Prowl Agent
Sign in

Privacy

What this product holds, why it holds it, and how to have it removed. Everything below describes what the software actually does; where a claim is unusual, it says how to check it.

Last changed 2026-08-16.

Signing in

Signing in uses Google and asks for three things: openid, your email address and your basic profile. Nothing else. We store your Google account identifier, your email address and your name, so a run has an account to belong to.

You can check this on Google’s own consent screen before you agree to it — it lists exactly what an application asked for.

Analysing a site

You give us a domain and our crawler reads pages of it, as any search engine’s crawler would, respecting robots.txt. Per page we keep:

  • the page's address and the HTTP status it answered with
  • its <title>, meta description, canonical URL and robots meta tag
  • its <h1> headings
  • counts: words, internal links, external links, hreflang tags
  • whether it carries structured data
  • a SHA-256 fingerprint of its visible text — the fingerprint, not the text

We do not store the pages themselves. The text of a page is reduced to a fingerprint, which lets us tell two pages apart without keeping either. The raw responses are never written down.

No model reads your pages. Findings are produced by rules, not by a language model, so nothing about your site is sent to a model provider. If that ever changes, this paragraph changes with it and the report names the model that phrased it.

A site you do not control can be analysed by anybody, because everything the free analysis reads is what a search engine already sees. Nothing private is reachable this way.

Connecting Google Search Console or Analytics

These are separate, optional and asked for one at a time. They are read-only: nothing we ask for can change anything in your Google account. We keep the data we read — queries, pages, positions, sessions and events — so that a later run can say what changed.

The token that lets us read is encrypted before it is stored. You can revoke it at any time from your Google account, and reports already produced stay readable.

Who else sees it

  • Google — because you signed in with it, and because it is the source of Search Console and Analytics data if you connect them.
  • DigitalOcean — the application and its database run there.
  • Anybody holding a report’s link. A report lives at an unguessable address and that address is the whole credential: it is meant to be handed to an agent or a colleague. Anyone with the link can read that one report and nothing else — not your account, not your other sites.

We do not sell anything to anybody, and there is no advertising here to sell it for.

How long it is kept

A free report stops being readable 30 days after it is produced. The record that a run happened, and what it found, is kept beyond that so a later run can tell you what changed — which is the only reason a second analysis is worth anything.

Taking it with you

Download everything we hold about you as one file: your sites, every report with what it found and what it could not reach, and anything you told us back about a finding. The file also lists what is not in it, and why — an omission you cannot see is worse than one you can.

Your Google credentials are not in it. They are not filtered out of the file; they are never read to build it.

Deleting it

Delete your account from inside the product. It tells you first, in counts, what is about to go, then asks you to type the address you signed in with. Nothing behind it can be asked for again.

Or write to [email protected] from that address and we will do it within 30 days.

Deleting removes the rows that hold your Google tokens, which stops us using them. It does not revoke the grant on Google’s side — that one is yours to withdraw, and claiming otherwise would be describing something we cannot do.

Asking anything else

[email protected].