This policy is available in nine languages. The Turkish text controls where required or permitted by applicable law; all other translations are provided for information.
Controller and scope
The data controller for Sitelemetry is EGENİL TELEFERİK MÜHENDİSLİK TEKNİK İŞLETME DANIŞMANLIK LİMİTED ŞİRKETİ, Cumhuriyet Mah. 1227 Sk. No: 11, Altınordu, Ordu, Türkiye.
This policy applies to sitelemetry.com, the Sitelemetry console, the Sitelemetry mobile application, audit services, APIs, support and related integrations. It explains our processing under Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK) and, where applicable, the GDPR and other privacy laws.
Information we collect
We collect information directly from you, from your authorized integrations, from normal use of the service and from publicly reachable technical surfaces of targets you submit.
Remote MCP disclosure. When you connect Codex, Claude or another MCP client, that client provider receives the tool request and returned audit result as part of your conversation under its own terms and privacy policy. Sitelemetry receives only the MCP traffic and tool arguments your client sends, not the rest of your AI conversation. The client receives audience-bound OAuth tokens; it does not receive your Sitelemetry password, account API key or stored Google integration tokens. When you use a performance tool, Sitelemetry sends the verified target URL to Google PageSpeed Insights, and Google independently fetches that URL to produce the performance result. MCP audits may be used only for websites you own or are expressly authorized to assess.
Purposes and legal bases
- Contract: create accounts, run requested audits, generate reports, provide subscriptions, integrations and support.
- Legitimate interests: secure the service, prevent abuse, troubleshoot, measure reliability and improve defensive audit quality without overriding your rights.
- Legal obligation: maintain financial, tax, fraud-prevention and compliance records and respond to lawful requests.
- Consent: operate optional connections or communications where consent is the appropriate legal basis. You may withdraw consent without affecting earlier lawful processing.
We do not use private audit content or Google user data to train general-purpose artificial intelligence models, and we do not sell personal information.
Audit targets and third-party information
Audits may observe public server responses, DNS and certificate data, exposed technologies, page content and similar technical information. You must have authority to submit the target and avoid supplying unnecessary personal data or secrets.
Some modules send the target or limited technical inputs to configured engines or APIs to perform the requested analysis. Reports may contain information about website operators or systems. You are responsible for using and sharing those reports lawfully.
Service providers and disclosures
We share only the information reasonably needed with service providers and other recipients that support hosting and infrastructure, email delivery, payments, authentication, analytics integrations, customer support and authorized audit engines. Examples include AWS for hosting, email infrastructure providers, Paddle for web billing, Apple for App Store purchases, Google for Google Play purchases and integrations you connect.
Depending on their role, recipients process information on our instructions or under their own terms and applicable data-protection obligations. We may also disclose information when required by law, to protect users or the service, in a corporate transaction with appropriate safeguards, or at your direction. We do not disclose audit data to unrelated advertisers.
Google API Services data
Separately, if you choose Sign in with Google, we use only the basic openid email profile identity scopes to receive your stable Google account identifier, verified email address and display name solely to create or sign in to your Sitelemetry account. This login does not request Google API service data, and Google access, refresh and identity tokens are not retained.
When you choose to connect Google Search Console, Sitelemetry requests only the read-only OAuth scope webmasters.readonly. We access verified property URLs and permission levels, plus clicks, impressions, click-through rate, average position and query, page, device, country and date dimensions. We also process the access and refresh tokens needed to maintain the connection.
We use this information only to provide user-initiated, read-only Sitelemetry dashboards, reports and exports. Sitelemetry does not create, edit or delete data in your Google services. Raw, aggregate, anonymized or derived Google user data is not sold; used for advertising, credit or lending, surveillance or unrelated profiling; transferred to data brokers or advertisers; used to train or improve generalized artificial-intelligence or machine-learning models; or sent to third-party AI or ML services for model training. Providers that host or operate Sitelemetry process only the minimum data needed to provide and secure these features.
OAuth tokens are never exposed to client-side JavaScript. They are encrypted and authenticated with AES-256-GCM and kept in an HttpOnly connection cookie that uses Secure and SameSite protections in production and is bound to the signed-in Sitelemetry account. Google report data is processed on demand and is not retained as a separate long-term copy; we may retain non-content usage counts needed to enforce plan limits.
You can disconnect the Google Search Console integration in Sitelemetry at any time, which removes the corresponding tokens from the active Sitelemetry connection and replaces or clears the connection cookie. That cookie expires no later than 30 days after it is set unless it is replaced. You can also revoke Sitelemetry from your Google Account connections. To request deletion of your Sitelemetry account or related data, contact support@sitelemetry.com.
Sitelemetry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Payments and app stores
Paddle acts as Merchant of Record for purchases made on the Sitelemetry website and collects payment, billing and tax information under its own privacy policy. Apple processes purchases made in the iOS app, and Google processes purchases made in the Android app, under their respective terms and privacy policies. Sitelemetry does not receive full payment-card details from any of these providers.
To verify access, prevent fraud and reconcile renewals, cancellations, refunds and expiry, our server receives and retains limited store data such as the provider, environment, product and plan identifiers, subscription status and dates, Apple transaction/original-transaction references and app-account token, or Google order reference, encrypted purchase token and obfuscated account/profile identifiers. We do not use this information for advertising or tracking.
Retention and security
After verified account-deletion confirmation, we lock account access and revoke active sessions immediately. Operational personal data covered by the request is deleted or anonymized within 30 days. Production backups expire naturally within 30 days and are not restored to active product use.
We retain only category-specific, minimally necessary records where a legal obligation still applies: billing and tax records, necessary commercial correspondence, authorized-audit evidence and pseudonymized deletion proof. They are isolated, access-restricted, not used for the product and kept only for the applicable period, up to 10 years under the current policy. We delete or anonymize them when the relevant legal ground or period ends.
We use access controls, password hashing, encrypted transport, secret separation, request validation, audit logging and other technical and organizational safeguards appropriate to the service. No system is completely secure, so please report suspected incidents promptly.
International transfers
Some providers may process data outside Türkiye or your country. Where required, we rely on adequacy decisions, contractual safeguards, explicit consent or another lawful transfer mechanism. The location of a submitted audit target may also determine where public technical requests are received.
Your privacy rights
Subject to applicable law, you may ask whether we process your data and request access, correction, deletion, restriction, portability or objection; withdraw consent; and complain to the competent data-protection authority. KVKK data subjects also have the rights described in Article 11, including learning the purpose and recipients of processing and seeking remedy for unlawful processing.
Send requests to support@sitelemetry.com. We may verify identity and authority before acting. You can also request account and connected-token deletion. We will respond within the period required by applicable law.
Children, updates and contact
Sitelemetry is a business service and is not intended for children under 18. We do not knowingly collect their personal information.
We may update this policy to reflect product, provider or legal changes. We will change the effective date and provide additional notice for material changes where required.