Legal

Privacy Policy

Last updated: 4 July 2026

The short version: we collect what we need to run your audits, take payment, and improve the site. We do not sell your data. Anonymous audits are deleted within hours.

01

Who we are

AuditBrief (auditpdf.com) is operated by Two Cores Operations Ltd, a company registered in England and Wales ("we", "us", "our"). We are the data controller for the personal data described in this policy.

This policy explains what we collect when you use AuditBrief, why we collect it, how long we keep it, and the rights you have under UK data protection law (UK GDPR and the Data Protection Act 2018).

02

What we collect

We collect the following, depending on how you use the service:

  • +Audit data. The website URLs you submit for auditing, the publicly available content and technical signals we fetch from those URLs, and the audit reports we generate from them.
  • +Branding data. Optional details you add to white-label your reports: agency or company name, contact details, accent colour, and any logo files you upload.
  • +Account data. If you create an account: your email address, password (handled by our authentication provider, never visible to us in plain text), company name, and subscription status.
  • +Payment data. Payments are processed by Stripe. We never see or store your full card details. We keep a reference to your Stripe customer and subscription records and the payment status of your reports.
  • +Contact messages. If you use our contact form: your name, email address, and message.
  • +Newsletter signups. If you subscribe to our newsletter: your email address.
  • +Usage data. We use Google Analytics 4 to understand how the site is used (pages visited, device type, approximate location). Our hosting provider also keeps standard server logs, which include IP addresses.

You can preview an audit without creating an account and without giving us any personal details at all.

03

Why we use it

We use this data to:

  • +Run audits and generate your reports (performance of a contract).
  • +Take payment for report downloads and subscriptions (performance of a contract, plus legal obligations around tax and accounting).
  • +Apply your branding to white-label reports (performance of a contract).
  • +Respond to messages you send us (legitimate interests).
  • +Send the newsletter you asked for (consent, and you can unsubscribe at any time).
  • +Understand how the site is used so we can improve it (legitimate interests).
  • +Keep the service secure and prevent abuse (legitimate interests).

We do not sell your personal data, and we do not use it for third-party advertising.

04

AI processing

Audits are generated with the help of AI. When you submit a URL, we fetch that page and extract technical signals (for example the title tag, meta description, link counts, and response time). Those signals and the URL are sent to Anthropic, our AI provider, to produce the written findings in your report.

We do not send your account details, payment details, or contact information to the AI provider. Only the submitted URL and the publicly observable signals from that page are processed.

05

How long we keep it

  • +Anonymous audits. Audits run without an account are stored temporarily and deleted automatically, normally within about 2 hours of creation.
  • +Account data and saved reports. Kept while your account is active. When your account is deleted, your profile, branding, uploaded logos, and saved reports are deleted with it.
  • +Contact messages. Kept for as long as needed to handle your enquiry.
  • +Newsletter emails. Kept until you unsubscribe.
  • +Payment records. Kept for as long as UK tax and accounting law requires.
06

Who we share it with

We use a small number of service providers to run AuditBrief. They process data on our behalf under contract:

  • +Stripe: payment processing and subscription billing.
  • +Supabase: database, authentication, and file storage (including uploaded logos).
  • +Anthropic: AI analysis used to generate audit findings.
  • +Google Analytics: usage analytics.
  • +Netlify: website hosting and newsletter signup handling.
  • +Resend: delivery of contact form messages to our inbox.

Some of these providers process data outside the UK, including in the United States. Where that happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses.

07

Cookies

We use cookies for two things: keeping you logged in when you have an account (essential), and Google Analytics 4 measurement (analytics). We do not use advertising cookies. You can block or delete cookies in your browser settings; the site will still work, though you will not stay logged in.

08

Your rights

Under UK GDPR you have the right to:

  • +Access the personal data we hold about you.
  • +Correct data that is inaccurate or incomplete.
  • +Have your data deleted, including your account and saved reports.
  • +Restrict or object to certain processing.
  • +Receive a copy of your data in a portable format.
  • +Withdraw consent at any time where processing is based on consent (for example the newsletter).

To exercise any of these rights, contact us via the contact page. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we handle your data.

09

Changes to this policy

We may update this policy from time to time as the service changes. The date at the top of this page shows when it was last revised. If we make material changes, we will flag them on the site.

10

Contact

Questions about this policy or your data? Reach us via the contact page. AuditBrief is operated by Two Cores Operations Ltd, registered in England and Wales.