Last updated: 12 August 2026 · Company details final · Pending legal review
haAplo ("we", "us") measures how readable and citable websites are for AI engines, and helps make them user and AI-friendly. This policy explains what personal data we collect, why, and what your rights are. It applies to the haAplo web application and API. We offer haAplo to both businesses (B2B) and consumers (B2C).
The data controller is PRIMEBUILD s.r.l., Via Borgogna 8, 20122 Milano (MI), Italy, VAT IT11516910962, company email [email protected]. Privacy contact: [email protected].
| Data | Why we collect it | Legal basis |
|---|---|---|
| Account data: email address and password (password stored hashed, never readable by us) | To create and secure your account | Contract |
| Audit data: the URLs you submit, crawled page content and audit results | To run the audits and fixes you request and show your history | Contract |
| Site and monitoring data: sites you register, tracked prompts, AI-bot visit counts reported by the optional plugin | To provide monthly re-audits, citation monitoring and reading proof | Contract |
| Usage and cost metering: API usage per account | To enforce plan quotas and prevent abuse | Legitimate interest |
| A record of sensitive actions on your account: logging in, changing plan, inviting or removing a team member, storing or revoking a Cloudflare token, approving or rejecting generated content, adding or removing a site, asking for your account to be deleted. Each entry holds what happened, when, and an account identifier — never your email address. The record cannot be edited or deleted, by us either | Security, and proving who approved what | Legitimate interest |
| Technical logs: timestamps and errors. For the free audit and other public endpoints we also store a salted hash of the caller's IP address — never the address itself, and it cannot be turned back into one — which is deleted one hour later | Security, rate limiting, debugging | Legitimate interest |
| Billing data: name, billing address, VAT number, payment method | To process subscription payments (handled by Stripe; we never see your full card number) | Contract / legal obligation |
| Waiting-list email (if you joined the waiting list) | To contact you about availability | Consent |
We do not sell personal data and we do not run advertising profiling. This site sets no cookies at all: your login session is kept by your own browser (local storage) and never travels to us as a cookie. There is no advertising tracker and no analytics script on this site.
When you audit a website, its publicly available pages are crawled and parts of their content are processed by AI model providers (listed below) to analyse content quality and generate fixes. We only process content that is already public on the audited website, and our generators are grounded: they only reuse facts found on your pages. Everything haAplo generates is marked as AI-generated with a public, machine-readable scheme: see /ai-transparency. We never use your data or your websites' content to train AI models.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (Frankfurt) |
| Railway | API hosting | EU region |
| Netlify | Website hosting | Global CDN |
| Resend | Transactional email | EU/US |
| Stripe | Payments, invoicing, VAT | EU/US |
| Anthropic | AI analysis of audited public content and generation of the outputs you request; citation checks (Claude) | US (EU endpoints where available) |
| OpenAI | Citation checks only (ChatGPT with web search) | US (EU endpoints where available) |
| Perplexity | Citation checks only | US |
| Google (Gemini) | Citation checks only (Gemini with web search) | US (EU endpoints where available) |
| Google (Search Console) | Search query strings and counts, read-only — only for sites you choose to connect; raw exports are never stored, and you can disconnect (revoking our access at Google) with one click | US (EU endpoints where available) |
Where a provider processes data outside the EU/EEA, transfers rely on adequacy decisions or Standard Contractual Clauses. This table is the single, live list of our sub-processors: it changes here first, and account holders are informed by email before an addition or replacement. A signable Data Processing Agreement is at /dpa.
You delete your account yourself, from the Security page inside haAplo. It is scheduled for 7 days later — enough time to undo a wrong click, or to stop someone who found your session open — and you can cancel it at any point during those days with one button. If you don't want to wait, the same page has a delete it right away button. Either way we confirm it to you by email.
What is deleted: your account, the sites you registered and their keys, the packages we build for them, drafts, AI-bot visit counts and tracked prompts. What stays, no longer pointing at you: the audits you ran, kept as measurements; the record of sensitive actions, which keeps what happened and never who; and billing records, for the statutory period only. You can also write to [email protected] from your account email address and we do it for you.
You have the right to access, rectify, delete and export your personal data, to restrict or object to processing, and to withdraw consent at any time. Write to [email protected]. You can also lodge a complaint with your local data protection authority.
If this policy changes in a way that affects you, we will update this page and the date above. Substantial changes will be announced by email to account holders.