Grade Engine — sample mode · live scan rolling out Evaluation-led · Web · App · Web3

Home  /  Privacy Policy

Legal

Privacy Policy

We collect as little as the job needs, we tell you exactly what and why, and we never add you to a marketing list without your say-so. Here is the whole picture.

Last updated · 2026-06-30 Informational — not legal advice

The short version

To grade a site we only need the URL you submit. To sell you a Deep Report we also need an email at checkout — used to send your receipt and report, and nothing else. No marketing email and no marketing-list sign-up happen unless you explicitly opt in. This is a plain-language summary and is not legal advice.

§ 01

Who we are (the controller)

Houtos Labs ("we," "us," "our") is the data controller for personal data processed through houtos.io and The Grader. You can reach us through the channels on our contact page or at our primary domain, houtos.io. Where this policy refers to the "GDPR," it includes the EU General Data Protection Regulation and the UK GDPR.

§ 02

What we collect

We practise data minimization — we collect only what a given action requires:

  • The URL you submit. The address of the website you ask us to grade, and the public technical signals we read from that live site to produce the grade and the site snapshot. We do not need an account to run the free grade.
  • Your email at checkout. If you buy a Deep Report ($50) or a development scope ($295), Stripe's hosted checkout collects your email and payment details. We receive your email and the payment metadata (amount, status, references) — we never see or store your full card number. This email is used transactionally only (your receipt and the delivery of your report); it is not added to any marketing list.
  • Marketing data — only if you opt in. We do not currently run marketing email. If we ever do, it will be via a single, clearly-labeled, unchecked opt-in box that is separate from your purchase — never pre-checked, never bundled into the transaction.
  • Operational and security data. Limited technical information needed to run the Service securely and reliably — for example, a Turnstile bot-check token, IP address and request metadata for rate-limiting and abuse prevention, and error diagnostics. We do not perform behavioral profiling, and we do not capture mouse-movement or keystroke data.

We do not knowingly collect data from children, and the Service is intended for business use by adults.

§ 03

How we use it & our lawful bases

Under the GDPR we rely on the following lawful bases:

  • Performance of a contract (Art. 6(1)(b)). To run the grade you requested, generate and deliver your paid report, issue your receipt, and operate the "Ask this report" consultation — including the transactional email needed to do so.
  • Legitimate interests (Art. 6(1)(f)). To keep the Service secure and available — bot-protection, rate-limiting, fraud prevention, error monitoring, and reconciling payments — balanced against your rights.
  • Legal obligation (Art. 6(1)(c)). To retain payment and accounting records where tax, accounting, or other law requires it.
  • Consent (Art. 6(1)(a)). For any future marketing communications, and for any non-essential cookies — given through a clear, unbundled opt-in you can withdraw at any time.

We do not sell your personal data, and we do not use your data to train AI models. Your report's content is the only context given to the "Ask this report" assistant; your email is never placed into a model prompt.

§ 04

Processors we share data with

We use a small set of trusted sub-processors to run the Service. Each receives only the data needed for its function, under a data-processing agreement:

  • Stripe — payment processing and hosted checkout (card details, email, payment metadata). Stripe is the system of record for payments.
  • Anthropic — the AI model that generates the report narrative and powers the "Ask this report" assistant (report signals; not your email).
  • OpenAI — text-embedding generation used for the report's retrieval and cached-answer matching (report-derived text; not your email).
  • Bright Data — supporting data collection of public web signals used in grading.
  • Vercel — hosting and serverless compute for the front end and AI layer.
  • Neon — the database that stores reports, payment/credit ledger records, and related data.
  • Sentry — error monitoring and diagnostics for reliability.
  • Cloudflare — network delivery, security, and the Turnstile bot-check.

We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a business transfer (with this policy continuing to apply).

§ 05

How long we keep it

  • Reports and site snapshots: retained for approximately 90 days (the re-grade window), then deletable, and purged sooner on request.
  • The URL you submitted and grading signals: retained for the life of the related report under the same window, subject to our minimization policy.
  • Payment and ledger records: retained for as long as tax, accounting, and other legal obligations require — even after a deletion request, the financial ledger entry is kept as a legal record with personal data minimized. Stripe retains payment data under its own policy.
  • Security and diagnostic logs: kept only as long as needed for security and reliability, then deleted or aggregated.
§ 06

Your rights (GDPR/UK GDPR)

Subject to the conditions in the law, you have the right to:

  • Access the personal data we hold about you (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16);
  • Erase your data — the "right to be forgotten" (Art. 17), subject to records we must keep by law;
  • Export / data portability — receive your data in a portable format (Art. 20);
  • Restrict or object to certain processing (Art. 18, Art. 21); and
  • Withdraw consent at any time where processing is based on consent (Art. 7(3)), without affecting prior processing.

To exercise any right — including access, export, or deletion — contact us via the details in section 9. We will respond within the timeframe the law requires (generally one month). Exercising your rights is free, and we will not penalize you for it.

§ 07

Cookies, Turnstile & tracking

We keep this light. We use a small amount of essential browser storage — for example, remembering your light/dark theme preference — that is necessary for the site to work and does not require consent. The Cloudflare Turnstile bot-check runs on the grader and checkout to tell humans from bots and protect the Service from abuse; it is a security measure, not advertising tracking.

We do not run advertising trackers or behavioral-profiling cookies. If we ever add non-essential analytics, we will request consent first and follow data-minimization (aggregated metrics, documented retention, no mouse-movement capture).

§ 08

International transfers & security

Some of our processors are located outside your country, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as the processors' Standard Contractual Clauses or equivalent mechanisms. We protect your data with encryption in transit, access controls, per-tenant isolation on our databases, and the principle of least privilege. No system is perfectly secure, but we treat your data carefully and design for safety by default.

§ 09

Contact & complaints

For any privacy question or to exercise your rights, contact Houtos Labs through our contact page or at houtos.io. If you are in the EU or UK and believe we have not handled your data properly, you also have the right to lodge a complaint with your local data-protection authority — though we would appreciate the chance to resolve it with you first. See also our Terms of Service and Refund & Credits policy.

Note

This is a plain-language summary; final terms are subject to counsel review. It is informational and not legal advice.

← Back to home