Legal
Privacy Policy
Last updated: September 12, 2026
TrustTraffic (“TrustTraffic,” “we,” “us”) runs trusttraffic.net and the TrustTraffic dashboard, and publishes the @trusttraffic/tracker package that site owners install on their own servers. This policy explains what we collect across all of that, why, and the choices you have. It applies to (a) visitors and account holders on trusttraffic.net itself, and (b) the crawler-traffic data our customers send us from their own websites.
The short version: we don’t track your website’s human visitors. The tracker only reports requests that identify themselves as a known AI crawler (GPTBot, ClaudeBot, PerplexityBot, and similar) via their User-Agent string — it runs server-side, ships no script to browsers, sets no cookies on your visitors, and does no fingerprinting.
1. Information we collect
Waitlist. If you join the pre-launch waitlist, we store the email address you enter and the time you joined, so we can email you when TrustTraffic opens.
Dashboard accounts. Sign-in is passwordless: you enter an email address, we create or look up an account for it, and set a signed session cookie. We store your email, account-creation date, and onboarding status. We don’t collect a password or run email verification at this stage — see Terms for what that means for account security.
Sites you add. For each site you connect, we store the domain and a randomly generated tracker token used to authenticate hits from that site.
AI-crawler hit data. Once you install the tracker on your own site, it sends us one record per detected AI-crawler request: the request path, the crawler’s name/vendor/category, the HTTP status code, the crawler’s User-Agent string and IP address, and a timestamp. This is traffic data about bots hitting your server, not data about your site’s human visitors.
Opt-in human count. If you enable the human-traffic comparison, the tracker sends only an aggregate count of non-bot page views per day — no path, no User-Agent, no IP, no per-visitor record of any kind.
Citation-tracking setup. The search queries and engines you configure are saved against your site so citation checks can run on your chosen schedule.
robots.txt checker. The public “which AI bots does this site allow” tool on our homepage fetches the robots.txt of whatever domain you enter and reports which crawlers it permits. We don’t store the domains you check.
Log & technical data. Like most web services, our servers see the IP address and request metadata of anyone using trusttraffic.net. We use this transiently for abuse prevention (rate limiting) and don’t build visitor profiles from it.
2. Cookies
We use three cookies, all functional — no advertising or cross-site tracking cookies, and no third-party analytics script runs on trusttraffic.net.
| Cookie | Purpose | Lifetime |
|---|---|---|
ttfc_session | Keeps you signed in to the dashboard | 30 days |
ttfc_gate | Pre-launch access gate | 30 days |
ttfc_theme | Remembers your light/dark preference | Persistent, no expiry set by us |
3. How we use information
- Operate the dashboard and show you your own crawler-traffic data
- Authenticate requests from your installed tracker and your dashboard session
- Notify you when the waitlist opens or about material changes to the service
- Prevent abuse of public endpoints (rate limiting, fraud/spam prevention)
- Debug and improve the service
We do not sell personal information, and we do not use your data to serve you or anyone else advertising.
4. Who we share it with
We use a small number of service providers to run TrustTraffic, each acting on our behalf under their own terms:
- Resend — sends the waitlist-signup notification email.
- Supabase — hosted database for account, site, waitlist, and hit data.
- Our hosting/infrastructure provider, to run the application itself.
We don’t share your data with anyone else, except where required to comply with the law, enforce our Terms, or protect the rights, property, or safety of TrustTraffic or others.
5. Data retention
We keep account and site data for as long as your account exists. Deleting a site from the dashboard deletes its stored crawler-hit history and citation configuration immediately. Waitlist entries are kept until launch or until you ask us to remove yours. You can request deletion of your account and associated data at any time — see Section 7.
6. Security
Session and access cookies are signed and HTTP-only, transmitted over HTTPS in production, and verified with a constant-time comparison to resist timing attacks. Public endpoints are rate-limited. No method of transmission or storage is 100% secure, and this is a beta-stage product — see the Terms for what that means about warranties.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to or restrict certain processing. To exercise any of these, email us at nathanadevv@gmail.com — we’ll respond within a reasonable time.
8. Children
TrustTraffic is a website-analytics tool intended for businesses and developers. It is not directed at, and we do not knowingly collect information from, children under 16.
9. International transfers
We and our service providers may process data in countries other than the one you live in. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to this policy
We’ll update the “Last updated” date above when this policy changes, and post the revised version here. Material changes will be flagged more prominently where appropriate.
11. Contact
Questions about this policy or your data: nathanadevv@gmail.com.