Controller and contact
The service is operated by Alexander Pichugin / Pichugin Studio. Privacy questions and deletion requests can be sent to alexander@answerworthy.md.
Data collected
- The submitted website URL and normalized public URL.
- The report email address.
- Optional founder context: product name, audience, buyer pain and geography.
- Public website evidence collected during the audit, including response metadata, selected text excerpts, links, structured-data types and measurements.
- Payment identifiers and status supplied by Stripe. Answerworthy does not store payment card numbers.
- The generated private report, operational error messages and timestamps.
Purpose and basis
The data is used to perform the purchased audit, provide the report, send the completion notice, prevent misuse, resolve failures and meet accounting or legal obligations. Commercial launch should map the applicable legal bases and required notices for each operating market.
Processors and data transfers
The implementation can use Vercel for hosting, a configured Postgres provider for storage, Stripe for payment, Google PageSpeed Insights for measurements, OpenAI for bounded content interpretation and Resend for optional delivery email. Only the data needed for each operation should be sent. Review and document the selected providers, regions, data-processing agreements and transfer mechanisms before launch.
Retention
Audit records and private reports are scheduled for deletion 90 days after creation. Database backups may persist according to the configured provider’s retention policy. Accounting records may require a separate lawful retention period.
Requested Read notifications
If you ask to receive your Read by email, we save your email address, the Read you requested and the time of your request. When your result is ready, we send its private link through Tiamat and Amazon SES. This request is for result delivery; marketing subscriptions require a separate choice. The address and delivery record are retained with your Read for 90 days. Anyone you share the private result link with can view that result. Download access uses the separate confirmation described below.
Requested download emails
When you request answerworthy.md, we record your email address, the Read you requested, the request time and the notice version shown to you. We send a confirmation through Tiamat and Amazon SES. Pressing Confirm access records the confirmation time and grants access to that Read on your browser. This request covers your download confirmation. Marketing subscriptions require their own choice.
Confirmation links expire after 15 minutes. The essential access cookie lasts up to 30 days, while the Read remains retained. Request and access records are removed when their Read is deleted.
Optional usage analytics
When you allow analytics, PostHog receives visits, upgrade clicks and completed download steps with a random browser identifier and a hashed Read identifier. Your email, report content, access links and confirmation secrets stay within the access system. We use the EU PostHog service when configured. The consent choice and random identifier last up to 180 days on your browser.
You can turn analytics off using Analytics preferences in the public-site footer or the control on your Read or download page. Browser Do Not Track and Global Privacy Control signals also turn it off. You can request your file with analytics off. Previously collected analytics may remain in the configured PostHog project; contact us for access or deletion requests.
Public-site crawling
The scanner requests public pages only and rejects local, private and reserved network destinations. Do not submit a URL containing secrets, preview tokens, credentials or non-public information.
Your choices
You may request access, correction or deletion of a report record by contacting alexander@answerworthy.md. Some requests may be limited by legal retention requirements or the need to prevent abuse.
Security
Private reports use high-entropy access tokens and are marked noindex. Transport and browser security headers are configured in the application. No internet service can promise absolute security; report links should be treated as confidential.