Privacy
Privacy overview
Effective August 21, 2026. This plain-language notice describes the current Onread service and product data flows.
Last updated August 21, 2026
Information you provide
Onread stores information you submit for quotes and consultations, including contact details, business and website information, service needs, preferred contact method, and project messages. Account users may also provide Business Context, goals, chat messages, recommendation status, support requests, and other workspace data.
Public information analyzed
The free preview and account audit may fetch accessible public website pages, robots.txt, and sitemap.xml. Managed-site monitoring may periodically request the configured public site address and store the time, reachability, HTTP status, response duration, and a bounded operational summary. These requests do not provide access to private analytics or accounts.
Managed client records
For managed website clients, Onread may store the website assignment, monitoring configuration and samples, incidents, maintenance notes, support tickets, and managed-service subscription or payment status. These records are scoped to the client account and used to deliver and document the service.
Connected Google reporting
When a managed website is configured with Google Analytics 4 or Google Search Console, Onread uses server-side credentials and the configured property identifier to request reporting data for the client portal. The portal displays provider responses or an explicit disconnected, empty, or error state; it does not invent analytics.
AI processing
When the AI Consultant or Implementation Help is used and an AI provider is configured, a compact context based on saved business and audit data may be sent to that provider to generate a response. Deterministic analyzers remain the source of audit scores and findings.
Authentication and service providers
The application may use Vercel for application hosting, a managed PostgreSQL provider for database hosting, Auth.js and Google for authentication, Resend for transactional email, Stripe for billing, Google reporting APIs for connected client analytics, and OpenAI for requested Onread AI features. Provider credentials remain server-side.
Payments and account security
Stripe processes payment details on its hosted pages; Onread stores billing identifiers, product and subscription state, invoice or receipt references, and fulfillment records rather than full card numbers. Onread AI billing and managed-service billing remain separate application records. Session cookies support sign-in and account security.
Security and retention
Public audit links use opaque tokens stored as hashes and expire after seven days. Rate-limit identifiers are also stored as keyed hashes. Operational pruning removes eligible expired security and preview records when the documented retention task runs. Other service, support, and billing records are kept as needed for account, operational, financial, and legal purposes.
Your choices
Confirm only profiles that belong to the business, avoid entering unnecessary sensitive information, and review generated content before publishing it. Automated account deletion is not currently available. Contact Onread to request access, correction, or deletion assistance; requests remain subject to applicable legal and operational requirements.
Questions
Contact colestroup@outlook.com with privacy or account questions.