Privacy Policy
It describes the current TendClear implementation and needs founder and legal review before a broader public launch.
What TendClear processes
TendClear processes account identity and authentication/session information; password-reset email addresses, expiring reset records and pseudonymous reset rate-limit information; business names, memberships and roles; submitted website names and URLs; business category, services, service area, preferred tone and CMS preference; and support or deletion communications you send us.
When you request a scan or audit, TendClear retrieves public website pages and records page addresses, response information, titles, search descriptions, headings, links, crawl coverage, findings, action plans, audit history and recheck results. Anonymous scans also use private access/claim tokens stored as hashes and pseudonymous rate-limit information.
If you request an AI-assisted draft, TendClear stores the relevant request context, generated output, your saved edits, provider/model identifiers and usage counts. If you optionally connect Google Search Console, TendClear stores the selected property, finalized date/page/query performance measurements and encrypted Google access credentials.
Why it is used
We use this information to operate accounts, perform requested scans, prioritize website improvements, prepare optional drafts, recheck measured conditions, display optional Search Console context, prevent abuse, secure and debug the service, and respond to support or deletion requests.
Google Search Console
Search Console is optional. TendClear requests read-only access and retrieves properties plus finalized measurements such as dates, pages, queries, clicks, impressions, click-through rate and average position. Stored credentials are encrypted. Search Console activity can help prioritize an existing website action; it does not prove causation or guarantee an outcome.
Disconnecting causes TendClear to attempt Google credential revocation and delete its stored connection, credentials, synchronization jobs and Search Console measurements for that website. TendClear does not send Search Console credentials or Search Console performance rows to OpenAI for the current draft feature.
AI-assisted drafts
When you request a draft, TendClear may send OpenAI your business name, category, service area, services, preferred tone, relevant page URL/path, current title and description, measured action details and action type/subject. It does not send passwords, cookies, database credentials, Google OAuth credentials or Search Console performance rows. The current API request is configured with storage disabled. AI output can be wrong and must be reviewed. Nothing is published automatically.
Service providers
Current providers are Render for application and PostgreSQL hosting, Resend for password-reset email when outbound delivery is configured, OpenAI for user-requested AI drafts, and Google for optional Search Console authorization and data. Payment processing is not currently implemented.
Retention and deletion
Anonymous rate-limit attempts are designed to expire after 24 hours, and unclaimed anonymous scan results after 72 hours. Claimed account, site, audit and draft data is retained while the account is active or until deletion. Search Console data is removed on disconnect. Operational logs and backups can follow the hosting provider’s operational retention rather than disappearing immediately.
Signed-in users can request account and data deletion from Privacy settings. The controlled beta uses a reviewed process so organization ownership, shared access, active work and Google disconnection can be handled safely. Contact privacy@tendclear.com with privacy questions.
Security and changes
TendClear uses HTTPS, managed PostgreSQL, tenant-scoped authorization, separate runtime/migration database roles, hashed security tokens and encrypted Google credentials. No system can promise absolute security. Because this is a private beta, this draft may change as the product changes; material updates should be dated and communicated before broader use.