This Privacy Policy explains how Wavro (“Wavro,” “we,” “our,” or “us”) collects, uses, and shares information when you use the website at wavro.io, the AI Visibility Audit, the AI Bot Access Checker, and any other tools or pages we operate (collectively, the “Service”).
By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information you provide directly
- URLs you submit for audit. When you run an audit or use a mini audit (such as the AI Bot Access Checker), we collect the URL you enter and the publicly accessible content fetched from that URL.
- Contact form submissions. When you contact us, we collect the information you provide: name, email address, website URL, subject line, and message.
- Email address for audit delivery. The audit form asks for your email so we can send you a copy of the report. It is stored with the audit record.
- Lead form submissions. If you request a full-site audit or implementation help through our get-started form, we collect the website URL, your email address, the type of help you are asking for, and an approximate page count.
- Changelog subscriptions. If you subscribe through the footer form, we store your email address so we can send the weekly AI search changelog. Every email includes an unsubscribe route.
- Optional information. Any other information you voluntarily share with us via email or forms.
1.2 Information collected automatically
- Audit results. We store the scores, check outcomes, and recommendations produced for each audit you run, linked to the URL you submitted.
- Cookies and similar technologies. We do not use advertising cookies or ad-tech tracking pixels, and you do not need an account to use the Service. We use Google Analytics and Mixpanel to understand how the Service is used; these providers set cookies or similar identifiers in your browser. You can block or delete these cookies through your browser settings at any time.
2. How We Use Information
We use the information we collect to:
- Operate and provide the Service, including running audits and returning results;
- Respond to inquiries submitted through the contact form;
- Diagnose and prevent abuse, errors, or security incidents;
- Improve the audit framework, accuracy of checks, and user experience;
- Communicate important Service updates when necessary;
- Comply with applicable laws and enforce our Terms of Service.
We do not sell your personal information, and we do not use audit results or contact submissions to train third-party AI models.
3. Third-Party Services
We use a small number of third parties to operate the Service:
- Hosting and infrastructure — the application and its database run on virtual servers operated on our behalf. Standard request logs are generated as part of normal operation.
- Email delivery — a transactional email provider delivers audit reports and contact-form messages. Their own privacy policy governs their handling of that data.
- Our crawler — Wavro fetches the publicly available HTML at the URL you submit in order to run the audit.
- Google Analytics and Mixpanel — product and traffic analytics. These providers set cookies or similar identifiers and receive usage data such as pages viewed, approximate location derived from IP address, device and browser type, and referring site. We do not send them your email address or the contents of contact-form messages.
We also use Google Search Console and Bing Webmaster Tools to see how our own pages perform in search. These report aggregated data about wavro.io itself. They do not track visitors and set no cookies through the Service.
We do not sell personal information, and we do not use advertising networks or ad-tech tracking pixels. If that changes, this Policy will be updated with a new effective date at the top of the page.
4. Data Retention
Different parts of the Service keep data for different periods:
- Full audit reports are stored so the report stays available at its own URL and can be shared. They are kept until you ask us to delete them, and are linked to the submitted URL and the email address used to request the report, not to an account.
- Mini audits (AI Bot Access Checker) are not stored. The check runs at request time and the result is returned to your browser without being written to our database.
- Brand Radar lookups are cached for up to 30 days, keyed by domain, so repeat lookups are fast. The cache holds only publicly available information about the brand. We do not record who searched for it.
- Email addresses given for report delivery or the changelog are kept until you unsubscribe or ask us to remove them.
- Contact and lead form messages are delivered to us as email and retained in our inbox for as long as needed to respond and keep a record of the correspondence.
- Server logs and analytics data are retained on a rolling basis and are not used to build profiles of individual visitors.
You may request earlier deletion at any time using the contact details in Section 10.
5. Your Rights
Depending on your jurisdiction (for example, the EU under GDPR, the United Kingdom under UK GDPR, or California under CCPA), you may have the following rights:
- Access — request a copy of the personal data we hold about you;
- Rectification — ask us to correct inaccurate or incomplete data;
- Deletion (“right to be forgotten”) — request that we delete your data;
- Portability — receive your data in a structured, machine-readable format;
- Restriction or objection — limit or object to certain processing;
- Withdraw consent — where processing is based on consent;
- Lodge a complaint — with a data protection authority in your country.
To exercise any of these rights, contact us using the details in Section 10. We will respond within one month, as required under GDPR and UK GDPR. You do not need an account with us to make a request.
6. Security
We use commercially reasonable safeguards to protect the information we store, including encrypted transport (HTTPS), restricted server access, and least-privilege database credentials. No system is perfectly secure, however, and we cannot guarantee absolute security.
7. International Data Transfers
Wavro and its infrastructure and analytics providers may store and process data in countries outside your home jurisdiction, including the United States. Where data is transferred out of the EEA or the UK, we rely on the safeguards offered by those providers, such as standard contractual clauses.
8. Children's Privacy
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this Policy from time to time. When we make material changes we will update the effective date at the top of this page, currently August 14, 2026, and where appropriate notify you by other reasonable means. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
10. Contact Us
Questions about this Privacy Policy, or requests to exercise your rights, can be emailed directly to [email protected], or sent through our contact form.
