Privacy · Data handling

StrictSEO privacy and data-handling boundaries.

StrictSEO’s current beta does not require an account and does not provide a page-snapshot upload service. This page explains local project storage, the optional read-only Search Console connection, where processing happens, and what still deserves care.

Effective July 17, 2026Applies to the current StrictSEO beta

Short version: the public analyzer processes pasted, uploaded, or extension-delivered page snapshots in your browser. The extension keeps bounded review data in temporary Chrome session storage. StrictSEO Browser runs on your computer and stores saved project evidence locally. If you connect Search Console, the app talks directly to Google with read-only access and keeps the credential in a separate private local file. The current product has no account, advertising, or remote snapshot API. Optional Google Analytics records sanitized public-page views only after consent and never receives analyzer, project, extension, local-browser, contact, or Search Console data.

The StrictSEO website

The public website is delivered through Cloudflare infrastructure. Ordinary delivery may require hosting and security systems to process request information such as an IP address, requested path, browser headers, timing, and security signals. This processing returns the site and protects it from abuse.

StrictSEO uses Google Analytics only after you select Accept analytics. It sends page views with URL query parameters and fragments removed. Enhanced measurement, Google signals, and ad-personalization signals are disabled. Analyzer inputs, uploaded or pasted HTML, reports, extension data, contact fields, local-browser evidence, and Search Console data are never attached to Analytics events. Rejecting Analytics does not block any product feature, and the Analytics choices control lets you change your decision.

The website does not create a StrictSEO account or ask you to sign in. Apart from the optional Analytics choice and cookies created after acceptance, the current application does not intentionally set a first-party product cookie. The contact form described below is the only current public form that transmits user-entered information and is also the route for requesting free private software access.

The contact and build-access form

The contact page loads Cloudflare Turnstile and accepts a name, reply email, category, and message. A free software access request additionally requires an organization or project, website URL, requested product, operating system and browser, intended use, and private-release acknowledgement. On submission, the browser combines those displayed access fields into the bounded support message and sends it with the Turnstile token to the shared portfolio contact Worker. The Worker may send the connecting IP address to Cloudflare as part of token verification, then forwards the escaped message through Resend to the support inbox. The Worker does not write submissions to an application database, but Cloudflare, Resend, and the receiving mailbox process delivery information under their own operational practices.

The contact form is separate from the analyzer and extension. It does not automatically attach page snapshots, reports, builds, browsing history, or local-browser evidence. It does not reveal a private download URL automatically; access decisions and versioned links are handled in a later reply. Do not put passwords, private reports, or confidential client information into a message. You can use the public analyzer and documentation without opening or submitting the contact form.

The browser-based analyzer

When you paste HTML or choose a local HTML file, the analyzer uses browser APIs to parse that content on your device. It does not render or execute scripts from the supplied HTML. Reports, previews, filters, and downloads are produced in your browser. A download occurs only after you choose an export action.

The analyzer cannot fetch an arbitrary website URL by itself. The optional URL field is report context, not a server-side crawler. To inspect a live page, use the Chrome extension or local StrictSEO Browser. This separation prevents the public website from becoming a remote page-content collection service.

The Chrome extension

The extension uses Chrome’s user-initiated active-tab access. It begins reviewing a normal HTTP or HTTPS page after you select StrictSEO, and it can continue during same-site navigation while the review remains active. Crossing to a different site requires another user action. The extension does not request permission to read all browsing history in the background.

The captured snapshot is bounded to the page information required by the analysis engine, including metadata, headings, paragraphs, links, images, structured data, and structural measurements. Credentials, URL fragments, sensitive query values, email or telephone destinations, and non-HTTP payloads are removed or redacted from captured URL inventory. Reports can still contain visible text from the page, so do not use the beta on a confidential page when even temporary local processing is inappropriate.

Review state is kept in Chrome session storage rather than a StrictSEO account. The extension retains at most 50 reviewed page reports for the temporary session. A detailed-report handoff uses a one-time token, expires after two minutes, and removes the undelivered snapshot after successful delivery. The current audited build has no snapshot upload API, remote code path, or arbitrary report destination. The only report targets are the production StrictSEO analyzer and the fixed local development origin.

The local StrictSEO Browser

StrictSEO Browser runs on your computer and binds its dashboard and debugging interfaces to loopback addresses. It launches stock Chrome or Chromium with a temporary profile, uses the shared page-analysis engine, and keeps reviewed-page, accessibility, and Lighthouse evidence in local process memory. The temporary browser profile is deleted when the process exits normally.

An explicit crawler can request same-origin pages, robots.txt files, and XML sitemaps within the limits you choose. Lighthouse may initiate the network requests needed to load the audited page. These requests go from your local environment to the target website; they are not sent through a StrictSEO crawl service. Exported crawl and Lighthouse reports are written only when you use the corresponding download controls.

When you save a crawl, import Search Console evidence, or add an action, the app writes a bounded project record to the operating system’s StrictSEO application-data directory. A project can retain up to 12 compact crawl snapshots, 12 Search Console imports of at most 25,000 usable page/query rows each, 200 fix-plan actions, and notes you enter. Project records include sanitized URLs, derived findings, link/discovery summaries, clicks, impressions, CTR, position, and comparison dates. They exclude raw page HTML, DOM excerpts, cookies, passwords, axe output, and complete Lighthouse reports. Clear local project erases that project record.

The optional Google Search Console connection

StrictSEO requests only Google’s webmasters.readonly scope. Authorization uses a Google Desktop OAuth client, PKCE, a short-lived matching state value, and a loopback callback to the app. The app opens Google’s authorization page in the system browser; StrictSEO.com does not receive the authorization code, token, property list, or Search Console rows.

The refresh credential and selected property are stored separately from project reports in a local application file restricted to the current operating-system user. The token is never placed in dashboard event messages, page snapshots, crawl records, or report exports. A private build may also retain the Google Desktop client ID and client secret from a JSON file you deliberately choose. Disconnect Google requests token revocation and removes the local refresh credential even when Google cannot be reached.

During a sync, the app sends authenticated read-only requests directly from your computer to Google Search Console for the verified property and dates you selected. It requests page/query clicks, impressions, CTR, and average position for a current period and the immediately preceding equal period, then filters results to the active project origin. Google can omit anonymized or lower-volume queries, and StrictSEO caps a response at 25,000 rows. Use the CSV fallback if you do not want to authorize an account.

Private build access and open-source components

StrictSEO.com does not publish direct extension or local-browser archive links. A visitor can submit the displayed access-request fields through the contact workflow. Once the request information is complete, StrictSEO may reply by email with the free private beta software package, its SHA-256 checksum, and release instructions. The public form does not return a link automatically, create an account, or attach analyzer and local-browser evidence.

The local browser bundles or depends on named open-source components for crawling, parsing, accessibility, and Lighthouse lab testing. Those components are attributed in the included third-party notices; they are not loaded as remote scripts into the StrictSEO website. Verify the complete checksum and archive integrity before installing any privately supplied build.

Your choices and safe use

  • Use pasted HTML when you want the narrowest browser-only review.
  • Activate the extension only on pages you intend to inspect, and stop the session when the review is complete.
  • Avoid private dashboards, personal records, unpublished client material, or authenticated pages if local snapshot processing is not acceptable.
  • Keep exported reports in an appropriate location because they can reproduce visible page evidence.
  • Disconnect Google Search Console when you no longer want the app to retain read-only access, and clear each local project whose metric history you no longer need.
  • Remove the unpacked extension in chrome://extensions or stop the local-browser process when you no longer need it.

No software can honestly be described as risk-free. The extension installation guide provides the exact setup and troubleshooting steps, while the methodology page explains how StrictSEO separates observable evidence from judgment and external data.

Review the product before installing

See the current permissions, supported pages, report handoff, limitations, and checksum instructions in one place.

Read the install guide