IndexTripwire Account

Legal

Privacy policy

Effective 16 July 2026. IndexTripwire processes account identity, configured sites and URLs, crawl evidence, incident history, optional checker emails, support correspondence, and product-usage events to provide and improve the service.

Public checker

We store the checked URL, findings, timing, referrer, and a salted, rotatable hash of the requesting IP address for security, abuse prevention, and funnel measurement. We do not intentionally retain the raw IP address.

Accounts and Google data

Authentication is handled by our Logto service. Google Search Console access is read-only. OAuth credentials are encrypted at rest; Search Console metrics and inspection results are used only for the account that connected them.

Sharing and processors

Incident reports are private unless an account member creates a revocable share link. We use infrastructure, authentication, email-delivery, and Google API providers to operate the service. We do not sell personal data.

Retention and deletion

Non-incident crawl history is normally retained for 30 days. Incident evidence is retained until account deletion. Scheduling account deletion locks monitoring immediately; application data is permanently removed after seven days. Disconnecting Search Console removes its stored credentials and derived data immediately. Backup copies expire through the backup-retention cycle described in our operational policy.

Your choices

You may disconnect Google data or schedule account deletion in account settings. For access, correction, deletion, privacy, or processor questions, contact [email protected].