Privacy Policy
Broken Link Checker is operated by Norse Digital Group LLC, 30 N Gould St, Ste 56325, Sheridan, WY 82801, USA. This page explains what data we collect, why, how long we keep it, and what your rights are.
The short version: you can scan a website without an account. We store your IP address for rate limiting and the scan report for 30 days. With an account, we store your email, name and the data your tools need, such as tracked keywords and monitors. We do not sell personal data, we do not use it for advertising, and we do not use your data to train AI models.
Data we collect when you run a scan
You do not need an account for the free scanner. When you start a scan, we collect the URL you submit, your IP address, and basic technical data such as browser type and request time.
We use your IP address to enforce the free limits. Current free limits are listed on the pricing page.
What our crawler does
When you scan a website, our crawler visits the publicly available pages of that site. It follows internal links and the sitemap, then tests each link it finds. We collect URLs, HTTP status codes and anchor text. We do not collect personal data from scanned pages, and we store page content only as far as soft-404 detection requires.
Only scan websites you own or have permission to check. Our crawler identifies itself and respects standard crawling conventions. Details are on the crawler page.
Scan reports and public reports
Anonymous scan reports are stored for 30 days, then deleted. Reports on paid plans follow your plan's history limit, listed on the pricing page.
Each report has a shareable link. Anyone with the link can view the report without logging in, so do not share the link if the results should stay private.
Reports appear in the public reports list only when a PRO account holder publishes them. Published reports can be withdrawn at any time.
Recent scans of the same site may be served from cache. A scan you run can return results from a scan completed a few hours earlier, possibly started by someone else.
Account data
Creating an account is optional. If you register, we collect your email address for login and service messages, your name if you provide it, and a password hash. We never store your password in plain text.
Signing in with Google
If you sign in with Google, Google sends us your name, email address, profile picture and a Google account ID. We use this only to create and log you into your account. We never see your Google password and cannot access anything else in your Google account.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
Monitoring and tool data
Paid tools store the data you configure them with: monitored URLs and uptime history, tracked keywords and ranking history, brand names and prompts for AI visibility checks, and phone numbers you add for SMS alerts.
Ranking data is retrieved through DataForSEO based on the keywords and domains you track. Prompts and brand names you configure for AI visibility checks are processed in two ways: checks against Claude run through our AI provider Anthropic, and checks against other AI platforms, such as ChatGPT, Gemini, Perplexity, Copilot and Google AI Overviews, run through DataForSEO. Send only prompts you are comfortable sharing with these providers.
Chrome extension
The Broken Link Checker Chrome extension is a client for the same scanning service. It collects data only when you act, never in the background.
- Page URLs. When you start a scan, the extension sends the URL of the page in your active tab to our servers. It also keeps a short history of pages you scanned, with their results, in your own browser. We receive no other browsing data.
- Authentication. Signing in issues a one-time code and a per-device access token. The token is stored in your browser's extension storage. You can revoke it at any time under Account → Connected apps.
- Personal information. Your account email identifies you in the extension, exactly as on the website.
- Website content. Scan results contain links, anchor text and HTTP status codes from the pages you scan, as described in the crawler section above.
Extension settings such as theme, scan defaults and exclude patterns sync through your Chrome profile, not through our servers. Notifications are off until you turn them on. We do not sell or transfer this data, and we use it only to run the scans you request.
Payments
Paid plans are processed by Stripe. Stripe handles your card details, name, email and billing address. We never see or store your full card number. We store your Stripe customer ID and payment history to manage your subscription and support requests.
Emails and SMS we send
We send transactional messages only: account confirmation, password resets, billing receipts, and the alerts you configure, such as downtime or broken-link notices. SMS alerts are delivered through Twilio and go only to numbers you add yourself. We do not send marketing email without consent, and every non-essential email has an unsubscribe link.
Third-party data processors
| Service | What they process | Purpose |
|---|---|---|
| Name, email, profile picture | Optional sign-in | |
| Stripe | Name, email, billing details | Payment processing |
| Mementor AS | All service data | Hosting, infrastructure |
| Amazon SES | Email address, email content | Transactional email |
| Twilio | Phone number, message content | SMS alerts |
| DataForSEO | Tracked keywords, domains, prompts and brand names | Ranking data and AI answer checks |
| Anthropic | Prompts and brand names | AI answer analysis (Claude) |
Each processor is bound by a data processing agreement. If we add or change a processor, we update this page.
How long we keep data
- Anonymous scan reports: 30 days, deleted automatically
- Reports and histories on paid plans: per your plan limit
- Rate-limit records and server logs: 30 days
- Account data: while the account is active, plus 30 days after you close it
- Payment records: as long as tax and accounting law requires, typically 7 years
Your rights
Under the GDPR, and similar laws such as the CCPA, you can access the personal data we hold about you, correct data that is wrong, delete your data, export it in a portable format, object to or restrict processing, and complain to a supervisory authority. Closing your account triggers deletion.
Email privacy@brokenlinkchecker.io to exercise any right. We respond within 7 days.
Children
The service is not directed at children under 16, and we do not knowingly collect data from them.
Changes to this policy
We update this page when our data practices change. The date at the top always shows the latest revision. For material changes, we notify registered users by email.
Contact
Norse Digital Group LLC
30 N Gould St, Ste 56325
Sheridan, WY 82801, USA
privacy@brokenlinkchecker.io