HelpAEO
Log inScan my site
Privacy

Privacy & data

Everything we store, every company we rely on to run this service, and where your data physically lives.

If anything below is unclear, or you want to know what we hold about you specifically, email hello@helpaeo.com and a person will answer you.

Who is responsible for your data

HelpAEO is operated by REA3 Limited, a company incorporated in Hong Kong (Business Registration No. 79875361-000-03-26-3), registered at Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong.

REA3 Limited is the company answerable for everything described on this page — the "data user" under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486), and the data controller if you are reading this from the European Union or the United Kingdom. For any question or request about your data, including deletion, write to hello@helpaeo.com.

Where your data is stored

Everything HelpAEO stores about you sits on servers we rent in Germany, from the German hosting company Hetzner Online GmbH. Those servers are inside the European Union, and the data on them is held to the European Union's privacy law, the GDPR.

We have chosen to run this service to the GDPR standard for everyone who uses it, wherever you happen to live — not only for people in Europe. In practice that means we collect the smallest amount of information the product can actually work with, we tell you what it is on this page, we never sell it or share it for advertising, and you can have all of it deleted whenever you want.

Nightly backups of that database are kept on those same servers in Germany and are automatically discarded after 14 days. Our own operational logs stay there for up to 30 days; they can record the addresses of sites that were scanned, they are not covered by the deletion described below, and they age out on their own.

What we store when you run a scan

  • The website address you asked us to scan
  • Whether it was a free or a paid scan, and when you ran it
  • Whether the scan is still running, finished, or failed
  • The results of each check and the score we calculated from them. Those results quote short pieces of what we found on the page, which can include a contact email address or phone number that the site publishes
  • A copy of the visible text of the page we scanned — both as we fetched it and as it is rendered in a browser, capped at 15,000 characters per side. This is the same text the report shows you back as the "agent's-eye view", together with how long the full page really was and how much of it an AI agent could actually see. A paid scan also reads your linked About page the same way.
  • The key that unlocks your report link. We store it scrambled (hashed), so the link we gave you keeps working but the key itself cannot be read back out of our database
  • Which account the scan belongs to, if it belongs to one — because you were logged in when you ran it, or because you used "save to my account" to claim it afterwards
  • How you found us, so we can tell which channels bring visitors: if the link you arrived on carried campaign parameters (utm_source, utm_medium, utm_campaign), and the host name of the site that sent you (for example google.com) — never the full address of the page you came from. Your browser keeps these from the first time you arrive that way (see "Cookies and your browser" below), and they are sent with a scan you start from our scan form, and stored on that scan

What we store when you have an account

  • Your email address, an optional display name, and whether you signed up as a brand or an agency
  • When the account was created, and when you last signed in and last used it
  • The login code we email you, stored scrambled (hashed) rather than as the code itself. It stops working 10 minutes after we send it, or after 5 wrong attempts
  • Your sign-in session, also stored scrambled (hashed) rather than as the value your browser holds. A session ends when you log out, or 30 days after you last used it — the record of it stays in the database, marked ended, until you delete your account
  • A Stripe customer ID against your account, but only once you have paid for something — we use it to open your billing page and nothing else. Accounts that have never paid do not have one

We do not store a password, because there isn't one — you sign in with a code sent to your email. Your IP address and your browser's identity are never written to the database, for anything: not for sign-in, not for sessions, not for scans.

What we store about the domains you track

  • Each tracked domain you add to your dashboard, and any label you give it. Removing one deletes that entry and the billing record attached to it — it never deletes a scan you already ran
  • If a tracked domain is on a subscription — a recurring charge you can cancel any month, whether you started it yourself or we set it up with you — we store whether it is active, where it came from, its Stripe reference, when the current billing period ends, and when it was cancelled. Cancelling never deletes the domain or its scans
  • For a tracked domain without a subscription, when you last used a free rescan of it — only so we know when your next one is due, since free rescans are one per domain every 30 days

Starting a subscription at checkout attaches the resulting report to your account automatically.

What we count, and what we deliberately don't

We keep a daily tally of a handful of product events — how many reports were opened today, how many people clicked through to checkout, and how many times the play button on the home-page demo was pressed. These are running totals only. No visitor identifier is attached to them, so there is no way for us to turn them back into a person, including you. We cannot tell which pages any individual visited. The one exception: once you press play on the home-page demo, our demo provider Supademo records how that viewing went (which steps you view and what you click) and shows it to us. It sees nothing else of the site.

We do not sell your data or share it for advertising. There is no advertising technology on this site, and nothing of ours follows you to other sites. The one place a third party records how you use the site is the demo, and only after you press play (see Supademo below).

The companies we rely on, and what each one receives

These are all of them. There are no others.

  • Hetzner (Germany) — rents us the servers in Germany where everything described above is stored.
  • Cloudflare (United States, with servers worldwide) — sits in front of our site to deliver it quickly and to keep it online under attack. Every visit passes through Cloudflare, so Cloudflare sees your IP address, as any provider of this kind necessarily does. It also runs the "are you human?" check on the scan and login forms, and gives us a privacy-focused visitor count (see "Cookies and your browser" below).
  • Stripe (United States and Ireland) — takes the payment. You enter your card details on Stripe's own page, never on ours; we never see or store a card number. Stripe collects your email address at checkout and tells us a reference number for the payment.
  • Resend (United States) — delivers our emails to your inbox: your sign-in code. It receives your email address and the contents of that email, and nothing else about you.
  • Poe (United States) — on paid scans only, some checks ask an AI model for a judgement. What we send is an extract of the text of the website being scanned. Your name, email and account are never sent. A free scan is never sent to an AI model at all.
  • Supademo (United States) — hosts the product demo on our home page. Nothing loads from Supademo until you press play. When you do, the demo loads from Supademo's own servers (app.supademo.com and its other addresses), which, together with the services Supademo itself uses, see your IP address and browser details, from which a general location can be told, and record which steps you view and what you click. It is not linked to your HelpAEO account. Supademo's own policy states that it processes data in the United States (on AWS) and collects device and browser information, IP address and general location.

Several of these companies are based outside Hong Kong and outside the European Union, so data reaching them is processed in places whose privacy laws differ from both. We share only the minimum each one needs to do its job — the narrow slice described above, never your scan history and never our database — and we choose providers that publish data protection commitments, which is what the Hong Kong Privacy Commissioner's guidance on cloud computing asks of us.

Cookies and your browser

We set no cookies of our own until you sign in. Cloudflare, which sits in front of the site, may set a short-lived cookie of its own to tell humans apart from bots. If you press play on the home-page demo, Supademo may set cookies of its own inside the demo (see above).

One cookie is set, and only if you sign in: the one that keeps you signed in. It is what makes your account work, it is readable only by our server and not by any script in the page, and it disappears when you log out. If you start a report and then sign in to save it, your browser holds onto that report for the length of that one visit so it isn't lost along the way, and discards it when you close the tab.

The first time you arrive from a campaign link or from another site, our page saves one entry in your browser's local storage, named helpaeo_attribution. It holds the campaign parameters (utm_source, utm_medium, utm_campaign) of the link you arrived on and the host name of the site that sent you, and nothing else. It is written before you scan or sign in, even if you never do, only that first time, and it has no expiry. It stays on your device and is sent to us only along with a scan you start from our scan form. To remove it, clear the site data for helpaeo.com in your browser's settings.

When you start a scan from our scan form, our page also saves one entry in your browser's local storage, named helpaeo:created-scans. It holds the ids of the last few scans you ran in this browser (at most twenty), and nothing else. We use it so the report offers its quick save form only in the browser that ran the scan. It is not a lock: anyone you share the report's link with can still log in and save a report that nobody has saved yet. It stays on your device and is never sent to us. It has no expiry. To remove it, clear the site data for helpaeo.com in your browser's settings.

Our visitor count comes from Cloudflare Web Analytics, which was built to work without cookies: it sets nothing on your device, does not fingerprint your browser, and does not follow you to other sites. The "are you human?" check on the scan and login forms is Cloudflare Turnstile, which exists to stop bots from running up our costs and likewise sets no tracking cookie. There is no Google Analytics, no Meta pixel, no advertising network, and no third-party tracker on this site. The one exception is the product demo on our home page: only after you press play does it load from Supademo, which may set cookies or similar storage of its own inside the demo (see its entry in the list of companies above).

How long we keep things, and how to delete them

We keep your account and your scans for as long as your account exists, so your history is there when you come back. We do not run an automatic expiry today. We have built one — it would clear the stored page text from older free scans and remove long-dormant accounts — and we will describe it here before we ever switch it on.

You can delete everything yourself, at any time, from the "Danger zone" section of your account page. It removes your account, your email address, your sign-in sessions and login codes, your tracked domains, and every scan attached to your account — paid ones included. It cannot be undone.

We ask Stripe to cancel any active subscription before we delete anything. If Stripe cannot be reached at that moment we still delete your data, and we cancel the subscription by hand as soon as we can — so if you ever see a charge after deleting, tell us and we will refund it.

If you would rather we did it for you, or you never made an account and want a scan removed, email hello@helpaeo.com and we will. Stripe keeps its own record of payments it processed, because it is legally required to.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we are using it. One email to hello@helpaeo.com is enough — there is no form, and we will not ask you why. We aim to answer within a few days and within 30 days at the outside. If you are in the European Union and you think we have handled your data badly, you have the right to complain to your national data protection authority.

Children

HelpAEO is a tool for people running websites professionally. It is not directed at children, and we do not knowingly collect personal data from them.

Reports you share

A free report link contains its own key, so anyone you send it to can open it without signing in. That is deliberate — it is how you share a free report with a colleague or a client. It also means you should treat the link as you would the report itself. Full-audit (paid) reports have no such link: they are visible only when signed in to the account that owns them. We ask search engines not to index report pages, and we have never published one.

Last updated 4 October 2026. We may update this policy as the product changes; this date always reflects the most recent revision. If a change affects what we collect or who receives it, we will say so here before it takes effect.