BoltAudit
Log In Sign Up Free

Privacy Policy

Effective date: 17 April 2026  ·  Last updated: 17 April 2026

Short version: We collect only what we need to run BoltAudit. We never read your WordPress users' data, customer data, or post content. Your payment is handled entirely by Paddle, who are the merchant of record.

Contents

  1. Who We Are
  2. What We Collect
  3. What We Do Not Collect
  4. How We Use Your Data
  5. Legal Basis (GDPR)
  6. Sub-Processors & Third Parties
  7. Paddle — Payment Processor
  8. Cookies
  9. Data Retention
  10. Your Rights
  11. Children's Privacy
  12. International Transfers
  13. Changes to This Policy
  14. Contact

1. Who We Are

BoltAudit is operated by HalalBrains ("we", "us", "our"). Our platform provides AI-powered performance and health audits for WordPress websites. Our services are accessible at boltaudit.com, app.boltaudit.com, and via the BoltAudit WordPress plugin.

For data protection enquiries, contact us at privacy@boltaudit.com.

2. What We Collect

2.1 Account Data

When you register for BoltAudit, we collect:

  • Your email address
  • Your name (optional)
  • A hashed password (we never store your password in plain text)

2.2 Site Metadata

When you connect a WordPress site, the BoltAudit plugin sends aggregate, structural information about your site. This includes:

  • WordPress version, PHP version, and server software
  • List of installed plugins and themes (names, versions, active/inactive status)
  • Database table names, sizes, and row counts — not table contents
  • PHP and server configuration values (memory limits, execution time, etc.)
  • Post type counts and taxonomy counts — not post content or titles
  • HTTP response headers and file permission flags

This data is used solely to generate your audit report and is never sold or shared with third parties for marketing purposes.

2.3 Billing Data

We store your subscription status, plan metadata, and references to Paddle transaction IDs. We do not store card numbers, CVVs, or any payment instrument details — all payment processing is handled by Paddle (see Section 7).

2.4 Usage Data

We log which audit types you run, timestamps, audit scores and grades, and model usage metrics. This powers your score history, trend charts, and weekly digest emails.

2.5 Technical Logs

Our Cloudflare Workers infrastructure automatically records request logs including IP addresses, HTTP method, path, status code, and response time. These logs are retained for 30 days for security and debugging purposes.

3. What We Do Not Collect

The following data never leaves your WordPress site and is never transmitted to BoltAudit servers:

  • WordPress user email addresses, usernames, or passwords
  • Post or page content, titles, or body text
  • WooCommerce customer names, addresses, or order details
  • Any database row content (only structure is transmitted)
  • The contents of wp-config.php (only specific safe constants such as WP_DEBUG)
  • Any personally identifiable information about your website's visitors

4. How We Use Your Data

DataPurpose
Email addressAccount login, audit completion notifications, weekly digest, security alerts
Site metadataGenerating AI audit reports and scores
Billing recordsSubscription status, transaction history, invoicing
Usage dataScore history, trend charts, digest emails, platform improvements
Technical logsSecurity monitoring, debugging, abuse prevention

We do not use your data for advertising, do not sell it, and do not use it to train AI models.

5. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, our legal bases for processing personal data are:

  • Contract performance (Art. 6(1)(b)): Processing your account data and site metadata is necessary to deliver the audit service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): Security logging and abuse prevention serve our legitimate interest in protecting the platform and our users.
  • Legal obligation (Art. 6(1)(c)): We retain billing records as required by applicable tax and financial regulations.
  • Consent (Art. 6(1)(a)): Marketing emails and weekly digests are sent only with your explicit opt-in. You can unsubscribe at any time.

6. Sub-Processors & Third Parties

We rely on the following third-party service providers to operate BoltAudit:

ProviderPurposeLocationData Shared
Cloudflare, Inc.Infrastructure — Workers, D1, R2, KV, Pages, CDNUnited States (global edge)All data transits and is stored on Cloudflare infrastructure
Anthropic, PBCAI engine — Claude API for audit analysisUnited StatesSite metadata sent as prompt context; Anthropic does not train on API inputs by default per their usage policy
Paddle.com Market LtdPayment processing and Merchant of RecordUnited KingdomEmail address, purchase amount, product details; card data handled entirely by Paddle

We do not share your data with any other third parties without your explicit consent, except as required by law.

7. Paddle — Payment Processor

BoltAudit uses Paddle.com Market Ltd as its payment infrastructure provider. Paddle acts as the Merchant of Record for all BoltAudit purchases, which means:

  • Paddle is the legal seller on your receipt and invoice, not BoltAudit directly.
  • Paddle collects and processes your payment information (card details, billing address) under their own Privacy Policy.
  • Paddle is responsible for sales tax and VAT calculation and remittance.
  • Any payment dispute or chargeback is handled through Paddle's support.

You can review Paddle's Privacy Policy at paddle.com/legal/privacy. When you complete a purchase, you also agree to Paddle's Buyer Terms at paddle.com/legal/checkout-buyer-terms.

BoltAudit receives from Paddle only: confirmation that a payment succeeded, the transaction ID, the subscription plan purchased, and the email address you used at checkout.

8. Cookies

The marketing website (boltaudit.com) sets no cookies. There is no analytics, advertising, or tracking on the marketing site.

The app (app.boltaudit.com) sets a single session cookie (ba_session) to maintain your logged-in state. This cookie:

  • Contains your authentication token (JWT)
  • Is marked HttpOnly and Secure
  • Expires when you log out or after 7 days of inactivity
  • Is not used for tracking, advertising, or analytics

No consent banner is displayed on the marketing site because no cookies are set. The app session cookie is strictly necessary and does not require consent under ePrivacy regulations.

9. Data Retention

Data TypeRetention Period
Account dataFor the lifetime of your account, then 30 days after deletion request
Audit reports12 months from the date of the audit; older reports are purged automatically
Billing records7 years (required for tax compliance)
Request logs30 days
Session tokens7 days from last activity

10. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of all personal data we hold about you.
  • Rectification: Ask us to correct inaccurate or incomplete data.
  • Erasure ("right to be forgotten"): Request deletion of your account and associated data, subject to our legal retention obligations for billing records.
  • Portability: Receive your account data in a machine-readable format (JSON).
  • Restriction: Ask us to pause processing while a dispute is resolved.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Unsubscribe from marketing emails at any time via the link in any email we send, or by emailing us.

To exercise any of these rights, email privacy@boltaudit.com. We will respond within 30 days. If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority (UK: ICO; EU: your national DPA).

11. Children's Privacy

BoltAudit is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us at privacy@boltaudit.com and we will delete it promptly.

12. International Data Transfers

BoltAudit's infrastructure runs on Cloudflare's global network. Data may be stored and processed in data centres outside your country, including in the United States. Where data is transferred from the EEA or UK to a third country, we rely on Cloudflare's and Anthropic's Standard Contractual Clauses (SCCs) as the transfer mechanism. You can request details of these safeguards by emailing privacy@boltaudit.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. For material changes, we will notify you by email at least 14 days before the change takes effect. Continued use of BoltAudit after notice of a material change constitutes your acceptance of the updated policy.

14. Contact

For any privacy-related questions, data requests, or complaints:

  • Email: privacy@boltaudit.com
  • General enquiries: hello@boltaudit.com
BoltAudit

Performance-first WordPress audit platform.

Product

Features Performance Scope Pricing How It Works

Platform

Sign Up Log In WordPress Plugin

Legal

Privacy Policy Terms of Service Refund Policy

Company

GitHub Contact

© 2026 BoltAudit by HalalBrains. All rights reserved.  ·  Privacy  ·  Terms  ·  Refunds