Privacy Policy

Legal

Last updated: July 26, 2026 · Contributor privacy version: 2026-07-14-contributors-v1

This site is operated by Patrick Stox LLC. This policy explains what the current public website and free tools process, why, which providers help process it, and the choices you have. A Lemon Squeezy checkout for digital products and subscriptions, paid Runs, customer workspaces, and related billing features are planned but disabled; they do not currently collect customer data. This policy will be updated before any of those products or their customer-data collection launches.

Information you give me

Contact form

When you submit the contact form, I collect your name, email address, company or website, message, and submission IP address. I use this information to respond, limit spam and abuse, and keep a reasonable correspondence record. Cloudflare and the email provider used to deliver a response may process it on my behalf. I do not sell or rent contact-form information. To request deletion, use the contact form.

Newsletter

If you subscribe to the newsletter, I collect your email address, signup source, and the IP address of the signup. Subscriptions use double opt-in: you'll get a confirmation email, and nothing is sent until you confirm. When you confirm, your email may be added to Resend, my email service provider, so I can send issues. Every email includes a one-click unsubscribe link. Unsubscribing stops newsletter delivery, marks the address unsubscribed in my records, and, when provider sync is configured, marks the global Resend contact unsubscribed from Broadcasts. My database retains the email, signup metadata, status, and relevant timestamps as a suppression and consent record until you request deletion or the record is no longer reasonably needed for legal, security, or recordkeeping purposes. You can request deletion via the contact form.

Questions and corrections

If you ask a question on an article, I collect your name, your question, the IP address of the submission, and your email address (optional — only if you want a reply). If you report an inaccuracy, I collect your name, email, the passage in question, your message, and the submission IP. Both are used only to respond and to improve the content. I also store the contributor Terms and Privacy versions and hashes accepted with the submission and its UTC assent time.

Emailed reports and one-time rechecks

Identified tools may let you email yourself a report and request one follow-up check about 30 days later. For that feature, I store your email address, the public URL you ask to recheck, a bounded copy of the report, the due time, delivery state, and a random unsubscribe token. The report and target are cleared after the one scheduled recheck is completed or you unsubscribe; the feature does not continue monitoring the URL. Unsubscribing also creates or preserves an email suppression record so the recheck is not sent again.

Feature requests

If you request a feature, I collect the feature name and description, a one-way IP hash used for abuse review, your optional notification email, and the contributor Terms and Privacy versions and hashes accepted with the request plus its UTC assent time. Approved requests may be displayed publicly without the email address.

Expert panel

If you apply to the expert panel, I collect the name, job title, company, email address, short bio, links, and photo you submit, along with the IP address of the application. Applications are reviewed before anything is published. Once you're approved, your name, title, company, and photo are shown publicly alongside the annotations and answers you contribute, and those contributions — including any audio you record — are stored and displayed on the site. Signing in uses a one-time magic link sent to your email, and a session cookie (ps_expert) keeps you logged in.

For each new expert application or contribution, I also store the accepted Terms and Privacy versions, server-owned hashes of their contributor snapshots, a UTC assent timestamp, the contribution context, and limited request metadata for security and audit evidence. For an audio answer, that evidence is stored on the related answer record rather than on the content-addressed audio object. Older records for which this was not captured remain marked as unknown; I do not backfill or infer assent. Owner-sourced quotes and unclaimed profiles likewise do not represent contributor assent. A legacy expert must accept the current policies before contributing again.

You may request access, correction, an export of reasonably identifiable profile and contribution data, unpublishing, or deletion through the contact form. Limited assent, moderation, security, backup, fraud-prevention, or discussion-integrity records may remain where reasonably necessary.

Free-tool inputs and results

Browser-local tools

Many calculators, parsers, simulators, file-import tools, and exports run in your browser. Unless a tool says that it fetches, renders, generates, shares, or submits something through the site, its pasted text, uploaded files, calculations, and browser-local project state are not sent to Patrick Stox LLC. Some working data lasts only until you close or reload the page; identified preferences, notes, snapshots, and projects may remain in local storage on that browser and device until you clear them. Downloaded exports remain under your control.

Traverse browser extension

The separately installed Traverse SEO & AI Search browser extension is local-first and runs audits after you choose an action. Its permissions, local records, user-started network requests, retention, and deletion controls are described in a dedicated Traverse extension privacy notice; that notice currently lives in the owner-only preview area pending a public store listing and is not yet reachable by visitors. This policy applies when Traverse deliberately calls a patrickstox.com endpoint. Source code and locally packaged builds do not mean that Traverse has been published in a browser store.

Optional Google Search Console and GA4 session connections

Identified analysis tools may offer an optional Google connection as a shortcut to manual exports. The Google Identity Services script loads only after you select a connect button. Search Console and GA4 are separate user actions with separate in-memory tokens: the site requests only webmasters.readonly for Search Console or analytics.readonly for GA4 and does not combine them into one upfront grant. The browser lists properties available to the selected Google account and sends the selected report requests directly to Google's Search Console, Analytics Admin, or Analytics Data API. GA4 landing-page sessions, key events, and source-currency revenue are used only as the tool describes.

Each short-lived access token is kept only in page memory: it is not sent to Patrick Stox LLC, written to browser storage, included in telemetry, combined with the other Google token, or exchanged for a server-side refresh token. Ending one session clears that token and its loaded analyzer context without revoking the Google grant or clearing the other source's input. Closing or reloading the page ends both local sessions. Google receives the information ordinarily involved in its sign-in and API requests under Google's Privacy Policy.

This optional session connection is not a saved integration. Nothing entered, loaded, or authorized on these tools transfers automatically to Traverse. A future saved Traverse connection would use a separate account, credential store, retention policy, and explicit authorization.

Bring-your-own API keys

Identified tools may let you use your own OpenAI, Anthropic, or Google API key. The key is kept only in that page's memory and the browser sends the request directly to the provider you select; the key and provider response are not sent through Patrick Stox LLC's server. Closing or reloading the page clears the in-memory key. The selected provider processes the request under its own terms and privacy policy, and any provider usage limits or charges are your responsibility.

URL fetching and third-party lookups

Tools marked as fetching a URL send the URL, domain, IP address, or DNS name you enter to a Cloudflare Worker. The Worker may request the public target and, depending on the tool, public DNS resolvers (Cloudflare by default; Google Public DNS where a tool offers it as an alternate resolver), domain registration-data (RDAP) services including the registry of record, the RDAP.org fallback proxy, and IANA's public RDAP bootstrap directory, Google's CrUX, Knowledge Graph, Web Risk (safe-browsing/malware check of a submitted URL), Cloud Natural Language, and autocomplete-suggestion services, or another source identified on that tool's page. A feature cache can contain the submitted public target, bounded fetched material, and the derived response; its lifetime and cache key depend on the feature, and a cached result may be returned to another request for the same public target. Target sites and lookup providers receive the network information ordinarily sent with a request from Cloudflare infrastructure; they do not receive your uploaded browser-local files unless the tool expressly says so.

Where the article entity card is configured to use Google Cloud Natural Language, this site sends up to about 20,000 characters of extracted article text for entity analysis. Google states that it processes that text in memory, does not store it as customer data, does not use it to train or improve the Natural Language model, and temporarily logs request metadata such as time and request size for service improvement and abuse prevention. If the Google credential is unavailable, the endpoint uses a local fallback instead.

Keyword and query suggestion sources

An identified autocomplete/suggestion tool sends the seed query or keyword you enter to one or more third-party suggestion endpoints depending on the source you select: Google (Search and YouTube suggest), Microsoft Bing, Amazon, and Apple (App Store) autocomplete. These are public, keyless endpoints; each provider processes the submitted query under its own privacy policy and may log the request in the ordinary course of operating its service.

Network and abuse-lookup services

Some tools that investigate hosting, IP addresses, or bot traffic send a resolved IP address as a reverse-DNS query to Team Cymru's public IP-to-ASN lookup service to identify the network operator. No browser-local files or personal profile data are sent — only the IP address being investigated.

Rendering and AI features

When you explicitly use a rendered-page feature, the submitted public URL and returned page material are processed by Cloudflare Browser Rendering. A Render Gap share report can include the tested URL and bounded initial and rendered HTML; if stored successfully, its unguessable share link expires after about seven days. When you use an enabled AI generation, rewriting, probing, or embedding feature, the text or other input shown by that feature is processed by Cloudflare Workers AI. Cloudflare states that it does not use Workers AI customer content to train models or improve its or third-party services without explicit consent. This site can separately store or cache a result in D1, KV, R2, or another named feature store; some AI results are cached under a cryptographic digest to control cost and abuse. Do not submit secrets, personal information, or confidential material to these features.

Run tokens, abuse prevention, and telemetry

Some bounded multi-URL tools use Cloudflare Turnstile and a signed run token. The token expires after about ten minutes; its server-side ledger stores a random run identifier, expiry, allowed budget, and usage count, not the URLs fetched under it. Rate limiting and security systems process request IP addresses and similar request metadata. Ratings and reactions store the score or reaction, time, a browser-derived anti-abuse fingerprint, a one-way keyed hash of the request IP, coarse network/location information, and moderation or suspected-abuse flags. Other community and feedback features may retain similar limited request metadata alongside the information you choose to send. These records are used to publish aggregate feedback, prevent duplicate or manipulated voting, investigate abuse, and moderate the feature.

Tool-use telemetry stores aggregate daily run and error counts by tool. It does not store a submitted URL, tool payload, raw IP address, user agent, or per-user identifier. Operational logs maintained by Cloudflare may separately contain normal request and diagnostic metadata for a limited provider-controlled period.

Share links and owner-preview monitoring

When a tool offers an optional share link, the report payload is stored only after you request or create that result and is subject to the expiration stated by the tool. Anyone who receives the link may be able to view the report, so do not create or distribute a share link for confidential material.

The public Watchtower dashboard shows a live, curated view of the SEO monitoring this site runs on itself: check status, finding summaries, and verification times, served read-only from /api/watchtower/public. It does not expose monitor targets, recipients, evidence payloads, or controls. Watchtower as a customer product — configurable monitors, recipients, and billing — is currently an owner-only preview, not a service offered to visitors. Its test configuration, compact snapshots, change events, and any configured alert address remain in the site's database until the owner deletes them; no public customer-retention promise applies yet.

Analytics

Site search and content-improvement logs

When you use the site's own search, I log a sanitized version of the query (limited to 80 characters, with email addresses and URLs removed), result count, search or follow-up event such as a result click, no-click, reformulation, or helpfulness response, referring search surface, selected result URL and position where relevant, and the search retrieval version or experiment variant. The request IP may be used transiently for rate limiting but is not stored in the search event. These owner-only logs are used to improve navigation, results, and content coverage. Query events are retained for 400 days; search-health events are retained for 90 days.

First-party performance measurement

A sampled portion of article visits sends the page path, timestamp, and Core Web Vitals measurements such as Largest Contentful Paint, Cumulative Layout Shift, and Interaction to Next Paint to this site's own endpoint. This performance record does not include a stored IP address, user agent, account, cookie ID, or other per-user identifier; the request IP is used only for rate limiting. These records are used to diagnose page speed and usability. They do not currently have a fixed deletion schedule and are kept only while reasonably useful for performance analysis, security, legal obligations, or system recovery.

Ahrefs Web Analytics (cookieless)

This site uses Ahrefs Web Analytics, a cookieless analytics service. Ahrefs says the service processes page URLs, referrers, user-agent and device information, country/city location, language, pageviews, link clicks, and form submissions. It receives the IP address that accompanies the request but says it discards the raw address rather than storing it in its database or logs. To estimate daily unique visitors, it combines the IP address and user agent with a salt that is deleted every 24 hours; the resulting data point is limited to one device, website, and day rather than a persistent cross-site identifier. The site loads this script for all activated visits without setting an Ahrefs cookie. Ahrefs processes the data under its privacy policy.

Google Analytics 4 (GA4)

This site uses Google Analytics 4 to understand how visitors find and use the site (pages visited, time on page, referring source, browser type, approximate country/region). GA4 runs in Google Consent Mode: for visitors in the EU, EEA, UK, and Switzerland, and whenever a Global Privacy Control signal applies, analytics storage starts denied and no analytics cookies are set before an eligible consent choice. Google may still receive limited cookieless pings used for aggregate measurement and modeling. For other visitors, analytics storage may be granted after the region and GPC check. Advertising consent signals also start denied and are updated only where the applicable consent-management choice permits it. Data is processed by Google under Google's Privacy Policy. You can also opt out using the Google Analytics Opt-out Browser Add-on.

Google AdSense

Published content pages and public free-tool pages may display advertising supplied by Google AdSense. Other site areas do not intentionally request display ads. On an eligible tool, an additional ad may be requested only after a visible result is produced; tool inputs and result text are not sent to Patrick Stox LLC's advertising account as a separate report or audience list. Google and its advertising partners may receive the page URL, IP address, browser and device information, consent or opt-out signals, and cookie or similar-technology identifiers needed to select, deliver, limit, secure, and measure ads.

For visitors in the EEA, UK, and Switzerland, the site uses Google's certified consent-management platform and IAB Transparency and Consent Framework signals. For visitors covered by supported US state privacy laws, the Google message provides applicable sale, sharing, and targeted-advertising choices. A Global Privacy Control signal is treated as an opt-out where applicable; Google may serve only restricted or non-personalized advertising when the relevant signal or choice requires it. You can revisit available choices using the “Privacy & cookie settings” control shown on pages where AdSense is active.

Microsoft Clarity

This site uses Microsoft Clarity to create pseudonymous session reconstructions and heatmaps from DOM, page, diagnostic, and interaction events such as clicks, scrolling, pointer movement, selections, and window resizing. Clarity masks input-box and dropdown content and other content classified as sensitive under the project's masking settings, but its records can still include page and interaction metadata and pseudonymous user/session identifiers. Microsoft currently documents 30-day retention for playback data and nine-month retention for click/heatmap data and labeled or favorited sessions. Clarity does not load for visitors in the EU, EEA, UK, or Switzerland, for visitors in California, or for any browser sending a Global Privacy Control signal. Data is processed by Microsoft under Microsoft's Privacy Statement; you can also opt out via Microsoft's privacy controls.

Cookies and local storage

When GA4 runs with consent, it sets first-party analytics cookies to distinguish visitors and sessions. Ahrefs Web Analytics sets no cookies. On monetized pages, Google AdSense and participating advertising providers may use cookies, web beacons, IP data, device information, advertising identifiers, consent records, and similar technologies for ad delivery, frequency control, fraud prevention, measurement, and—only when permitted—personalization. The site uses Google's certified consent and US-state privacy messages and provides withdrawal or opt-out controls where applicable. The site also stores preferences and working data—such as theme, font size, reading progress, article notes, and some tool projects—in your browser's local storage. These values stay on your device unless a feature clearly offers a server fetch, submission, or share operation. You can block or delete cookies and clear local storage in your browser settings; doing so may reset preferences or tool projects, reduce ad relevance, or affect analytics accuracy.

Your privacy choices

Global Privacy Control (GPC). If your browser or an extension sends a GPC signal, I treat it as an opt-out: GA4 stays cookieless and Microsoft Clarity does not load.

Do Not Track (DNT). Browsers offer a DNT setting, but there is no common standard for how sites must respond. This site does not respond to DNT separately; I honor the GPC signal described above instead.

Other controls. On pages where advertising is active, use “Privacy & cookie settings” to revisit available Google consent choices. You can also manage cookies in your browser, use the Google Analytics opt-out add-on, opt out of Clarity, unsubscribe from the newsletter via any issue, and request access to or deletion of anything you've submitted via the contact form.

California residents

I do not sell your personal information for money, and I honor the Global Privacy Control signal as your opt-out of any "sharing." Note that third parties such as Google may collect information about your visit through cookies and similar technologies when their tools are active. Because California treats session-replay recording with particular care, Microsoft Clarity is not loaded for visitors I can identify as being in California.

Service providers I use

I rely on providers to run the current site: Cloudflare (hosting, security, database, object/key-value storage, queues where enabled, browser rendering, and Workers AI), Resend (newsletter and configured transactional email), Google (AdSense advertising and consent management, GA4, optional public-data APIs, and optional browser-session Search Console connections used by identified tools), Microsoft (Clarity), Ahrefs (cookieless analytics, the free Domain Rating lookup, and public site-stat inputs where configured), and Better Stack (checks the public site about every three minutes and hosts its public uptime/status information). Identified authority and crawl-data tools may also send the domain, page URL, or target you submit to Moz (Links API website/page authority metrics, where configured), Keywords Everywhere (OpenPageRank domain metrics, where configured), DataForSEO (backlink/authority-rank metrics, where configured), Semrush (Authority Score/backlink metrics, where configured), Majestic (Majestic Million backlink-authority snapshot lookups, and live Trust Flow/Citation Flow metrics where configured), and Common Crawl (public web-crawl index lookups). Public URL tools may also contact the target site and any other lookup source named on the tool page. These parties process data under their own terms and privacy notices.

The Page and Website Authority Checker also lets you optionally submit your own Moz or DataForSEO credentials for a single lookup instead of using this site's shared, configured account. Those credentials are used only to authenticate that one request directly to the provider you chose; they are never written to this site's cache or database, never logged, and never included in the response returned to you. Provide your own credentials only if you are comfortable with a Cloudflare Worker relaying them to that provider on your behalf for that one request.

Troubleshooting payments

The limited $1,000 troubleshooting checkout is currently unavailable because Stripe is not configured. The page asks this site's configuration endpoint whether checkout is enabled before contacting Stripe. Only when checkout is enabled and a Stripe publishable key is returned does the browser load Stripe.js; that request can provide Stripe ordinary network and device metadata such as IP address, user agent, time, and referring page. If enabled, Stripe hosts the card fields and processes card and billing details under Stripe's Privacy Policy; Patrick Stox LLC does not receive the full card number. I would receive and store the email, question, submission IP, payment-intent reference, status, and versioned acceptance of the displayed troubleshooting terms needed to review, fulfill, secure, and administer the request.

Planned paid products

Lemon Squeezy is the planned merchant of record for eligible future digital products and subscriptions, but that checkout, its webhooks, and the related customer products are disabled. Lemon Squeezy does not process customer purchases for those planned products today. The provider list, payment disclosures, retention terms, and privacy choices will be updated before they are enabled.

Unreleased integrations

Shopify, WordPress, CMS, and framework integrations currently described or present in the repository are private, offline, or local MVP work, not public services or connected customer accounts. They do not currently collect or process public customer data. This policy and any integration-specific notice will be updated before one is released or authorized to access customer content.

Where your data is processed

This site is operated from the United States, and the providers above process data in the United States and other countries. If you visit from outside the U.S., your information may be transferred to and processed in the U.S.

Data retention

Newsletter delivery continues until you unsubscribe. After unsubscribe, the database keeps the address, signup metadata, unsubscribed status, and relevant timestamps as a suppression and consent record until deletion is requested or the record is no longer reasonably needed for legal, security, or recordkeeping purposes. Search query events are retained for 400 days and search-health events for 90 days. A scheduled report's stored URL and report content are cleared after its one approximately 30-day recheck or an earlier unsubscribe; a suppression record may remain. Public profiles and contributions are kept while published or needed for moderation and site history. Form submissions, ratings/reactions and other abuse records, first-party performance records, aggregate tool counters, operational records, and owner-preview data currently do not all have one fixed deletion schedule; they are kept only while reasonably useful for their stated purpose, security, legal obligations, or system recovery. Temporary caches and share reports use feature-specific expirations. Microsoft currently documents the Clarity periods described above; Google says Cloud Natural Language stores no submitted customer text but temporarily logs request metadata; and other provider backups and logs expire on provider-controlled schedules.

You may request access, correction, unpublishing, or deletion through the contact form. I will evaluate the request against the information I can reasonably identify and any legal, security, backup, fraud-prevention, or recordkeeping need. Browser-local data must be cleared from your own browser.

Children

This site is not directed at children under 13. I do not knowingly collect personal information from children.

Third-party links

This site links to external websites. I am not responsible for the privacy practices of those sites and encourage you to review their policies.

Changes

This policy may be updated periodically. The "Last updated" date at the top reflects the most recent revision. Continued use of the site after changes constitutes acceptance.

Contact

Questions? Use the contact form.