Trust & privacy

Here’s what SiteModeAI collects — and what it deliberately leaves alone.

No vague “we value your privacy” paragraph and then 14 mystery trackers. This page explains the product in plain English. The full legal wording is in the Privacy Policy.

When someone visits a connected website

✓

What may be recorded

  • Page path that was opened
  • Referring website hostname, when available
  • Coarsened screen width
  • Browser language
  • Website’s SiteModeAI site ID
  • Time of the event
  • A limited action category such as WhatsApp click, phone tap, form submission, Get Quote click or a button the account holder asked SiteModeAI to recognize
  • Supported real-visitor performance measurements such as content paint, interaction responsiveness and layout stability
✕

What the visitor-measurement system is designed not to store

  • Analytics cookies
  • Local-storage visitor IDs
  • Browser fingerprints
  • Visitor IP addresses in website activity tables
  • Full user-agent strings in website activity tables
  • What someone typed into a form

What the website connection code actually does

When a page loads, the connection code sends the small set of website-activity fields described above to SiteModeAI. It can also recognize a limited set of common business actions, such as clicking WhatsApp, tapping a phone number, submitting a form, or pressing buttons with familiar labels such as “Get Quote” or “Book”. Account holders can also teach SiteModeAI the visible words on another important button.

In supported browsers it can send limited website-performance measurements so the owner can understand whether pages feel fast and stable. It does not read the contents of form fields. It records that a form was submitted, not what the visitor wrote.

Account and application security

✓

Passwords: stored as salted password hashes, not plain-text passwords.

✓

Sessions: a random server-managed session token is stored in an HttpOnly cookie. The database stores a hash of the token so sessions can be revoked, including after password changes and resets.

✓

Website ownership: authenticated requests are checked against the account that owns the website entry.

✓

Basic abuse protection: sensitive endpoints use rate limits and the application sends common browser security headers.

✓

Connection security: production sessions use secure cookies and the application is served over HTTPS by the hosting platform.

Our hosting providers still see normal internet traffic

SiteModeAI uses cloud infrastructure to run the application and database. Like ordinary web hosting, infrastructure providers may process technical connection information needed to receive requests, protect systems and operate their networks.

That is different from intentionally storing visitor IP addresses in SiteModeAI website-activity tables. The product is designed not to do that.

Privacy Check is a useful scanner, not a lawyer

Privacy Check automatically inspects up to five important pages it can safely find. It looks for recognized tracking tools, cookies appearing during the check, privacy-policy links, cookie-notice signals, outside services, selected security headers, mixed-content resources, insecure form destinations and cookie flags visible in the returned response.

The scanner does not fully execute every script like a real browser. Websites can also behave differently by location, consent choice, login state or browser. A clean result therefore means “we did not spot an obvious issue in this automated check,” not “this website is legally compliant.”

Website Check is based on the checks we actually make

The preview records website-health checks and can show recent downtime, response speed and secure-connection status. Uptime percentages are calculated from recorded checks, so we label them “Uptime from our checks.”

The free preview does not promise uninterrupted 24/7 checking or instant alerts.

Internal traffic, exports and sharing

Website owners can optionally exclude their current public network from a selected website. SiteModeAI stores a one-way keyed hash for that exclusion rather than the raw IP address.

Owners can download website activity as CSV, export broader account data, and create read-only report links. Shared-report links are revocable and their secret tokens are stored hashed.

Account data and deletion

Account holders provide an email address and may provide a name. Website addresses and collected website activity are associated with the account.

Account holders can permanently delete their SiteModeAI account from the Account section. Deleting an account also removes its websites and associated SiteModeAI website activity and saved checks through database relationships. During the preview, privacy requests can also be sent to metalliccraftsindia@gmail.com.

The legal pages

This page is the human-readable explanation. For the formal service wording, read the Privacy Policy and Terms.