Privacy policy
Last updated: July 27, 2026.
This policy describes, in plain language, how personal data is handled at Tabkeel (tabkeel.com), under Brazil's General Data Protection Law (LGPD, Law 13.709/2018) and, where applicable, the GDPR.
Controller and data protection officer
The controller and data protection officer is Francisco Ferreira. Direct channel for any data matter, including exercising your rights: francisco@tabkeel.com. We answer within 15 days.
What we collect, and why
When you run an exam (no account)
- The URL you pasted and the public content of the examined site, processed to generate the report. Legal basis: performance of the service you requested.
- An anonymous aggregated record of the exam: the domain becomes a keyed hash (HMAC) — we can count repeat runs, but the hash cannot be turned back into the domain without our secret key, which we never store in the database. We keep counts (pages, findings by type and severity) plus segmenters (whether the site has a pricing page, legal page and active checkout, and which stack fingerprints appear). This feeds the statistical corpus described in the methodology. We do not keep page content nor who pasted the URL.
When you create an account
- Your email, to authenticate by link and communicate account matters. Legal basis: performance of contract.
- Exam history for exams you run while logged in: domain and full report, visible only to you (row level security in the database).
When you subscribe
- Payment is processed by Stripe; we never see or store card numbers. We keep the customer identifier and the active plan. Legal basis: performance of contract and tax obligations.
When you connect Google Search Console (optional)
- Read-only access to your Search Console data. We request the minimum scope (webmasters.readonly): we read your queries, clicks, impressions, average position and pages. We can never write, change your site, publish or post anything.
- Google only ever exposes properties you have already verified as owner in your own Search Console — so we only see sites that are already yours.
- Your Google refresh token is stored encrypted and used only to read your data on your behalf. Disconnect anytime in one click and the token is deleted immediately.
Analytics and cookies
We use one privacy-first product analytics tool, PostHog (including session recording), to see how the product is actually used and fix what is confusing — and only after you accept the cookie banner. Nothing is captured until you opt in: analytics and session recording start opted out by default, and you can decline. Session recordings mask email and password fields. We do not run adtech, ad pixels, cross-site trackers or fingerprinting.
What we do not do
- We do not sell or rent personal data, of anyone, to anyone.
- We do not publish reports about third-party sites: the report goes to whoever pasted the URL.
Who processes data on our behalf
- Vercel (hosting of the site and server functions);
- Supabase (database and authentication);
- Stripe (payments);
- PostHog (product analytics and session recording, only after you accept the cookie banner);
- Google (Search Console — only if you connect it: read-only access to your search performance data);
- OpenAI (in the "what AI says about you" feature and in the Search Console action plan / title-meta rewrites: we send the examined site's public profile, or your Search Console query and page data, to obtain the model's answer; no account credentials go with it).
These processors handle data on servers outside Brazil (US/EU), under standard contractual safeguards for international transfer.
Retention
- Exam report without an account: processed and returned; not stored associated with you.
- Anonymous corpus aggregate: kept indefinitely (it identifies nobody).
- Account and history: while the account exists. Request deletion and we erase within 30 days.
- Search Console connection: the encrypted token is kept until you disconnect, then deleted immediately.
- Tax records of payments: for the legally required period.
Your rights
You may request confirmation of processing, access, correction, anonymization, portability, deletion and information about sharing. Channel: francisco@tabkeel.com, subject "data". You may also complain to the Brazilian data protection authority (ANPD).
Security
Passwordless authenticated links (no stored passwords), row level security in the database, service keys restricted to the server and least privilege throughout. Incidents with relevant risk are communicated to those affected and to the authority within legal deadlines.
Changes
If this policy changes materially, the date at the top changes and, if you have an account, we notify you by email. The version in force is always this page.