Effective August 19, 2026 · Questions or requests? florian@sqrly.ai — a human answers.
1. What we collect, and why
If you run the free snapshot
Your email address and the store URL you asked about. We use the email once to confirm it's really you (double opt-in) and once to send your report link. Your email is stored alongside the request for our own records — it never appears in the report itself, which contains only facts about the store's public website.
If you subscribe to sqrly Pulse
Your email (for the dashboard link, alerts, and digests — you can point alerts at a different address from the dashboard), your store URL, your scan history, and your billing relationship. Payment details go directly to Stripe; we never see or store card numbers.
What's in a report
Reports are about a business's public website: what our scanner read on its public pages, what its product catalog exposes, and what AI assistants said about it when we asked. Public pages sometimes mention people (a founder's name on an about page); that content is already public, and it appears in a report only served at a private link.
Usage signals
We count report opens (a count and a device type like "iPhone" — never your IP or identity), collect anonymous interaction events on dashboards (which panels get opened, so we know what's useful), and store any feedback votes or notes you choose to leave. Dashboard-link recovery is rate-limited by IP address; those rate-limit records expire within a day.
2. Cookies: none for you
sqrly.ai and your reports set no cookies and load no third-party trackers, ad pixels, or analytics scripts. That's why there's no cookie banner. The only cookie in the whole system belongs to our own internal admin login. Reports remember tiny preferences (like "you've seen the tour") in your browser's local storage, which never leaves your device. The free-snapshot form uses Cloudflare Turnstile to keep bots out — it's designed to work without tracking you.
3. Who touches the data
We run on a small set of processors, each getting only what it needs:
- Cloudflare — hosts everything (site, scanner, storage).
- Stripe — billing for sqrly Pulse; they hold your payment details.
- Resend — delivers our emails (confirmation, report links, alerts).
- AI providers (Anthropic, OpenAI, Google, Perplexity) — during a scan we send them your store's name, category, and public website facts to see how their assistants answer. We never send them your email address or billing information.
We don't sell data, rent lists, or share anything with advertisers. There are no advertisers.
4. How long we keep things
- Free snapshot reports: expire automatically after 90 days.
- Subscriber reports and dashboards: kept while your subscription is active, up to a year per report.
- Subscription records: kept while you're subscribed, then as long as billing and tax rules require.
- Recovery rate-limit records: gone within 24 hours.
5. Reports about stores we haven't met
We sometimes generate a snapshot of a store's public AI-readiness and share it privately with that store's owner — that's often how merchants first hear of us. These reports are built entirely from the store's public website and public AI-assistant answers, are never posted publicly, and are sent as a private link. If one is about your store and you'd like it gone, one email to florian@sqrly.ai deletes it.
6. Your rights
Wherever you are — and including under GDPR and CCPA — you can ask us to show you everything we hold about you, correct it, export it, or delete it. Email florian@sqrly.ai; because the founder answers the inbox, this usually happens the same day, not in 30 business days. Deleting a subscription deletes its dashboards, reports, and scan history.
7. Changes
If this policy changes in a way that matters, subscribers get an email before it takes effect, and this page's date updates. We won't quietly get worse.
8. Contact
sqrly · operated by Florian Mandel (the data controller) · San Francisco, CA · florian@sqrly.ai · sqrly.ai/contact