01Who we are
In this policy, "we", "us" and "PixyScan" mean Kiara TechX LLP, a limited liability partnership registered in India (LLPIN ACP-8449) with its registered office at 1101, Time Square 1, Opp. Baghban Party Plot, Thaltej, Ahmedabad, Gujarat 380059, India. PixyScan is a product of Kiara TechX LLP.
This policy covers the PixyScan website and the PixyScan application. It takes effect on 2 October 2026 and we will post any change here with a new effective date.
02What we collect
We collect three kinds of information, plus a fourth only if you connect Google Search Console. Each one is treated differently.
- Account information you give us - your name, email address, password (stored only as a hash), and the workspace and site names you choose.
- Scan data we produce - the URLs, HTML metadata, headers, links, images and findings recorded when we crawl a site you have added, and, for a scan started from a CI/CD pipeline, the branch, commit (with a link to it) and release label the pipeline sends. This is data about a website, not about a person, unless you have put personal data into your own web pages.
- Operational data - log records, IP addresses, browser and device information, and error reports, kept so the service can be run and debugged.
- Google user data - only if someone connects Google Search Console to a site. The section on Google user data below covers what we receive, how we use it and how to remove it.
03What we do not collect
We do not use third-party advertising or cross-site tracking, we do not sell or rent personal data to anyone, and we do not build advertising profiles.
We do not read the content of sites you have not added, and the crawler does not attempt to bypass authentication: if a page requires a login, it is not fetched.
04Why we are allowed to hold it
Where the GDPR applies, our lawful bases are: performance of a contract, for everything needed to provide the account and run scans you have asked for; legitimate interests, for security, abuse prevention, debugging and service improvement; legal obligation, for tax and accounting records; and consent, for anything optional you have specifically opted into.
05Where it is stored
Customer data is hosted in the European Union (Frankfurt, Germany). Because we are established in India, data may be accessed by our staff there for support and operations. Where personal data moves out of the EEA or the UK, that transfer is made under the European Commission's Standard Contractual Clauses.
06How long we keep it
How long scan data is kept depends on your subscription tier: 30 days on Free, 180 days on Hobby, one year on Basic, two years on Pro, and up to ten years where a contract sets it. When the window passes, the scan records fall out of retention and are deleted.
Account records are kept while the account is open. If you delete your account we remove your personal data within 30 days, except for records we are required to keep for tax and accounting purposes, which are retained for the period the law requires.
07Who else sees it
We use a small number of service providers to run the product - hosting, email delivery and payment processing among them. Each is bound by contract to process data only on our instructions.
The current list is published on the subprocessors page, and we will post changes there before a new provider begins processing customer data.
If you connect Google Search Console, we also exchange data with Google: we send it the requests that read your Search Console data, and it sends that data back. The next section covers this.
08Google user data
This section applies only if you connect Google Search Console to a site in PixyScan. Connecting is optional and available from the Basic tier up. A person with admin access to the site connects it from that site's settings, and each site can use a different Google account.
What we access. We ask Google for read-only access to Search Console (the webmasters.readonly permission). With it we read the list of Search Console properties the Google account can see and, for the one property you choose for the site, its search performance data: clicks, impressions, click-through rate and average position, in total, by page and by query, for each search type Google reports. We also receive the Google account's email address and Google's identifier for that account. We never change anything in Search Console.
How we use it. The data is used only to show that site's search performance, and it is shown only to people with access to that site in PixyScan - the members its admins add and the workspace's admins. It appears on the site's Search performance screen and in the CSV files they export from it or from the site's Pages list, and beside the site's scans: search traffic on the site's Overview, clicks and impressions for each page next to the issues and pages a scan found, the site's deploys and scans marked on its traffic trend, its health score shown beside its weekly clicks, before-and-after measurements of the changes PixyScan detected between scans, and an alert when the site's search clicks drop after a deploy. The email address is shown so your team can see which Google account a site is connected with. We do not use Google user data for any other purpose. People at PixyScan do not read it, except with your permission (for example, when you ask us to investigate a problem), where it is needed for security, such as investigating abuse, or where the law requires it.
Your agreement. Before a site is connected, the person connecting it is shown what PixyScan will store, who will see it - the people with access to that site in PixyScan, the members its admins add and the workspace's admins - and where the site's traffic-drop alerts go, and the site is connected only once they tick that they agree. We record that agreement: who agreed, when, and which version of those terms they agreed to. Disconnecting the site records that the agreement was withdrawn.
When those terms change - for example, before the data is used in a new way - syncing for each connected site pauses until the person who connected it reads the new terms and agrees again, or until another admin of the site reconnects it with their own Google account and agrees. While a site waits, PixyScan reads nothing from Google for it, its Search Console data and the measurements worked out from it are not shown, and no traffic-drop alert is raised for it. Nothing is deleted because a site is waiting: once agreement is given again, syncing resumes and catches up on the days it missed.
How we store it. The access Google grants us (a refresh token) is encrypted at rest and is never shown to anyone, you included. The synced data is stored with the rest of your customer data in the European Union (Frankfurt, Germany), and only as far back as your tier allows: 6 months on Basic, and 16 months, Google's maximum, on Pro and Enterprise. Breakdowns by device or country, and between queries and pages, are fetched from Google when someone opens them and cached for a few hours, and so are the per-page figures shown next to a scan's issues and pages. The measurements we work out from the data - the before-and-after result for each change PixyScan detected, and our check of whether clicks dropped after a deploy - are stored with it.
Traffic-drop alerts. When a site's search clicks fall sharply in the days after a deploy, PixyScan raises an alert whose message includes the size of the drop and the click figures behind it. The alert appears in the site's alerts in PixyScan, is emailed to the people who receive the site's alert emails - its members and the workspace's admins, unless they have unsubscribed or the site has turned this alert's emails off - and, if the site has set them up, is sent to its Slack or webhook address. The site's admins choose those addresses in its alert settings, and once a message is delivered there, the receiving service's own terms apply.
Taking your data with you. People with access to a site can download its Search Console data as CSV files from the site's Search performance screen, for the date range and search type they choose: the daily totals (clicks, impressions, click-through rate and average position for each day), the pages, and the queries. A very long pages or queries file holds its top 50,000 rows by clicks.
Sharing. We do not sell Google user data, we do not use it for advertising, and we do not use it to develop or train AI or machine learning models. We do not transfer it to anyone else, except where that is needed to provide this feature - our hosting provider stores it, as it stores all customer data; our email provider delivers traffic-drop alert emails; and a site's alerts go to the Slack or webhook addresses its admins set up - or where the law requires it.
Retention and deletion. Disconnecting Search Console from a site deletes that site's synced data, and choosing a different Search Console property for the site deletes the data synced from the previous one. If your workspace moves to the Free tier, syncing pauses, the data is hidden, and it is deleted 30 days later unless you upgrade again. If the person who connected a site loses admin access to it, syncing pauses until another admin reconnects, and the data is deleted after 30 days if nobody does. If our access to the Google account is removed, syncing pauses until someone reconnects, and the data is deleted after 30 days if nobody does. Deleting the site, or closing the account that owns its workspace, deletes the data too. When a Google account is no longer used by any site, we revoke our access with Google and delete its token.
Measurements we work out from the data follow their own schedule. A finished before-and-after result is kept for your tier's Search Console history (counted as at least 90 days) plus 30 days, and never more than 18 months; the page-by-page detail behind it is deleted after 120 days. Our check of whether clicks dropped after a deploy is deleted after 60 days. These measurements are also deleted together with the synced data: when Search Console is disconnected from the site, when the site's Search Console property changes, and 30 days after syncing pauses - because the workspace moved to the Free tier, the person who connected the site lost admin access, or our access to the Google account was removed. Deleting the site, or closing the account that owns its workspace, deletes them with the rest of the site's data. A traffic-drop alert that was already sent stays in the site's alerts, like its other alerts, until the site is deleted, but when the site's Search Console data is deleted for any of these reasons, the alert loses the click figures it reported: it keeps only that search clicks dropped after a deploy, when, and which deploy it was. Copies already delivered by email or to a Slack or webhook address are held by those services and are not changed.
How to revoke access. Choose Disconnect on the Search Console tab of the site's settings. You can also remove PixyScan's access from your Google Account, under Security, Third-party apps and services, at myaccount.google.com/permissions. After that, syncing stops and the site asks an admin to reconnect. If nobody reconnects within 30 days, the site's synced data is deleted; disconnecting the site in PixyScan deletes it straight away.
PixyScan's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
09Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how we use it, and to receive a copy in a portable format.
To exercise any of these, email privacy@pixyscan.com. We will respond within 30 days. If you are in the EEA or the UK and you are not satisfied with our response, you have the right to complain to your local supervisory authority.
10Security
Data is encrypted in transit with TLS and at rest. Access to live systems is restricted to the people who need it, passwords are stored using a modern password-hashing function, and access is logged.
We hold no SOC 2 or ISO certification, and we would rather say so plainly than imply one is in progress.
11Children
PixyScan is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
PixyScan is a product of Kiara TechX LLP.
Kiara TechX LLP · LLPIN ACP-8449 · GSTIN 24ABEFK1110G1Z1
1101, Time Square 1, Opp. Baghban Party Plot, Thaltej, Ahmedabad, Gujarat 380059, India
Questions about this policy: privacy@pixyscan.com