Privacy Policy

Updated 18 September 2026

This policy describes what personal data Torumata processes, why, and what rights you have.

The data controller is Hatteria labs s.r.o., company ID (IČO) 29938589, registered at Klatovská třída 2308/172, Jižní Předměstí, 301 00 Plzeň, Czech Republic. Contact for privacy matters: support@torumata.com.

Account data: your email address and your identifier in Keycloak, the identity provider we run ourselves.

Audit data: the domain you submit, the content of the pages the crawler downloads, and the results of the analysis: score, findings, and generated files.

Technical data: the IP address at registration, to protect the form against abuse, and the NEXT_LOCALE cookie holding your language choice.

At registration: if you arrived via a link with campaign parameters (utm_source, utm_medium, utm_campaign, etc.), we store this source against your account, from your URL's parameters only, without cookies and without any third-party identifier (e.g. Google's gclid). It is stored once, at registration, and never updated afterwards.

If you sign in with Google, we learn your email address and account identifier from Google. Google in turn learns that you are signing in to Torumata; we never receive your password or other data from your Google account.

We process account and audit operation to perform the contract (these Terms).

We process technical protective measures, such as request-rate limits, on the basis of legitimate interest: protecting the service against abuse.

We measure traffic on the public pages on the basis of legitimate interest: we need to know which pages people use. The measurement runs without cookies and without identifying a particular person (see Traffic measurement).

Page content from a paid audit is sent through OpenRouter, Inc. (USA) to language models from OpenAI, Google and Anthropic: page text for the content analysis and the language check, and page screenshots for the colour review. OpenAI models run on Microsoft Azure, Google models on Google Cloud, and Anthropic models on Google Cloud or Amazon Web Services. Which model receives the content depends on which one is currently available and whose maker the audited site has not blocked in robots.txt. The AI citations module also sends language models short queries derived from the titles and headings of the site's pages, not the page content; the model searches the web for sources to answer them. Since 18 September 2026 there are four such channels running side by side. For the OpenAI model, OpenAI itself does the searching, in a data centre in the European Union, and for the Google model, Google itself does the searching, likewise in the European Union. For the Anthropic model, since 17 September 2026 Anthropic itself does the searching, but only at its endpoint in the United States: its search is available nowhere else, so these queries leave the European Economic Area. The fourth channel uses the search engine of Exa Labs Inc. (United States), with a model running in the European Union merely composing an answer from its results; these queries therefore also leave the European Economic Area. For answers from the Google model we additionally check where the source links lead: Google returns them as redirects through a domain of its own, so we send that domain a request for the response headers, without downloading any content. This is a required part of the content analysis, not an optional add-on. The free audit does not use a language model.

Email delivery and backup storage are handled by Forpsi (the support@torumata.com mailbox and external S3 backups). Sign-in runs on our own self-hosted Keycloak. Payments are processed by Armitage Labs OÜ (Creem, Estonia) as the Merchant of Record. At purchase we pass it your email address, our internal identifier of your account and the order details (which pack you are buying and for how much); payment card data is processed solely by Creem and never reaches us. For these purposes Creem is a controller under its own privacy policy.

Creem is based in Estonia, within the European Union; according to its privacy policy, where it uses service providers outside the EEA it covers them with safeguards such as the standard contractual clauses.

The language models run in data centres in the European Union. Each request, however, is first received by the OpenRouter service, based in the United States, on infrastructure that need not be in the EU, so we do not claim that the data never leaves the European Economic Area. Queries in the AI citations module that go to the Anthropic model have, since 17 September 2026, demonstrably left the European Economic Area: Anthropic's native search runs only at its endpoint in the United States. Since 18 September 2026 the same applies to the channel where Exa Labs Inc. in the United States does the searching. What leaves is the query itself and the domain name, not your page content or screenshots. According to its documentation, OpenRouter does not store request content by default and stores only metadata such as the number of tokens and the response time. According to OpenRouter's data, Microsoft Azure, Google Cloud and Amazon Web Services do not retain request content or use it to train models. The transfer to OpenRouter relies on the European Commission's standard contractual clauses under Article 46(2)(c) GDPR, which OpenRouter refers to in its privacy policy; as of 17 September 2026 OpenRouter is not listed under the EU-US Data Privacy Framework.

Raw HTML content from crawled pages is deleted 30 days after the audit. Scores, findings, and generated files remain stored until you delete the project or account; deleting a project or account deletes the associated data too.

The IP address from the registration and sign-in forms lives only as a counter in Redis valid for at most one hour (the rate-limit window); it is not stored permanently. The campaign data you arrived with (utm_source and the rest) is attached to the account and is deleted together with it.

Under the GDPR you have the right to:

  • access the data we hold about you
  • correct inaccurate data
  • erase your account and related data
  • port your data to another provider
  • restriction of processing
  • object to processing based on legitimate interest

Exercise these rights via support@torumata.com. If you believe processing violates the GDPR, you can file a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz).

We use only technical cookies necessary to run the service: language choice (NEXT_LOCALE) and the sign-in session. We use no marketing or analytics tracking cookies.

We measure site traffic with Umami, which we run ourselves on our own server; the data never leaves our infrastructure and we don't pass it to anyone.

Umami doesn't use cookies. It records the page visited, referrer, browser, operating system, device type, and country of origin. It uses the IP address only as one input into a hash together with the user agent and the domain. The resulting session identifier changes periodically (monthly by default), and the IP address itself is not stored in the database.

We respect your browser's Do Not Track setting: if you have it enabled, we don't measure you at all. Measurement doesn't cover the signed-in part of the app (the dashboard and administration), only the public pages.

We never store or process passwords; Keycloak alone manages them. Access to data is limited to what running the service requires.