Last updated: September 2026
This policy describes what Winking Toad ("we," "our," "the Service") collects when you use winkingtoad.com, why we collect it, and who we share it with. We've written it to describe what the application actually does, not generic boilerplate.
1. What we collect
Account information
- Username, email address, and a hashed password (we never store your password in plain text).
- Account tier and subscription status, and — once billing is enabled — a customer and subscription identifier from our payment processor.
- A usage-credit balance and a log of credit grants/deductions, for paid usage-metered features.
Crawl data
- The URLs, titles, meta tags, headings, structured data, links, images, and other page content of any website you choose to crawl using the Service. This is stored so you can view, export, compare, and schedule crawls of your own sites.
- If you crawl a site you don't own or control, that site's publicly-visible page content is stored the same way. Don't use the Service to crawl sites you're not authorized to crawl.
Third-party connections you set up yourself
Some features require you to connect a third-party account. We only use these credentials for the specific action you request, and only against the site/account you provide:
| Feature | What's stored | What it's used for |
|---|---|---|
| Shopify Apply Fix | Shop domain, Admin API access token | Reading/updating the product data you approve in the review table |
| WordPress Apply Fix | Site URL, username, Application Password | Reading/updating the post/page data you approve in the review table |
| MCP access | A hashed API key (the raw key is never stored) | Authenticating your own MCP client (e.g. Claude Code, Cursor) to your own crawl data |
| Google Search Console | An OAuth token issued by Google, scoped to read-only Search Console data | Showing your real search impressions/clicks alongside crawl issues on the same URLs |
Usage of AI features
Features like AI Visibility and Prompt Explorer send a question you type (or a generated buyer-style question about a category you specify) to Google's Gemini API to get a real AI-generated answer. We don't send your crawl data, account details, or website content to these APIs unless it's part of the specific text you're asking about.
Automatically collected information
- IP address, for rate-limiting guest (non-account) crawls and basic abuse prevention.
- Standard server logs (timestamps, requested paths, response codes) for operating and debugging the Service.
- A session cookie, required to keep you logged in. We don't use third-party advertising or tracking cookies.
2. Why we collect it
To operate the core features of the Service (crawling, storing and displaying your results, letting you export or schedule crawls), to authenticate you and maintain your account, to process payment once billing is enabled, to prevent abuse of the free tier, and to provide the optional AI-powered and third-party-connected features described above — only when you actively use them.
3. Who we share it with
We don't sell your data. We share it only with:
- Google (Gemini API) — the text of AI Visibility/Prompt Explorer requests you initiate, per Google's privacy policy.
- Google (Search Console API), if you connect it — to read your own Search Console performance data with your explicit OAuth authorization, which you can revoke at any time from your Google Account settings or by disconnecting it in the app.
- Shopify or WordPress, if you connect them — only the specific site you provide credentials for, only for the actions you approve.
- Our payment processor, once billing is enabled, to process subscription payments. We do not store your card details ourselves.
- Law enforcement or legal process, only if legally required.
4. Data retention and deletion
We retain your account and crawl data for as long as your account is active. If you want your account and associated data deleted, contact us using the details below and we'll delete it, other than records we're legally required to retain (e.g. billing records).
5. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these, contact us using the details below.
6. Security
Passwords are hashed with bcrypt, never stored in plain text. API keys and access tokens you provide (Shopify, WordPress, MCP) are used only for the connection you set up. We use HTTPS for all traffic to the Service. No online service can guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.
7. Children's privacy
The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
8. Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above and, where required by law, notify account holders directly.
9. Contact
Questions about this policy, or requests to access, export, or delete your data, can be sent to privacy@winkingtoad.com.
← Back to Winking Toad