English
Seges Trust

Privacy

Privacy notice

Seges Trust is free and never requires an account to use its tools. Where it is enabled, signing in with Google is entirely optional. This page describes, in plain terms, exactly what the live tools on this site do with the data you give them.

The instant page check (/critique)

When you submit a public URL to /critique, the server performs a one-time headless-browser visit to that page. The resulting report — the submitted URL, its host, a timestamp, and the findings — is scheduled for deletion 90 days after creation under a randomly generated report ID, so the report can be revisited later at its own permalink. Firestore TTL deletion is asynchronous, so an expired permalink can remain available briefly while the deletion is processed. If you are signed in when you submit, the report is also tagged with your Google account ID so it can appear on your Account page; if you are not signed in, no account ID is stored on the report. Some findings (the client-side secret scan) are withheld from that stored report and from the immediate response unless the submitted URL’s host also holds a currently-verified domain-verification record — an unverified attestation alone does not unlock them.

Domain verification (/domain-verification)

Requesting a DNS ownership challenge stores the submitted host, a randomly generated verification token, a status (pending or verified), and timestamps in our database. Whether your Google account ID is stored on that record is decided when you first request the challenge, not when you confirm it: if you are signed in at that moment, your account ID is bound to the record — so a different account cannot claim it, and the verified domain will appear on your Account page. If you request the challenge anonymously (signed out), no account ID is stored on it, and signing in only later, when you confirm the challenge, does not retroactively add one. Confirmation must still complete under that same account (a mismatched or absent session at confirmation is rejected), but it never adds an account ID that wasn’t already there. No other information about you or your site is collected by this feature. Each record is automatically deleted after its documented retention window: 24 hours for an unconfirmed challenge, or 30 days after a host is successfully verified.

Signing in with Google (optional)

/critique and /domain-verification work fully without an account. Where Google sign-in is enabled, it requests only your Google account ID and email address — never your password, contacts, files, or any other Google data. We store the Google account ID, email, and the times you first and most recently signed in until you delete the account from the Account page. That action deletes the account record, every verified domain attached to that account, any of your own still-pending (unconfirmed) domain challenges, and every critique report attached to that account. Signing in does not change what /critique or /domain-verification check or return.

IP address use

Every request’s IP address is used transiently, in memory only, for two purposes: rate limiting (to keep the free tools available for everyone) and country-based region gating (to keep functional tools unavailable in the EU/EEA/UK). Neither use writes your IP address to a database or any persistent store.

Cookies

If you never sign in, this site sets no cookies at all — every /critique and /domain-verification check works with no cookie of any kind. Where Google sign-in is enabled, one signed, HttpOnly session cookie is set, containing your account ID, email, and an expiry; it keeps you signed in and expires automatically after 14 days. A second short-lived cookie exists only during the sign-in redirect itself and is deleted within minutes. This site sets no advertising, analytics, or tracking cookies of any kind.

This notice describes current behavior only and is not a substitute for legal advice. See also the Terms page for the conditions that apply to using /critique.