Privacy Policy
Effective July 2026
What we collect
Free scans: the website you enter, an optional email, and standard request data (IP address for abuse limits). Paid accounts: your email, business details you confirm, billing handled by Stripe (we never see card numbers), the scan history your plan generates, and — if you enable text-message outage alerts — the phone number you provide.
What we send to AI providers
Only public business information — your business name, category, city, and the customer questions we ask. Never your email, account details, or payment information. Providers we use: OpenAI, Google (Gemini), Perplexity, and Anthropic (Claude); each retains API data per its own policy.
Google Analytics data (if you connect it)
Connecting Google Analytics is optional. When you connect, you grant Radar read-only access to your GA4 property. We read aggregate traffic statistics only — session and visitor counts by traffic source — to show you how many visitors AI assistants send to your website. We store an encrypted credential and a cached copy of that aggregate report; we never read, store, or receive information about your individual site visitors. This data is shown only to you, is never sold, never shared with third parties, never used for advertising, and never used to train AI or machine-learning models. You can disconnect anytime in Settings (which deletes the stored credential) or from your Google Account security settings. Radar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Business Profile checks
As part of website health checks, we look up your business's public Google Maps listing (rating, review count, photos, hours) through Google's Places API. This is the same public information any customer sees on Google Maps; we store the summary with your scan history.
Uptime monitoring
For tracked businesses we periodically request your public website (the same way a visitor's browser does) to confirm it is online, and store the result (up/down, response time). If your site goes down we notify you by email, and by text message if you added a phone number. Text alerts are sent through Twilio; reply rates from your carrier may apply. Remove your number in Website health to stop texts.
Public reports
Free report links use unguessable tokens, are marked noindex, and expire after 90 days. They show observed AI answers about a business — public information — and never your email or account data. Business owners can request correction or removal at support@routeless.io.
Processors we use
Railway (application hosting, US), Vercel (web hosting), Stripe (billing), Resend (email), Twilio (text alerts), Sentry (error monitoring), OpenAI, Google, Perplexity, and Anthropic (AI observations), DataForSEO (Google search-surface collection), Google (PageSpeed, Places, and Analytics APIs), Cloudflare (bot protection). Each processes only what its function requires.
Bot protection (Cloudflare Turnstile)
Public forms (free scans, agency inquiries) are protected by Cloudflare Turnstile, which runs invisibly — no puzzle appears. Turnstile evaluates technical signals (such as IP address and browser characteristics) solely to distinguish people from bots; it does not identify or profile you. Its processing is described in Cloudflare's Turnstile Privacy Addendum.
Retention and deletion
Free reports: 90 days. Local plan history: 12 months. Growth: 24 months. Uptime check detail: 30 days (incident history follows your plan history). Cancelled accounts keep export access for 30 days, then deletion is queued. Deleting your account also deletes stored Google Analytics credentials and cached reports. You can export everything or delete your account from Settings at any time.
Your rights
Access, export, correction, and deletion are self-serve in Settings or by emailing support@routeless.io. We answer within one business day and never sell personal data.