Privacy
Privacy Policy
What we collect, what we do with it, and what you can tell us to do about it — written to be read, not to be survived.
Last updated
The short version
We collect what we need to run the product: your email, your workspace, your billing record, and the content of the pages you ask us to audit.
Our script tag sets no cookies, creates no visitor identifier, and sends us nothing about your human visitors. The only thing it records about traffic is a daily count of AI crawler visits.
On our own marketing pages we count visits ourselves, with no cookies, no third-party tracker and an identifier that is discarded and regenerated every day — so we cannot recognise you tomorrow, and there is no banner to click.
We do not sell your data, we do not run ad trackers, and we send nothing you give us to any AI or language model provider.
You can delete any site yourself at any time, and ask us to delete your account and everything in it.
This summary is for orientation only. The numbered sections below are the agreement.
1.Who we are
ReadyLayer is a service that shows you how AI agents read your website, diagnoses what stops them, and publishes a machine-readable “Agent Layer” alongside your site. We are based in Omaha, Nebraska.
This policy explains what personal information we handle, why, and what you can tell us to do with it. If anything here is unclear, or you want a straight answer about a specific piece of data, write to privacy@readylayer.io and a person will answer you.
2.What this policy covers, and the two hats we wear
This policy covers readylayer.io, the ReadyLayer dashboard, our public scanner, and the ReadyLayer script tag (ar.js) that you may install on your own site.
We handle data in two distinct roles, and the difference decides who answers to whom:
- As a controller — for your ReadyLayer account. Your email, your workspace, your billing record. We decide what to collect and why, and this policy governs it.
- As a processor — for the content we collect from the websites you ask us to audit, and for anything the script tag sends us from your visitors. That is your data about your site and your audience. We act on your instructions, and our Data Processing Addendum governs it.
Why this matters to you
If you are evaluating ReadyLayer on behalf of a company, the DPA is the document your legal or security reviewer wants. It is public, it applies automatically, and you do not need to ask us to sign anything to get its protections.
3.Information we collect
Account and sign-in information
You sign in with a magic link sent to your email address, or with Google or GitHub. We store your email address and a display name (initially derived from your email address — you can change it). If you use Google or GitHub, our authentication provider also records the identity details that provider returns, such as your name and profile image URL. We never receive or store your password for those services.
Workspace and team information
Your workspace name, the members in it and their roles, and any invitations you send — which store the invited person’s email address and a single-use acceptance token until the invitation is accepted or expires.
Billing information
Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers. We store the resulting Stripe customer and subscription identifiers, your plan, your billing interval, and the add-on quantities you have purchased.
Websites and page content you ask us to analyse
When you add a site and run an audit, we fetch its publicly accessible pages and store what we extract, so we can score them and generate your Agent Layer. For each page that can include the URL, title and description, headings, links, meta and Open Graph tags, structured data, the visible text, a Markdown conversion, an accessibility tree, and the fully rendered HTML of the page.
If a page on your site contains personal information — a team bio, a testimonial, a name in a case study — that information is inside the content we store. It is public on your site, but it is still personal data, and it is covered by the DPA.
One-off scans run from the public homepage scanner are the exception: those do not store the rendered page HTML at all, only the analysis result, and that result expires from our cache.
Technical and security information
- IP addresses, used to rate-limit our public endpoints and to prevent abuse. For that purpose they are held only as short-lived counters in our cache, expiring within an hour, and are never attached to your account. Your IP address is also one input to the visitor identifier described under website analytics below, where it is hashed with a rotating salt and never stored in its original form.
- Anti-abuse challenges. If you trigger our rate limits on the public scanner we show a Cloudflare Turnstile challenge, which sends your IP address and a challenge token to Cloudflare for verification.
- Error diagnostics. When something breaks we record the technical context needed to fix it — stack traces, the request that failed, and the account it belonged to.
Agent traffic on your site
If you install the script tag, we record a daily count of visits from known AI and search crawlers, by crawler name, for each of your sites. This is a count — see the section on the script tag for exactly what is and is not sent.
Visits to our own website
We count visits to our marketing pages and sign-up flow so we can see which pages people read and where they get stuck. We built this ourselves rather than installing a third-party analytics product, because that is the only way to do it without sharing our visitors with someone else.
- No cookies, and nothing stored on your device. There is no tracking cookie, no local storage, and no fingerprinting script.
- A daily, rotating identifier. To tell one visit from another we compute a one-way hash of your IP address and browser user-agent, salted with a secret that changes every day. The result cannot be reversed to your IP address, and because the salt rotates at midnight UTC, the same browser produces a completely different value tomorrow. We therefore cannot recognise a returning visitor, and cannot build a profile across days — by construction, not by policy.
- What is recorded. The page visited, the referring website’s domain (never the full URL), a
utm_sourceif the link carried one, the country Cloudflare reports for the request, and whether the device is a desktop, phone or tablet. Nothing else. - How long. Individual records and the rotating identifier are deleted after 90 days. What remains after that is aggregate counts with nothing linking them to a person.
Our lawful basis is legitimate interests — understanding how our own website performs. Because nothing is stored on or read from your device, this does not require consent under the ePrivacy rules, and we do not show a cookie banner because we have no cookies to ask about.
What we do not collect
- We do not use advertising cookies, third-party analytics trackers, or any cross-site tracking on our website or in our dashboard. The visit counting described above is our own, stays on our own infrastructure, sets nothing on your device, and cannot follow you to another site or from one day to the next.
- We do not build profiles of your website’s human visitors, and the script tag assigns them no identifier of any kind.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not send your data, or your customers’ content, to any AI or large language model provider. ReadyLayer’s analysis and generation are deterministic code running on our own infrastructure. There is no AI provider in our stack, and nothing you give us is used to train a model — ours or anyone else’s.
4.How we use information
- To run the product — authenticate you, audit your sites, calculate Agent Readiness Scores, generate and host your Agent Layer, monitor for changes, and send you alerts.
- To bill you — manage subscriptions, add-ons, invoices and renewals through Stripe.
- To support you — answer your questions and investigate problems you report.
- To keep the service safe — rate limiting, abuse prevention, blocking attempts to point our crawler at private networks, and investigating security incidents.
- To improve the product — understand which features are used and where the product fails, using aggregate and diagnostic information rather than the content of your pages.
- To meet legal obligations — tax and accounting records, and responding to lawful requests.
We do not use the content of your pages for anything except delivering the service to you.
5.Our lawful bases (UK/EU GDPR)
If you are in the UK or the European Economic Area, we rely on the following bases under Article 6:
- Performance of a contract — providing the service you signed up for, and billing you for it.
- Legitimate interests — securing our service, preventing abuse, diagnosing errors, measuring how our own website performs, and improving the product. We have considered these against your rights and kept the data involved minimal and short-lived.
- Legal obligation — retaining financial records and responding to valid legal process.
- Consent — where we ask for it. You can withdraw consent at any time without affecting anything we did beforehand.
For personal data inside the website content you ask us to analyse, you are the controller and you determine the lawful basis. We process it on your instructions.
6.The ReadyLayer script tag and your visitors
If you install our script tag, it runs in your visitors’ browsers on your site. That makes it the part of ReadyLayer most likely to concern you and your own privacy obligations, so here is precisely what it does.
What it sends us
- A heartbeat, on page load and roughly once an hour after. The entire payload is your site key. It contains no information about the visitor, the page, or the session. It exists so your dashboard can show whether the tag is still installed.
- A configuration request, to fetch the Agent Layer files to advertise on that page. This is an ordinary request for a public file identified by your site key.
- A crawler beacon — but only when the visitor is a known AI or search crawler. The script inspects the browser’s user-agent string locally and sends a beacon only if it matches a short list of known agents such as Googlebot, GPTBot, ClaudeBot or PerplexityBot. For an ordinary human visitor, no beacon is ever sent.
What we keep
From the beacon we keep one thing: a per-day counter of how many times each named crawler visited each of your sites. The page URL sent with the beacon is discarded and never stored. The user-agent string is used in memory only, to decide which crawler name to increment, and then discarded. We do not store IP addresses, page URLs, or raw user-agent strings from your visitors.
What it does not do
- It sets no cookies on your site.
- It writes nothing to local storage or session storage.
- It assigns no visitor identifier, so it cannot recognise a returning visitor, and it cannot follow anyone between pages or across sites.
- It does not read form fields, page content, or user input.
- It does not fingerprint the browser or the device.
What this means for your cookie banner
Because the script tag stores nothing on the visitor’s device and creates no identifier, it is not the kind of technology that normally requires consent under the ePrivacy Directive or the UK PECR. We are telling you what it does, not giving you legal advice — your own obligations depend on your site and your jurisdiction, so confirm it with your adviser.
As with any request over the internet, our servers necessarily see the network-level details of the requests the script makes — the originating IP address and the user-agent header — in order to respond at all. Those are used for rate limiting and dropped as described in the technical information section. Your site key is a public identifier by design: it appears in your page source, and it grants no access to your account or your data.
7.How our crawler behaves
When you run an audit we fetch pages with a headless browser. Our crawler identifies itself honestly, in every request, as:
Mozilla/5.0 (compatible; ReadyLayerBot/1.0; +https://readylayer.io/bot)
Anyone who finds that in their logs can look us up at readylayer.io/bot, which documents this crawler and how to block it.
- It obeys robots.txt. We read your robots.txt before crawling and honour disallow rules — both the rules addressed to all agents and any addressed to ReadyLayer specifically. Disallowed URLs are dropped from the queue and are not fetched, and links discovered mid-crawl are checked against the same rules.
- It is anonymous. Every fetch is made without cookies, without credentials, and without any session. It sees exactly what an unauthenticated visitor sees, so it cannot reach anything behind a login.
- It is deliberately slow. Pages are analysed one at a time, never in parallel, so an audit does not act as load on your server.
- It is bounded. Each audit stops at a page limit set by your plan.
- It cannot be pointed at a private network. We block requests that resolve to private, loopback, link-local or cloud-metadata addresses, and we re-check every redirect hop. This protects both you and us.
You may only submit sites you own or are authorised to act for. That is a condition of using ReadyLayer, and it is set out in the Terms of Service.
10.Service providers we use
These are the third parties that process data on our behalf, and what reaches each of them. We keep this list current: if we add a provider, it appears here, and customers covered by our DPA get notice and an opportunity to object before it starts processing their data.
| Provider | What we use it for | What it receives |
|---|---|---|
| Supabase | Authentication and our primary application database | Account email, display name, sign-in identity, and all data stored by the product, including the page content we collect when auditing your sites |
| Stripe | Subscription billing and payment processing | Your name, email, billing address and payment method, collected directly by Stripe at checkout. We store only the resulting customer and subscription identifiers — never card numbers |
| Amazon Web Services (S3) | Storage of the Agent Layer files we generate for you | Content derived from the pages we audit on your sites |
| Cloudflare | DNS, TLS, content delivery, Turnstile anti-abuse challenges, and access control for our internal admin tools | Network metadata for requests to our services, including IP address and browser user agent. Turnstile additionally receives an IP address and challenge token when a challenge is shown |
| Resend | Transactional and product email, and our marketing contact list | The recipient's email address and the contents of the message, such as a team invitation. We also keep a standing contact record for each account holder — email address, display name, and your account's plan and status — so that product announcements reach the right people; it is removed when your account is deleted, and you can unsubscribe at any time from the link in any such message |
| Sentry | Error monitoring and performance diagnostics | Technical diagnostics when something breaks: stack traces, request context and the account associated with the error |
| Hetzner | Hosting for our application and background job servers | Data processed by the product while it runs on our servers |
Notably absent, and intended to stay absent: any AI or large language model provider. Nothing you give us is sent to one.
11.Where your information is processed
ReadyLayer is operated from the United States. Our service providers run infrastructure in the United States and in Europe, so your information may be processed in either.
Where we transfer personal data out of the UK or the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the additional measures described in our Data Processing Addendum.
12.How long we keep things
We would rather tell you what actually happens than write that we keep data “only as long as necessary”.
- Account and workspace data — for as long as your account is open. When you delete your account we keep it for 30 more days, so you can undo it, and then remove it permanently — subject to the exceptions below.
- Audit history, page content and generated Agent Layer files — until you delete the site they belong to, or close your account. These do not currently expire on their own. If you want a site’s stored content gone, deleting the site in your dashboard removes it, including the stored page HTML.
- Rate-limiting counters — under an hour. These expire automatically.
- Public scanner results — cached briefly so a shared result link keeps working, then discarded.
- Billing and tax records — retained for as long as tax and accounting law requires, typically seven years, even after you close your account.
- Security and administrative logs — we keep a record of administrative actions taken on accounts as a security control. This record survives account deletion by design; a log that a deletion can erase is not a log.
13.How we protect information
- All traffic to our services is encrypted in transit with TLS.
- Every table in our database enforces row-level security, so a query cannot reach another workspace’s rows even if application code is wrong.
- Internal administrative tools sit behind a separate access layer requiring single sign-on and multi-factor authentication, and access is granted only from the command line — never from the admin interface itself.
- Every administrative action on a customer account writes an audit record in the same transaction as the change.
- Secrets and credentials are stripped from error reports before they leave our systems.
- Our crawler is constrained so it cannot be used to reach private networks or cloud metadata endpoints.
No service is perfectly secure, and we will not pretend otherwise. If you believe you have found a vulnerability, please tell us at security@readylayer.io. We will not pursue legal action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
Your site key
The key in your script tag is a public identifier, not a secret. It is embedded in your page source by design. It cannot be used to read your data, change your account, or see your audits.
14.Your rights over your information
Wherever you live, you can ask us to do all of the following, and we will not charge you or treat you differently for asking:
- See it — get a copy of the personal information we hold about you.
- Correct it — fix anything inaccurate. Your email and display name are editable directly in your profile settings.
- Delete it — close your account and have your personal information removed, subject to the records we are legally required to keep.
- Export it — receive it in a portable, machine-readable format.
- Object or restrict — object to processing we base on legitimate interests, or ask us to pause processing while a dispute is resolved.
- Withdraw consent — at any time, where we relied on it.
How to exercise them
Email privacy@readylayer.io from the address on your account. We will confirm receipt and respond within 30 days. If a request is complex and we need longer, we will tell you why before that deadline passes.
Three things you can do yourself, immediately, without asking us: edit your profile in Settings, delete any site from your dashboard — which permanently removes that site’s stored page content, audit history and generated files — and download a full export of your workspace as JSON.
You can also close your account yourself. The owner of a workspace can delete it from Settings → Billing. That cancels any subscription straight away and permanently deletes the workspace and everything in it after 30 days, during which you can still change your mind with one click. We keep only what we are legally required to, listed under “How long we keep things” above.
If the personal information concerns a visitor to a customer’s website, or appears inside content on a customer’s site, that customer is the controller. Send your request to them and we will support them in answering it. If you contact us instead and we can identify the customer, we will pass your request on and tell you we have done so.
If you are in the UK or the EEA and you think we have got this wrong, you have the right to complain to your local supervisory authority. We would appreciate the chance to fix it first.
15.California and other US state privacy rights
If you live in California, Colorado, Connecticut, Virginia or another state with comprehensive privacy legislation, you have the rights described above — to know, access, correct, delete, and obtain a portable copy — and the right not to be discriminated against for exercising them. Use the same address: privacy@readylayer.io.
Some specifics, stated plainly because they are the ones people ask about:
- We have not sold personal information, and we do not share it for cross-context behavioural advertising. There is no opt-out link on this site because there is nothing to opt out of.
- We do not collect sensitive personal information as that term is defined under California law, so there is nothing for you to limit the use of.
- We do not use automated decision-making that produces legal or similarly significant effects about you.
- You may use an authorised agent to make a request. We will ask for proof that you authorised them.
Where we handle personal information on behalf of a customer, we act as that customer’s service provider, and we are contractually prohibited from retaining, using or disclosing it for any purpose other than performing the service.
16.Children
ReadyLayer is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to privacy@readylayer.io and we will delete it.
17.Changes to this policy
We will update this policy as the product changes. The date at the top always reflects the most recent revision.
If a change materially affects how we handle your personal information — a new category of data, a new purpose, a new service provider — we will tell you by email or in the product at least 30 days before it takes effect, so you have time to object or close your account.
18.Contact us
Privacy questions, requests, and complaints all go to the same place, and a person reads it:
ReadyLayer is based in Omaha, Nebraska. Our postal address is available on request for formal notices, and for anything contractual rather than privacy-related use legal@readylayer.io.