sitesfor.ai — Policy & security ================================ Last updated: 2026-06-23 Canonical: https://sitesfor.ai/policy.txt This file is a plain-text combination of the privacy policy and the security disclosure contact for sitesfor.ai. It opens in any browser tab as a text file, and AI assistants can ingest it directly. For the machine-readable RFC 9116 security.txt with Expires and Canonical fields, see https://sitesfor.ai/.well-known/security.txt. ---- Privacy policy ---- Data controller --------------- Alexander Poplavsky Solutions, operating sitesfor.ai. Registered in Poland, EU; operates globally. DPO contact: contact@poplavsky.solutions. Tracking cookies ---------------- We set none. No analytics tags, no advertising pixels, no embedded third-party JavaScript of any kind. There is no cookie banner because there is nothing to consent to. What we observe (not personal data) ----------------------------------- The Checker scans URLs you give it. Websites are public information; the privacy framework that applies to user data does not apply to scan inputs or scan outputs. One anonymised row per scan is kept in our corpus — URL, signal results, score, optional self-classified vertical, and timestamp — to power the percentile and per-signal rarity columns of subsequent reports and the aggregate AI Readiness Index. Reports themselves are ephemeral; they are returned inline as the HTTP response body and discarded after the request. AI Readiness Index ------------------ The Index on the homepage publishes only aggregate, anonymised, and deduplicated statistics rolled up from the scan corpus. No individual domain or its score is ever shown publicly. An individual report is private to the user who ran the scan. Outbound scans -------------- When you submit a URL we fetch it from our infrastructure with the sitesforai-scanner/1.0 user-agent. The Checker is user-initiated — one URL per click, rate-limited 10 per IP per UTC day — and behaves like a single browser fetch, not an unattended crawler. We therefore do not gate scans on the target's robots.txt: a user typing a URL into /check has clear intent comparable to opening that URL in their browser. AI-bot user-agents we GRADE against (GPTBot, ClaudeBot, Bingbot, ...) do honour robots.txt because they crawl at scale; our scanner does not. We refuse to scan internal addresses (RFC1918, loopback, link-local, cloud metadata, IPv6 unique-local) — the SSRF guard rejects those with HTTP 403 before any fetch is issued. Updates to this policy ---------------------- We update this artifact as the product evolves. The current version is the canonical statement; older versions are kept in git history. ---- Security ---- Contact: mailto:contact@poplavsky.solutions Preferred-Languages: en, pl Hiring: https://sitesfor.ai/#contact Reachable AI-agent surfaces: https://sitesfor.ai/.well-known/security.txt (RFC 9116) https://sitesfor.ai/.well-known/mcp.json (MCP discovery) https://sitesfor.ai/sitesfor.acp.json (ACP feed — studio catalogue) https://sitesfor.ai/sitesfor.openapi.json (OpenAPI 3.1) https://sitesfor.ai/llms.txt (concise AI summary) https://sitesfor.ai/llms-full.txt (extended AI summary)