Privacy Policy
Last updated: 20 August 2026
This policy covers Bot Appétit at scan.milkmoonstudio.com, a free tool operated by Milk Moon Studio (Pty) Ltd (“we”, “us”). It explains what we collect when you use the tool and what we do with it. For the rules of using the tool, see ourTerms of Use.
You do not need an account to run a single-page scan, and we do not ask for your name or email to run one. A multi-page site scan needs an account, because it takes several minutes and we need somewhere to send the result.
Accounts
If you create an account we store your email address, the identifier from whichever service you signed in with (or a secure form of your password), the sites you have added as projects, and any domains you have verified as yours. We use these to sign you in, to show you your own scan history, and to tell you when a scan you asked for is ready. We also add your email address to HubSpot, the tool we use to keep track of who uses Bot Appétit.
We do not sell any of this. You can delete your account at any time — emailjakes@milkmoonstudio.com — and your email address, sign-in details and projects go with it.
Scan results are not deleted with your account, because they were never stored against you in the first place. Scan results are never linked to who ran them: the history of an address shows what was found and when, not who asked. Two people scanning the same page moments apart produce two entries that look identical, because the result is a fact about that page — not about either of them.
What we send to Google when you scan
When you run a scan you give us a web address. To produce your results we fetch that page the way a search engine would, and we send that web address to Google, which provides two parts of the report:
- Google PageSpeed Insights — measures how fast the page loads.
- Google Safe Browsing — checks whether the page is flagged as unsafe.
Please do not submit a web address that is itself confidential — for example a password-reset link, an unlisted preview, or an address with a token or an email address in it — because the address is shared with Google as described above. Scan the public address of a page rather than a private link to it.
What we keep, and why
To understand how the tool is used, to improve our checks, and to see how sites change over time,we keep a record of each scan. That record includes:
- the web address you scanned, and the address it resolved to after any redirects;
- the results we produced — the overall score and the outcome of each individual check;
- general technical information about the request: approximate location (country and city), network provider, browser type (User-Agent) and language;
- which platform the scanned site appears to be built on (for example Webflow or WordPress);
- the date and time of the scan, and how long it took.
We do not store your IP address, with or without an account. Where we need to recognise repeat use or detect abuse, we convert your IP address into a one-way, irreversible code (a salted hash) that cannot be turned back into your address. We keep that code, not the address.
If your browser already carries our analytics cookies (Google Analytics or HubSpot — see “Cookies and analytics” below), we also record the identifier from those cookies with your scan, so we can tell how many separate people use the tool and recognise a returning visitor. This identifier comes from cookies that are already set; it does not name you, and we do not combine it with any contact details.
We rely on our legitimate interest in running, understanding and improving a free service as the lawful basis for keeping this information (section 11(1)(f) of POPIA; Article 6(1)(f) of the UK/EU GDPR). The records are not used to identify you as an individual, and we keep them for as long as the tool operates so we can measure change over time.
Scan links and page history
Every scan gets its own web address — a permalink — shown on the results page so you can save it or send it to a developer. Opening it shows that scan exactly as it was, without re-running it. These links do not expire, and anyone who has one can view that scan.
Results pages also show a history of the exact page scanned: earlier scans of that same address, with their dates and scores. This history is visible to anyone who scans, or holds a link to, that exact address — including scans run by other people. It covers only the one address, not the rest of the site.
Where we can tell from our analytics cookies that a scan was run in your browser, we may also show you other pages on the same site that you scanned. That list is shown only to you; other visitors never see which pages you scanned.
We only ever scan pages that are already publicly reachable, and we ask search engines and AI crawlers not to index scan links. If you would like a particular scan removed, emailjakes@milkmoonstudio.com with the link and we will delete it.
Copies of scanned pages
To test that our checks keep working correctly, we sometimes keep a copy of a page we scanned — the HTML and the small files a search engine would read, such as robots.txt. We keep these only where a page is different enough from ones we already hold to be useful as a test case, so most scans are never copied.
These copies are used solely to re-run our own checks against a page we have already seen, so we can tell the difference between our scanner changing and a website changing. They arenever published, shared, or made searchable, and we do not use them to train anything. We only ever copy pages that are already publicly accessible.
If you would like a copy of your page removed, emailjakes@milkmoonstudio.com and we will delete every copy we hold for your site.
Anti-abuse checks (Cloudflare Turnstile)
Before each scan we run an invisible check that confirms you are a real person using a real browser rather than an automated script. You will not see a puzzle or a checkbox. To do this, Cloudflare Turnstile processes your IP address, information about your browser’s secure connection, your browser type, and our public site key. Cloudflare states that it cannot identify you personally from this. We have not enabled Turnstile’s “pre-clearance” feature, so it does not place a clearance cookie on your device. Cloudflare describes this service in itsTurnstile Privacy Addendum.
Rate limiting
To keep the tool available, we count requests from your IP address over a rolling one-minute window and refuse requests above a set number. These counters are short-lived and are not used to identify you.
Cookies and analytics
We use Google Analytics, loaded through Google Tag Manager, to understand in aggregate how the tool is used. This sets cookies in your browser. We do not use these cookies to identify you personally, and we do not sell your data.
Who else is involved
The tool runs on Cloudflare, which serves the site, provides the anti-abuse check, and hosts the scan records described above. Google provides the performance and safety checks and the analytics. Each processes data on the terms of its own privacy policy.
Your rights
Under POPIA and the GDPR you have rights over your personal information, including to ask what we hold and to ask us to delete it.
If you have an account, you can ask us what we hold about you and ask us to delete it, and we can act on that directly.
If you scan without an account, the records we keep are not tied to you as a named individual — we hold no name, no email, and no reversible IP address — which can make a specific record impossible for us to single out. If you have a concern, contact us and we will help as far as we reasonably can.
Changes
We may update this policy. The date at the top changes when we do. Because the policy lives with the tool itself, it is kept current with what the tool actually does.
Contact
Milk Moon Studio (Pty) Ltd — jakes@milkmoonstudio.com