashed version of your password — a one-way scramble that cannot be turned back into the password you chose. We will never be able to tell you what your password is, only let you set a new one.
Alongside that, an account records:
- When you signed up, when you last signed in, and whether you have confirmed your email address.
- Which plan you are on, any add-ons, and how many scan credits you have left.
- Your Stripe customer and subscription reference, if you have ever paid us — see below. Never a card number.
- The sites you have verified, the scans you have run, and any schedules, monitors, API keys or webhooks you have set up.
- A session cookie while you are signed in, listed on the cookie page.
You can download all of it, or close the account, from your own account settings — no need to ask us. See your rights.
What closing an account does, precisely. Your email address and password are erased, every sign-in session ends, and any Google connection is revoked and its credentials destroyed, along with everything we had read through it. The scans you ran are unlinked from you rather than deleted, and their reports stay reachable at the addresses they already have. That is deliberate: a report is a page people forward to a developer or a client, and deleting one months later would break a link somebody else is relying on. Once unlinked, nothing connects those reports to you — and the raw evidence behind them expires on the usual 90 days regardless. If you want a specific report taken down as well, email us and we will do it.
Data on the sites we scan
This one is unusual and worth spelling out, because most privacy policies have no reason to mention it.
To check a website we download its pages and take screenshots, and we keep that copy so we can re-examine it later without troubling the site again. If a page contains personal information — staff names, photographs, direct email addresses, a phone number — then our copy contains it too.
We do not go looking for it, we do not index it, we do not extract it and we never use it for anything except producing the report for that scan. It is deleted with the rest of the raw evidence after 90 days. We only ever fetch pages that are already published for anyone to read, and we respect the instructions a site publishes in its robots.txt file.
If your website has been scanned and you want our copy of it removed sooner, email us and we will do it.
Why we are allowed to (lawful bases)
| What | Lawful basis | In plain terms |
|---|---|---|
| Running the scan you asked for, and emailing you the report | Contract | You asked us to do a thing; we cannot do it otherwise. |
| Recording your IP address against a scan | Legitimate interests | To stop Keslo being used to attack or survey other people’s websites. We judged this to be in the interests of those site owners as well as ours, and it is the least we can record and still spot a pattern. |
| Product update emails | Consent | Only if you tick the box. You can withdraw at any time and every email has an unsubscribe link. |
| Replying to your message | Legitimate interests | You contacted us and presumably want an answer. |
| Copying the pages of a site being scanned | Legitimate interests | We cannot report on a website without reading it. We keep the copy only as long as the report can still be re-checked against it. |
Google Search Console and Analytics data
If you connect a Google account so we can read Search Console — or, when it becomes available, Analytics — this section applies. If you have not, none of it does, and nothing in this section happens by default.
Two different things share a name here, so: this section is about the Search Console and Analytics accounts for your own website, which you may choose to let us read so your reports can say more. It has nothing to do with the analytics we run on keslo.co.uk to count visits to our own pages — that is described under Cookies, it only runs if you accept the banner, and the two never meet.
What we ask for
Read-only permissions, and only ones you grant. We cannot change anything in your Google account, submit or delete sitemaps, alter your website, or modify anything in Analytics. There is no code path in our software that writes to any Google product, on any permission — not a stub, not a disabled feature, nothing that a configuration change could switch on.
- Search Console, read-only (
webmasters.readonly) — available now, and what the Connect button asks for today. - Analytics, read-only (
analytics.readonly) — a separate choice, and not connected unless you make it. Connecting Search Console does not grant this and does not imply it later: it is a second button, and a second consent screen at Google where you can decline it without affecting anything you have already connected. Our application has not yet completed Google’s review for a permission of this kind, so until it has you may see a warning from Google before the consent screen.
We are describing the second one before you can use it deliberately. It is in the software you would be granting access to, a reviewer or a curious customer can find it there, and reading about it first in a policy is better than discovering it in a source file.
What we read, and what we do with it
From Search Console:
- Your list of properties — so you can choose which one speaks for which site.
- Search performance figures — how often your pages were shown, clicked, and their average position.
- Google’s indexing verdict on individual pages — whether it indexed a page, and if not, what it says about why.
- Your sitemap records — what has been submitted and whether Google could read it.
From Analytics, once that permission becomes available and if you grant it:
- Your list of properties and their data streams — so you can choose which one speaks for which site.
- How the property is set up — its time zone, its data streams, which events you have marked as important, and how long Google keeps your data. Most of what we can tell you about Analytics is about its configuration rather than its figures, because the useful finding is usually that the numbers are being collected wrongly.
- Totals per landing page — sessions, engaged sessions and completed key events, so a report can say that a page losing ground in search is a page that was bringing in business.
- Totals per channel and per event name — to spot traffic Google cannot categorise, and events you have marked as important that have stopped firing.
- A sample of page paths — checked for personal data recorded in your own URLs, which is a real and common misconfiguration. If we find any, the report tells you the kind and the number and never prints the matches themselves: those would be your visitors’ personal data, and a finding is exactly the thing that gets forwarded and printed.
We ask for totals, never individuals. Every Analytics request we make is for figures grouped by page, channel or event — there is no request anywhere in our software for a user id, a device id, a client id, or anything else that describes one of your visitors rather than one of your pages.
All of it is used for one thing: producing the findings in your own reports. We do not use it to build advertising or marketing profiles, we do not sell it, we do not transfer it to anyone else except the infrastructure providers listed below who host it on our behalf, and no human at Keslo reads it except where you have asked us to look at something and we have said so.
Limited Use
Keslo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How it is stored
The token that lets us read your account is the only value in our database that is encrypted at rest. It cannot be hashed, because we have to use it, so it is encrypted with a key held separately from the database — and it is never written to a log, an error message or a report.
Getting rid of it
Disconnecting from your connected accounts revokes our access at Google and deletes everything we hold from it immediately — the property lists, the search figures, the indexing results and the Analytics figures, whatever their age, for both products at once and whether or not you had connected both.
Closing your Keslo account does the same thing, and does not need you to disconnect first: it revokes our access at Google and deletes the same data, before it erases the account itself.
You can also remove our access from your own Google account’s permissions page. That stops us reading anything further straight away, but it happens entirely at Google’s end and we only find out the next time we try to use the access — so what we have already stored is deleted on the usual 90-day sweep rather than at once. If you want it gone immediately, use the disconnect button, which is one click and does both.
Even without disconnecting, raw Google data is deleted after 90 days — the same window as everything else we collect, so there is one number rather than two, and one setting governs both products so neither can outlive the other. Findings already written into a report stay, because a report is a document you may have sent to somebody else; they describe a website rather than a person.
How long we keep it
| What | How long | Then what |
|---|---|---|
| Raw evidence from a scan (pages, screenshots, headers) | 90 days | Automatically deleted. |
| Raw Google data (Search Console and Analytics) | 90 days, or immediately on disconnect | Deleted. Disconnecting, and closing your account, do not wait for the 90 days — see Google Search Console and Analytics data. |
| The findings and report produced from it | Indefinitely | Kept so you can compare a site over time. These describe a website, not a person. |
| IP addresses | 12 months | Removed from the record automatically. The rest of the entry stays, without anything identifying. |
| Your email address | Until you ask us to remove it | Deleted on request, or when you close your account. |
| Contact form messages | [decide: suggest 24 months] | Deleted. |
These are enforced by software that runs automatically, not by somebody remembering to do it.
Who else sees it
A very short list. We do not sell data, share it with advertisers, or allow anyone to use it for their own purposes.
| Who | What for | Where |
|---|---|---|
| Resend | Delivering report emails and contact form messages | United States |
| Anthropic | Writing the “where to start” plan on a paid report — see below for exactly what is sent | United States |
| Stripe | Taking payments, and only if you buy something — see paying for a plan | United States |
| netcup | Hosting the servers everything runs on | Germany |
| Wasabi | Storing the evidence behind a report — the page contents, screenshots and timings a finding is based on | United Kingdom |
If you decline the cookie banner, or never answer it: there is no analytics provider, no advertising network, no tag manager and no social media tracking on this website, and none of these pages loads anything from anybody else. The photographs are served from our own servers rather than fetched from a third party by your browser, so nobody else is told which pages you looked at. Declining is not a preference we record and work around — the Google script is never requested at all, which you can check in the network tab of your own browser.
If you accept: this site loads Google Analytics, which sets the two cookies named on the cookie pageand tells Google which of our pages you looked at and roughly where in the world you are. We use it to see which guides are worth writing more of. You can change your mind whenever you like by clearing this site’s storage in your browser, which brings the banner back.
This is our own visitor counting, and it is not the Analytics feature in the product. Keslo can also read the Search Console and Analytics accounts for your own website, if you connect them, so your reports can say more — that is a different thing with the same name, it is described under Google Search Console and Analytics data, and nothing you do with the banner on this page affects it either way. We never mix the two: what our tag records about visitors to keslo.co.uk never reaches a customer’s report, and what we read from a customer’s Google account is never used for our own marketing.
There is one further exception, and it is the checkout page. If you go to buy a plan, that page loads Stripe’s payment form, which means Stripe’s software runs on it and Stripe knows you are there. No other page on this website does that, you cannot arrive at it by accident, and it happens whatever you chose about analytics — a payment cannot be taken without a payment processor. What that involves is set out below.
Paying for a plan
We use Stripe to take payments. This section applies only if you buy something; if you have not, none of it does.
We never see your card
The payment form on our checkout page is Stripe’s, shown inside our page rather than on their website. Your card number is typed into Stripe’s form and goes straight to Stripe — it does not pass through our servers, is not stored by us, and is not something we could show you or anybody else if we wanted to. What we are told afterwards is that a payment succeeded, which plan it was for, and the last four digits and expiry so your billing page can show you which card is on file.
What Stripe is told
Your email address, what you are buying and what it costs, and the technical details of the payment itself. Stripe also collects information about the device you are using to check the payment is not fraudulent — that is what the two cookies described on the cookie page are for, and they are set only on the checkout page.
Why the form is on our page rather than theirs
So that buying something does not send you off to a different website halfway through. The card fields are still Stripe’s own, sealed off from the rest of the page, which is what keeps the arrangement above true: moving the form did not move where the card number goes.
If something on your connection blocks Stripe — an ad blocker or a company network, which does happen — the page says so and offers to send you to Stripe’s own checkout instead, which does not need it.
Sending data outside the UK
Resend and Anthropic are both based in the United States, so emails we send you pass through there, and so does the short summary of findings described below. Both transfers rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which is the arrangement UK law provides for exactly this. Our servers are in Germany, which the UK recognises as offering equivalent protection, and the evidence behind your reports is stored in the United Kingdom, which leaves the country it started in not at all.
Connecting Google works the other way round, which is why it is not in the list above. We do not send your information to Google — we ask Google for information you already have there. Those requests go to Google in the United States and contain only which property we are asking about and which dates; what comes back is stored with the rest of your evidence, in the United Kingdom, under the same 90-day rule.
Cookies
This website sets no advertising cookies of any kind, and no analytics cookies unless you accept the banner. The rest is what makes the site work: a login cookie if you have an account, a note of whether you asked for the light or dark version, a short list of the reports you have opened so the start page can offer them back, and — on the checkout page only — Stripe’s two fraud checks. None of those needs your consent, because none of them is used to recognise or measure you. The cookie page is the complete list, generated from the same declaration the site itself uses, and it says how long each one lasts and where to find it in your own browser.
Your rights
Under UK data protection law you can ask us to:
- Show you what we hold about you, and give you a copy.
- Correct it if it is wrong.
- Delete it.
- Stop using it for a particular purpose, or restrict what we do with it while a disagreement is sorted out.
- Give you a portable copy in a standard machine-readable format, so you can take it elsewhere.
- Stop sending you marketing, which you can also do from any email we send.
Two of these you can do yourself, immediately. If you have an account, your account settings have a button to download everything we hold about you as a machine-readable file, and another to close the account — no request, no waiting. What closing it does is set out above.
For anything else, email hello@keslo.co.uk and we will respond within one month. These rights are free to use. If you ask us to delete something we are required to keep, we will tell you what and why rather than quietly keeping it.
One limitation: if you scanned a site without giving us an email address, we have no way to connect that scan to you, so we cannot find it on request. You will need to tell us the address you scanned and roughly when.
How we protect it
- Everything travels over an encrypted connection.
- Passwords are hashed and never stored in a readable form.
- Access to the servers is limited to named people using cryptographic keys, not passwords.
- Data that is no longer needed is deleted automatically rather than accumulating.
If we ever suffer a breach that puts you at risk, we will tell the ICO within 72 hours and tell you without undue delay.
Automated scoring
Keslo produces a score for a website automatically. This is a judgement about a website, not about a person, and it has no legal effect on anybody and does not decide anything about you. Every finding shows the evidence behind it, and you are welcome to disagree with us — tell us and we will look at the rule.
The “where to start” plan
A paid report can carry a short plan at the top of the findings list, saying which of the problems are really the same problem and what order to tackle them in. That paragraph is written by Anthropic’s Claude, which means a small amount of information about the scan leaves our servers. Everything else in a report — every finding, the score, and every written fix — is produced by our own software and is sent nowhere.
What is sent: the address of the website scanned, and for each problem found, its name, how serious it is, the sentence explaining why it matters, and how many places on the site it affects.
One thing worth spelling out, because “the sentence explaining why it matters” does not sound like it contains much. If you have connected Google, that sentence can carry totals derived from Search Console and Analytics — for example that nine pages are shown in search and rarely clicked, or that pages which produced a certain number of recorded conversions have fallen in Google’s results. Those totals go with it. What still never goes: which pages, which searches, which events, and any figure for an individual page.
What is not sent, deliberately: the list of affected page addresses. It is the most identifying part of a scan and it is not needed to answer the question being asked, so it never leaves our servers — the model is told that four hundred pages are affected, never which four hundred. Nothing about you as a person is sent: no name, no email address, no account details. If you are not logged in, or your report is a free one, nothing is sent at all.
The plan is stored on our servers and reused for any later scan that finds exactly the same problems, so a site that has not changed does not send anything a second time. We use Anthropic’s commercial API, whose commercial terms say the data sent is not used to train their models.
Children
Keslo is a business tool and is not directed at children. We do not knowingly collect information about anyone under 18. If you believe we have, tell us and we will delete it.
Changes to this policy
When we change this page we will change the “last updated” date at the top. If a change matters — a new recipient of your data, a new purpose, a longer retention period — we will say so prominently rather than relying on you noticing a date.
If you want to complain
Please tell us first, so we get the chance to put it right. You also have the right to complain directly to the UK regulator, the Information Commissioner’s Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to come to us first.