Privacy
Krystian Gwizdała, a private individual in Poland, is the controller of the data described here. Write to hello@letagentsin.com about anything on this page, including deletion. There is no registered company behind this yet. If one is formed and becomes the controller, this page will say so and everyone whose address we hold will be told.
What we store
- Scan results. Requests to public pages of a domain, and what they answered. These describe companies rather than people. A scan we run is published: it appears at
/v/<domain>and in the downloadable set at/corpus.json. A scan you run stays at its own/r/<id>address: we do not link it from this site, do not show it at/v/<domain>and do not include it in/corpus.json. Three things are worth knowing about that address. If the domain was already scanned in the last fifteen minutes you are handed that scan instead of a new one, and when it is one of ours it is one of the published ones. The address is the only thing protecting a scan of your own, and it has not always been worth that job: from 20 August 2026 it carries 64 random bits, before that 16, and twenty-four reports made on 7 August 2026 - counted on 20 August 2026 - carry none at all, because the suffix did not exist yet and the address is the domain and the minute. Those twenty-four stopped being served on 20 August 2026: the rows are still there, the pages are not. Treat any of the others as a link to keep rather than a secret. And if our database refuses the write, the report lives only in memory and its page says so. - Contact details, when you give them: an email address to send a scan result, to confirm a domain you asked us to watch, or to deliver something you bought. An inquiry submission also includes your name, company or product, selected interest and message. A watch record holds an identifier for the watch itself, the address you gave us, the domain you asked us to watch, when it was created, when you confirmed it, which measurement the last alert was compared against, the score at that measurement, how many points were measurable then, when we last checked, when it should be checked again before its ordinary turn, which changes are waiting for a second measurement before we mail them, when you stopped it, kept so we cannot undo your unsubscribe, whether it is a trial or paid, the subscription identifier, when there is one, which category to read the domain against, when it is not one we publish, the brand name to search for beside the domain, when you gave one. That list is generated from the record itself rather than written here, so it cannot fall behind it. The inquiry form sends the fields you enter to Formspree for delivery to the owner's notification address; we do not buy data or join it to another service.
- A page counter. A date, a path or the name of a button that was pressed, and whether the request looked like a browser, an unnamed client, or one of a short list of search and AI crawlers we watch for by name so we can tell which indexes read us. Alongside that, one word from a fixed list naming the family of client that asked: chrome, firefox, curl, python and a dozen others, or other when it is none of them. It tells us how much of our traffic is a script rather than a person, which is the question this product exists to ask. The crawler name and that one word are the only things kept from the user-agent, and neither carries a version, a platform or a build. No IP address, no user-agent string stored, no identifier that could be joined to a person.
- Cookieless web analytics. For browsers that run JavaScript, PostHog counts page views, approximate unique visitors and the few actions that make up the product funnel: starting and completing a scan or visibility audit, opening a report, and successfully submitting an email form. We do not send the domain scanned, an email address, a report address, a watch token, or URL query strings. PostHog processes the request IP address and user-agent transiently to make a privacy-preserving identifier on its EU servers; neither raw value is stored and the identifier is not kept in the browser.
- AI visibility audit inputs. When you run the beta, the brand, domain, product category, selected depth, prompts, answers and cited sources are saved with a random audit identifier in MongoDB. A worker sends the prompts to signed-in Claude, Codex and Google Antigravity CLI sessions and to the Perplexity Search API. The result returns to this browser by that random identifier. Do not put confidential information in the category field.
What we do not do
No cookies, advertising pixel or session recording. The PostHog script records only aggregate web analytics and the named funnel events above: automatic click capture, heatmaps, surveys, user profiles, exception capture and feature flags are disabled. A page remains fully readable without running that script, and our separate server counter measures the agents that do not run it. We do not sell personal data or use it to train anything.
Who processes it for us
Heroku (hosting, EU region), MongoDB Atlas (storage), Resend (scorecard and monitoring email delivery), Formspree (contact-form delivery), PostHog Cloud EU (cookieless aggregate web analytics), and, only when you run the visibility beta, the configured model providers Anthropic, OpenAI, Google and Perplexity. Each sees only what is needed to do that job. A payment provider is added here the day payments go live, and it will be named before anybody is asked for a card.
How long
Scan results are kept as long as they are published, because a permanent link that stops working is worse than one that ages. An address given for monitoring is kept until you stop it: every email we send carries a stop link, and using it ends the mail immediately. An address given for a one-off delivery is kept for as long as we owe you a receipt or a rescan. Inquiry messages are kept in Formspree and the owner's mailbox as needed to answer and manage the conversation. Visibility audit jobs and their answers are kept while the beta is being evaluated; ask us to delete one by sending its identifier.
Your rights
Access, correction, deletion, portability and objection, under the GDPR. One email to hello@letagentsin.com is enough, and there is no account to close first. You can also complain to your data protection authority.
Scanning somebody else
Anyone can scan any domain here, which is the point: a vendor is measured the way an agent would measure them, from the outside, using only what they publish. If your domain is in our corpus and you would rather it were not, write and it comes out. If a verdict about you is wrong, write and we rescan; corrections are published beside the row rather than quietly applied.