Privacy Policy

Last updated: June 25, 2026

This page is maintained by AI Grader by Magnetic WP to explain how we handle personal data when you use our website and the AI visibility scanner. It is written with the EU General Data Protection Regulation (GDPR) and the UK GDPR in mind.

1. Who we are

AI Grader by Magnetic WP ("we", "us") operates the magneticwp website and scanner. For GDPR purposes we act as the data controller for the personal data described below. You can reach us at privacy@magneticwp.com.

2. What we collect

  • Account data — when you sign in, we store your email address and an authentication identifier from our auth provider.
  • Scan data — the URL you submit, the public HTTP responses we fetch from it, and the resulting score and report.
  • Usage data — basic logs (IP address, user agent, timestamp) used to prevent abuse and operate the service.
  • Cookies — see Section 6.

3. Legal bases (GDPR Art. 6)

  • Contract — to run the scan you requested and provide your account.
  • Legitimate interests — service security, abuse prevention, product analytics.
  • Consent — for non-essential cookies and marketing emails. You can withdraw consent at any time.
  • Legal obligation — when we must retain or disclose data to comply with law.

4. How we use data

  • To run scans and show you the results.
  • To provide your account, dashboard, and billing.
  • To improve our checks, scoring, and reports.
  • To detect, prevent, and respond to abuse or security issues.

5. Sharing & sub-processors

We share data only with vetted sub-processors who act on our behalf:

  • Cloud hosting and database (managed backend infrastructure).
  • Email delivery (transactional sign-in and report emails).
  • AI provider (to generate plain-English fix lists from scan results — only the technical scan data is sent, never your account email).

We do not sell personal data.

6. Cookies

We use a small number of cookies and similar storage:

  • Strictly necessary — sign-in session, security, and saving your cookie choice. Always on, no consent required.
  • Analytics — only loaded after you click "Accept" on the cookie banner. Used to understand which pages and checks people use.

You can change your choice at any time by clicking "Cookie settings" in the footer or clearing the mw_cookie_consent entry in your browser.

7. International transfers

Some sub-processors are located outside the EEA/UK. Where this applies, transfers rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent UK IDTA safeguards.

8. Retention

  • Account data: while your account is active and up to 12 months after deletion for backups and legal records.
  • Scan results: until you delete them, or 24 months for public scans.
  • Server logs: up to 90 days.

9. Your rights (GDPR Art. 15–22)

You have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. You can also lodge a complaint with your local supervisory authority. To exercise any right, email privacy@magneticwp.com and we will respond within 30 days.

10. Security

Data in transit is protected with TLS. Authentication uses your provider's standard token flow. Row-level security is enabled on user data tables.

11. Changes

If we change this policy materially, we will update the "Last updated" date and, where required, notify you by email or in-app.

See also: Terms of Service.