Privacy Policy
Last updated: 10 July 2026
Note: paceghost.io is currently in active development. As our service evolves, this Privacy Policy is subject to frequent changes and updates to reflect new features, infrastructure, and third-party integrations.
Welcome to paceghost.io! This Privacy Policy explains how Branco Digital UG (haftungsbeschränkt) (“Branco Digital,” “we,” “us,” or “our”), the operator of the website paceghost.io (the “Service”), collects, uses, shares, and protects your personal data.
We are committed to protecting your privacy and ensuring that your personal data is handled in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR). By using our Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for the processing of your personal data is:
Branco Digital UG (haftungsbeschränkt)
Hochstraße 94
52525 Heinsberg
Germany
Email: info@paceghost.io
For our full legal details, please refer to our Imprint.
3. What Personal Data We Collect and Why
We collect personal data in the following ways:
A. Data You Provide Directly to Us:
- Account Creation Data: When you create an account on paceghost.io, we collect your email address and a hashed version of your password. Purpose: To create and manage your user account, enable you to log in, and communicate with you about your account. Legal Basis (GDPR): Performance of a contract (Art. 6(1)(b) GDPR).
- URLs for Scanning: When you submit a URL to be scanned and analyzed by our Service. Purpose: To perform the requested website scan and generate an AI compatibility report. Legal Basis (GDPR): Performance of a contract/service (Art. 6(1)(b) GDPR).
- Communications: If you contact us via email or other channels, we will collect any information you choose to provide. Purpose: To respond to your inquiries and provide customer support. Legal Basis (GDPR): Legitimate interest (Art. 6(1)(f) GDPR); Performance of a contract (Art. 6(1)(b) GDPR) if your inquiry relates to your use of the Service.
B. Data Collected Automatically When You Use the Service:
Usage and log data collected when you access or use our Service may include your IP address, browser type and version, operating system, referring URLs, pages visited, features used, time spent on pages, and timestamps. This data is collected through our servers and third-party services including Supabase and SimpleAnalytics.
Purpose: To operate, maintain, and improve our Service; to monitor usage trends; for security purposes. Legal Basis (GDPR): Legitimate interest (Art. 6(1)(f) GDPR); Performance of a contract (Art. 6(1)(b) GDPR).
C. Data Collected from the Websites We Scan:
When a URL is submitted for analysis, our Playwright microservice extracts publicly accessible content from that website, including text, DOM structure, and screenshots. This data forms the basis of the AI compatibility analysis and the reports generated by paceghost.io. While we do not intend to collect personal data from scanned sites, some may be incidentally included if publicly visible.
Legal Basis (GDPR): Legitimate interest (Art. 6(1)(f) GDPR); Performance of a contract/service (Art. 6(1)(b) GDPR).
4. How We Use Your Personal Data
We use the personal data we collect to:
- Provide, operate, maintain, and improve the paceghost.io Service.
- Create and manage your user account and authenticate your access.
- Process URLs submitted for scanning and generate AI compatibility reports.
- Make the reports generated for your account available to you and, where you choose to create one, via a time-limited share link.
- Communicate with you, including service-related notifications and support responses.
- Monitor and analyze usage trends to enhance functionality and user experience.
- Prevent fraud, unauthorized access, and enforce our Terms of Service.
- Comply with applicable legal obligations, court orders, or governmental requests.
5. Cookies and Similar Technologies
Our Service uses cookies and similar technologies that are strictly necessary to operate the website and your account. We do not use cookies to gather analytics — website analytics are cookieless (SimpleAnalytics, see below).
- Strictly Necessary Cookies: Essential for browsing the website and accessing secure areas (e.g., your user account via Supabase authentication). Used based on legitimate interest (Art. 6(1)(f) GDPR) or performance of a contract (Art. 6(1)(b) GDPR).
- Analytics: On our marketing website, we use SimpleAnalytics, a privacy-first analytics service that does not use cookies and does not track individual visitors. Within the app, a cookie consent banner is shown; at present no non-essential cookies are set, so declining it has no effect on functionality. If we introduce cookies or similar technologies that are not strictly necessary in the future, we will obtain your consent (Art. 6(1)(a) GDPR) before setting them and update this notice accordingly.
Most web browsers allow you to control cookies through their settings preferences. You can set your browser to block or alert you about cookies, but some parts of the site may then not work.
6. Data Sharing and Disclosure
We do not sell your personal data. We may share your personal data with:
-
Service Providers: Trusted third-party companies performing services on our behalf including:
- Supabase: Authentication, database management, and Realtime communication.
- Fly.io: Hosting for our Playwright microservice and other backend microservices.
- Stripe: Payment processing and subscription management.
- Cloudflare: Edge hosting and content delivery for our website and app.
- Brevo: Transactional email services for notifications, and — if you subscribe to our newsletter — email marketing/newsletter delivery (subscriber email address and list membership).
- SimpleAnalytics: Privacy-friendly, cookieless website analytics. These providers only access personal data necessary to perform their tasks and are obligated not to disclose or use it for any other purpose.
-
Search and AI Data Providers: To perform website analysis and search visibility benchmarking, we submit data to various third-party APIs. These include LLM providers (OpenAI, Anthropic, Google Gemini) accessed directly and, for most other models, via OpenRouter (an LLM aggregator that routes requests to underlying providers including DeepSeek and Mistral), and search data providers (SerpAPI, Brave Search, You.com, Perplexity; DataForSEO and Serper.dev are retired but may retain historical logs with the provider). We provide these providers only with the publicly accessible website content (text, DOM structure from scanned URLs) or search/chat queries necessary for our analysis. We do not send your paceghost.io account personal data to these providers. We encourage you to review their respective privacy policies for how API-submitted data is handled.
-
Legal Obligations: We may disclose your personal data if required by law or to protect and defend our rights or property.
-
Business Transfers: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change.
7. Data Retention
- User Account Data: Retained as long as your account is active. When you request deletion, your account remains reversible for 30 days (it is deactivated after 15 days); after 30 days the deletion is irreversible, and all personal account data is fully deleted within 90 days, unless we are legally required to retain it longer.
- Website Scan Data: URLs, extracted content, and generated reports are retained for up to 24 months from the date of collection, after which they are automatically deleted. This data is also deleted when your account is deleted, subject to the account-deletion timeline above.
- Usage/Log Data: Retained for a period necessary for security and analysis (typically 12–24 months, or as determined by our analytics providers).
- Signup Rate-Limit Data (ephemeral): To prevent automated signup abuse, we record a one-way hash of your IP address at the moment of account creation in a separate, access-restricted log. This hashed value is never linked to your profile or account and is automatically purged within 72 hours. It is used solely to enforce a per-network signup limit and is not used for analytics or tracking. Legal Basis (GDPR): Legitimate interest (Art. 6(1)(f) GDPR).
8. Data Security
We implement reasonable technical and organizational security measures to protect your personal data, including encryption (e.g., for passwords via Supabase), access controls, and secure hosting environments. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
9. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), primarily the United States, by third-party service providers such as Supabase, Fly.io, Stripe, Cloudflare, Brevo, LLM/search API providers (including OpenRouter), and SimpleAnalytics. We take steps to ensure data is treated securely and in accordance with this Privacy Policy, typically by relying on Standard Contractual Clauses (SCCs) and, where the provider participates, the EU-U.S. Data Privacy Framework (e.g., Cloudflare is DPF-certified). Cloudflare, in particular, is a US-headquartered company that by default processes edge/routing metadata (such as your IP address and request headers) both inside and outside the EEA in the course of delivering our website and app.
10. Your Data Protection Rights (GDPR)
If you are a resident of the EEA, you have the following rights:
- Right of Access: Request copies of your personal data.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure: Request erasure of your personal data, under certain conditions.
- Right to Restrict Processing: Request restriction of processing, under certain conditions.
- Right to Object: Object to processing based on our legitimate interests.
- Right to Data Portability: Request transfer of your data to another organization or directly to you.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at info@paceghost.io. You also have the right to lodge a complaint with a supervisory authority. For users in Germany, the competent authority may be the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).
11. Children’s Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personally identifiable information from children. If you are a parent or guardian and aware that your child has provided us with personal data, please contact us.
12. Report Access and Share Links
Reports generated from your website scans are accessible only through your account; they are not published on our website. You can generate a share link for a report (for example, to share a PDF download); share links are time-limited signed URLs that expire automatically, but anyone in possession of a valid link can access that report while the link remains valid. Do not share a report link if you do not want its contents to be visible to the recipients.
13. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. For material changes, we may also provide notice through email or a prominent notice on our Service.
14. Contact Information
If you have any questions about this Privacy Policy, please contact us:
Email: info@paceghost.io
For our full legal details, please refer to our Imprint.