Privacy
Privacy policy
Last updated: 7 September 2026. This policy explains how this CrawlLoom deployment handles data used to run and manage crawl audits.
Use this page as an operational privacy notice. The organisation operating this deployment should review it and add its legal name and contact details before relying on it as a formal legal policy.
Information processed
When you start a crawl, CrawlLoom processes the target URL, crawl settings, URLs discovered during the audit, rendered page content, page metadata, headings, link data, status results, and crawl timings. This information is used to provide the audit and its exports.
Browser and session data
The dashboard uses a random, tab-specific identifier in your browser session storage to keep one tab's live crawl separate from another. For security management, the server keeps the session identifier, full IP address, browser/device description, and recent activity time in memory for up to seven days; these details are visible only to an authorised administrator. Administrator and Auditor sign-ins use HTTP-only, same-site cookies. Auditor usernames and salted password hashes are stored in the configured MySQL database; readable passwords are not stored.
Storage and retention
Live crawl results are held in application memory for the active session. Where MySQL history is enabled, completed crawl results are stored in the deployment's configured database until an authorised administrator deletes them. The administrator can permanently remove an individual saved audit or clear all saved crawl history from the protected administration page.
Third-party websites
Crawls request the websites you choose to audit. Those websites may receive the normal technical information associated with a web request, such as the crawler's IP address and request headers. Their own privacy notices and terms apply to their services.
Security and changes
Access to the deployment and its database should be restricted by the operator. No internet transmission or storage system is completely secure. This policy may be updated when the application's data handling changes; the date above will be revised when that happens.