Overview
Legal
Last updated: October 6, 2026
1. Scope
This policy explains how Prerender Buddy ("we," "our," or "us") handles personal data when you visit the public website, create an account, connect a website, use a diagnostic tool or browser extension, contact support, use the crawler-rendering service, or use AI Visibility, article generation, supported publishing, Buddy/Agent, API/MCP access, eligible AI Ads workflows or optional human management.
2. Data we handle
-
Account data: Name, email address, authentication identifiers, workspace membership, and session information handled through Clerk.
-
Site and setup data: Domain, public origin URL, setup method, DNS and HTTPS status, cache settings, API-key metadata, and verification state.
-
Rendering and diagnostic data: Public URLs submitted for testing or rendering, publicly available page content and resources, response status, crawler family, cache result, timing, and bounded operational logs.
-
AI Visibility data: Controlled prompts, provider answers, source and citation relationships, run context, tracked brand aliases, and tracked or detected competitors. These records come from configured provider API runs, not private consumer conversations.
-
Content and Buddy/Agent data: Full article drafts, proposals, supporting answer/source and website evidence, review and approval state, conversations, and relevant account or site context used to answer a request.
-
Publishing connection and release data: CMS/site/store/blog identifiers, configured field or repository mappings, destination settings, encrypted connection credentials, signing secrets or deploy hooks, feed-key hashes, approved release snapshots, schedules, actor identifiers and contact details where supplied, remote identifiers and URLs, delivery attempts, results, errors and timestamps.
-
API and MCP access data: API-key prefixes and hashes, OAuth authorization and token records, permitted scopes, workspace/site identifiers and relevant request or action records. A connected client receives the evidence or content requested within its authorized scope and may retain that output under its own terms.
-
Creative and Ads data: Uploaded or generated creative assets, copy and variations, proof results, provider account identifiers, encrypted provider credentials, connection state, and imported performance records such as impressions, clicks, spend, currency, and reporting dates.
-
Billing data: Plan and subscription status, billing contact, and Stripe customer or subscription identifiers. Payment-card details are entered into Stripe-hosted interfaces and are not stored by Prerender Buddy.
-
Support data: Messages, email correspondence, and relevant account or setup diagnostics supplied to resolve a request.
-
Email preferences: Optional marketing choice, consent time and source, policy version, unsubscribe time, and delivery-provider synchronization status.
-
Technical and security data: Request metadata needed for service delivery, abuse prevention, rate limiting, troubleshooting, and security. Infrastructure providers may transiently process IP addresses and maintain their own service logs.
3. Why we use it
-
To create and secure accounts and workspaces.
-
To fetch public pages, generate and cache rendered HTML, route eligible crawler requests, and report service status.
-
To run controlled AI Visibility checks and organize answers, citations, aliases, and competitor evidence.
-
To generate complete article drafts from available evidence, provide Buddy/Agent assistance, and support eligible creative, Ads connection, handoff and performance-reporting workflows.
-
To validate configured publishing connections, deliver reviewed drafts, execute explicitly approved publication or publication schedules, and record the resulting release and delivery state.
-
To provide scoped API/MCP access and optional human management when those services are used.
-
To provide diagnostics, support, billing, transactional messages, and account administration.
-
To send optional product education and marketing messages only when you have opted in, and to preserve and enforce your unsubscribe choice.
-
To enforce plan limits, prevent abuse, investigate failures, and maintain service security.
-
To understand aggregate product use and improve onboarding where consent or another lawful basis applies.
-
To comply with legal, accounting, tax, or regulatory obligations.
Depending on the context and applicable law, processing is based on performing our agreement with you, our legitimate interests in operating and securing the service, your consent, or compliance with a legal obligation.
4. Public-page rendering and diagnostics
Prerender Buddy is designed for public website pages. The renderer may load the configured public URL and its public resources in a browser environment and cache the resulting HTML. Durable render logs remove query strings and fragments, but the current process-local HTML cache uses the exact requested URL. The managed rendering service applies configured freshness and bounded stale-response rules and periodically removes entries past their retention deadline. After confirmed publication through supported native CMS connectors, PB attempts to clear the registered site's renderer cache. This is separate from off-platform edits, Git/feed releases, hosting completion and other cache layers; verify the live result and use the appropriate purge or refresh path when needed. Do not send credentials, session identifiers, personal data, signed links, or private page content through the rendering path.
5. Chrome extension
If you use the Prerender Buddy Chrome extension, the extension may send the URL of the active browser tab to the Prerender Buddy API when you run a crawlability check. We use that URL to fetch and analyze publicly available page content for crawler visibility signals.
The extension does not read passwords, form fields, cookies, or private browsing history. It does not modify the pages you visit. If you choose to save a site, the extension opens the Prerender Buddy web app so account creation, login, and site setup happen through our normal Clerk-powered web flow.
6. Product analytics
On the public website, Google Analytics 4 measures page visits and engagement only after you allow optional analytics. It uses browser and cookie identifiers to summarize visits and traffic sources. Our tag sends page paths and referrers without query strings or URL fragments; it does not send form values, email addresses, account IDs or tested website URLs. Automatic form tracking, Google signals and advertising personalization are disabled. You can withdraw permission through Cookie Settings. Read how Google uses information from sites that use its services.
With your consent, we use PostHog Cloud in the United States to measure page visits and product funnel events. PostHog client analytics exclude query strings, referrers, tested website URLs, site domains, and email addresses. PostHog session replay and broad automatic interaction capture are disabled.
With the same optional analytics consent, we use Microsoft Clarity for heatmaps and privacy-masked interaction recordings. Clarity may process the visited page, browser and device information, clicks, scrolling, pointer movement, and reconstructed page interactions. Input fields and other content Microsoft classifies as sensitive are masked before transmission, and the authenticated dashboard is explicitly masked. Clarity is not initially loaded unless analytics consent is granted; withdrawing consent clears its cookies and ends consent-based tracking.
We also record a limited set of authenticated service milestones, such as account setup, site creation, successful verification, and subscription activation. These events use the account provider's pseudonymous user identifier and limited plan or setup properties; they do not include email addresses, tested URLs, or customer site domains.
7. Service providers and international processing
We use service providers for identity, hosting, edge routing, billing, email, AI Visibility and generation features, support assistance, analytics, and availability monitoring. Their roles vary by service: some process data on our instructions, while others such as payment providers may also act as independent controllers for specific legal or fraud-prevention purposes. Enabled AI features send the relevant prompt, conversation, evidence or generation context to their configured provider. Supported publishing sends the reviewed article and required metadata to the customer-configured CMS, repository, webhook or hosting workflow. Those destinations and connected API/MCP clients can have their own processing and retention terms.
PostHog and Microsoft Clarity may process analytics data in the United States. Other providers may process data in the United States, the European Economic Area, or other locations under their applicable terms and transfer mechanisms. The current functional provider inventory and links to provider documentation are in the Data Processing Overview .
8. Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
9. Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
The current technical storage inventory and application retention defaults are described in our Data Processing Overview .
10. Your rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data and (where the lawful ground of processing is consent) to withdraw consent.
Send a request to security@prerenderbuddy.com . We may verify your identity before acting. For GDPR requests, we aim to respond without undue delay and within one month, or explain a permitted extension within that period. See the GDPR and Privacy Rights page for the request process.
Where the GDPR applies, you may also lodge a complaint with the supervisory authority in your country of residence, work, or the place of the alleged infringement.
11. Contact
If you have any questions about this privacy policy or our privacy practices, please contact us at security@prerenderbuddy.com . For general product support, email support@prerenderbuddy.com .