Privacy Policy — llms.txt Studio
Operator: ChatLogic Insights Ltd, registered in England and Wales, company no. 15593166 · Applies to: llmstxt.echorank360.com · Effective: September 2026 · v1.0
llms.txt Studio generates and validates llms.txt files for domains you specify and, on the Monitor plan, checks them weekly. This policy explains what we hold about you and why.
1. What we collect
- Domains and URLs you submit, generated files, validation results and grades, and — for monitored domains — a stored copy of your
llms.txtused to detect change, drift findings, and alert history. - Public web content fetched from the domain you specify (pages, sitemap, robots.txt) to generate and check files. Our crawler identifies itself as
llmstxt-studioand respects robots.txt. - Canary fetch logs (Monitor, optional): if you enable the attribution link, we log the timestamp, user-agent string, and coarse network organisation of anything that fetches it, so you can see when your file was read. This shows fetches of the link, not people.
- Domain-verification records: the DNS TXT value or meta tag we check to confirm you control a monitored domain.
- Account data (required for Monitor): email address, password hash (never the password), creation date, subscription status and number of domain slots.
- Payment data: processed by Stripe; we receive a customer ID, amount, status, card brand and last four digits — never full card numbers.
- Technical data: IP address (as passed by Cloudflare), user agent, timestamps, request logs — for rate limiting, abuse prevention, security, and debugging. Free tools are limited per IP.
Google Sign-In. If you choose "Continue with Google", Google sends us your Google account email address, your name, and a stable account identifier (the OpenID sub). We use them only to create your llms.txt Studio account or sign you in, and to link your Google identity to that account. We request no other Google scopes: we never read, write, or post to your Gmail, Drive, Calendar, or any other Google service, and we do not receive your Google password. You can revoke our access at any time at myaccount.google.com/permissions; your llms.txt Studio account then remains usable with a password you set on the Account page.
2. Why, and on what legal basis (UK GDPR)
| Purpose | Basis |
|---|---|
| Generating, validating and monitoring files you request | Contract |
| Alert and account email you enabled | Contract |
| Billing, receipts, refunds, disputes | Contract; legal obligation (accounting records) |
| Rate limiting, security, abuse prevention | Legitimate interests |
We do not sell personal data and do not use it for advertising. Alert emails contain no marketing.
3. Processors
Cloudflare (proxy, TLS, cookieless analytics) · Stripe (subscriptions, customer portal) · Brevo (alert and account email) · RackNerd (hosting) · Google Identity, when you choose Continue with Google — we receive your Google account email, name, and a stable ID; nothing else. No AI model provider is used by this product. We disclose data if legally compelled and will tell you unless prohibited.
4. Shareable results
Free-tool results live at unguessable URLs; anyone with a link can view that result. Monitor dashboards require login.
5. Retention
- Free-tool runs: at least 30 days, then may be pruned.
- Monitored-domain data: for the life of the subscription, then 90 days in case you resubscribe, then deleted.
- Fetched page cache: up to 30 days.
- Account data: deleted or anonymised within 30 days of account deletion.
- Payment records: 7 years (UK tax law). Logs: up to 90 days.
6. Your rights
Access, correction, deletion, restriction, objection, portability, and — where consent applies — withdrawal. Email us from your account address; we answer within one month. Cancel subscriptions any time in the customer portal. You may complain to the UK ICO (ico.org.uk) or, in the EU/EEA, your local authority.
7. Cookies
Strictly necessary only: a session cookie when logged in and a short-lived token for forms and rate limits. No advertising or cross-site tracking. Cloudflare may set its own security cookies; analytics, where present, is Cloudflare's cookieless Web Analytics.
8. Transfers and security
Hosting is in the EU (Netherlands). Stripe, Brevo and Cloudflare may process data in the US under the UK IDTA/Addendum or SCCs. TLS everywhere, bcrypt password hashing, database bound to localhost, nightly rotated backups. If a breach affects your data we notify you and, where required, the ICO within 72 hours.
9. Children, changes, contact
Not intended for anyone under 18. Changes are posted here with a new version and date; subscribers are emailed for material changes. Contact: the support address in the site footer or on your receipt.