Hartevo

Privacy Policy · 隐私政策

1. Scans are ephemeral · 扫描即用即弃

When you scan a URL, we fetch its public pages, compute the report in memory, return it to your browser, and store nothing on our servers. Your scan history lives only in your own browser's localStorage.

2. Monitoring subscriptions · 监控订阅

If you opt into weekly monitoring, we store: your email address, the monitored domain, your language preference, and weekly score snapshots. This data is used solely to send you the weekly report and is deleted when you unsubscribe (one click in every email).

3. Payments · 支付

Payments are processed by Creem (merchant of record). We never see or store your card details. Creem's privacy policy governs the checkout.

4. Analytics · 分析

We use Vercel Web Analytics: aggregate, cookie-free page-view and event counts. No cross-site tracking, no advertising identifiers.

5. Your rights · 你的权利

Email admin@hartevo.com to access or delete any data we hold about you; we act within 7 days.

6. Google user data · Google 账号数据(Search Console)

If you connect Google Search Console inside the Hartevo app (app.hartevo.com), we request a single read-only scope (https://www.googleapis.com/auth/webmasters.readonly). We use it only to read your own verified property list and your site's Search Analytics — impressions, clicks, click-through rate, average position, and top queries and pages — and to display those numbers back to you as a performance card inside the app. Because the scope is read-only, Hartevo cannot change, add, or delete anything in your Search Console.

Your Google OAuth refresh token is encrypted at rest (AES-256-GCM) and used only on our server to mint short-lived access tokens on demand; it is never exposed to your browser or to the assistant. You can disconnect at any time in the app (which deletes the stored token) or revoke access at myaccount.google.com/permissions. Questions about Google data: privacy@hartevo.com.

Hartevo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, do not use it for advertising, and do not use it to develop, improve, or train generalized or non-personalized AI/ML models. Human access is limited to what you explicitly request, security, or legal compliance.