AIWebSignalsobserve the machine web
Privacy and data practices

Privacy Policy

AIWebSignals is built to inspect public technical signals while minimizing unnecessary collection and keeping product claims proportional to observable evidence.

Effective August 18, 2026

What this policy covers

This policy explains how AIWebSignals handles information when you use aiwebsignals.com, the public scanner, reports, monitoring features, guides, and related services. AIWebSignals is designed for public-web analysis. Do not submit secrets, private network locations, authentication credentials, or information that you expect to remain confidential.

Information you provide

When you request a scan, you provide a public domain or URL. When you configure monitoring, you provide a public target, cadence, enabled or paused state, and related alert preferences. The service may also receive information you voluntarily include in a support request.

External email, webhook, and push notifications are not currently active, so AIWebSignals does not currently collect delivery destinations for those channels. In-app alert history and monitoring preferences may be stored when you use those features.

Information created by the service

The scanner retrieves bounded portions of publicly available pages and machine-readable resources such as robots.txt, llms.txt, and sitemaps. Raw downloaded page bodies are not stored. AIWebSignals stores normalized observations, findings, report identifiers, timestamps, monitoring configurations, execution state, and change history needed to provide the product.

Management capabilities are shown once to the user. Only a one-way hash of a management token is stored by the service. Public targets and normalized results should not be treated as private or confidential records.

Analytics

AIWebSignals uses Google Tag Manager and Google Analytics 4 to understand broad product usage and conversion steps. Application analytics are designed to use categorical events. Scanned domains, full target URLs, report IDs, configuration IDs, and management tokens are excluded from those event payloads. Google Analytics may use cookies or similar identifiers depending on browser, regional, and consent settings.

Advertising and cookies

AIWebSignals intends to use Google AdSense. When advertising code is enabled, third-party vendors, including Google, may place or read cookies, use web beacons, IP addresses, or other identifiers, and use advertising cookies to serve ads based on a user's visits to this site or other sites. Google and its partners may use this data to personalize advertising where permitted and consented.

How information is used

  • Provide scans, reports, monitoring, history, and the in-app alerts currently available to you.
  • Protect the service, enforce rate and capacity limits, investigate abuse, and maintain reliability.
  • Measure aggregate product usage and improve navigation, content, and conversion flows.
  • Meet legal obligations and enforce the Terms of Use.

Sharing and service providers

Information may be processed by infrastructure, analytics, advertising, security, and notification-delivery providers acting on behalf of AIWebSignals or under their own published terms. AIWebSignals does not sell scanned domains or management credentials. Information may also be disclosed when reasonably necessary to comply with law, protect users or the service, or address fraud and security incidents.

Retention and security

Normalized reports and monitoring records are retained while needed to operate history and monitoring features, until removed through available controls, or until operational cleanup. A fixed automatic deletion period is not currently promised. AIWebSignals uses bounded network access, public-address validation, key-based management, one-way hashes of management keys, and access controls intended to reduce risk. No internet service can guarantee absolute security.

Your choices

You may choose not to run a scan, may pause or delete a monitoring configuration using its management key, and may use available browser or Google controls for cookies and advertising. Losing a one-time management key may prevent the service from verifying authority over its associated configuration.

Children, changes, and questions

AIWebSignals is a general-audience technical service and is not directed to children under 13. We may update this policy as the product, advertising, notification delivery, or legal requirements change. Material updates will receive a new effective date. Use the Contact page for questions, and do not post sensitive or personal information in a public issue.

Connected AI traffic ingestion — effective August 31, 2026

When a site owner explicitly creates a connected AI traffic configuration, an authorized CDN, hosting platform, server, WordPress installation, or reverse proxy may send request-log deliveries to a scoped AIWebSignals collector. Raw delivery bodies are processed transiently for normalization and are not retained as raw log files.

Connected storage is intentionally limited to normalized automated-request evidence: timestamp, source, HTTP method, hostname, URL path without its query string, response status, classified provider and agent label, declared or inferred purpose category, identity-evidence level, and hashed request or session linkage when available. AIWebSignals does not persist client IP addresses, cookies, query strings, request bodies, raw user-agent strings, raw request IDs, authorization headers, or provider account API credentials for this feature.

Each connected configuration uses separate random ingestion and management keys. AIWebSignals stores one-way hashes of those capabilities rather than their plaintext values. The selected normalized-event retention period is between 7 and 90 days, with 30 days as the default. A valid management key can pause or delete the connection and its retained normalized events.

Connected traffic is first-party evidence supplied under the site operator's authority. Provider platforms that transmit the data remain subject to their own terms and data-handling practices. AIWebSignals analytics are not designed to receive connected hostnames, URL paths, connection IDs, ingestion keys, or management keys.

Agent Policy decision processing

When a site owner configures Agent Policy, AIWebSignals stores the policy configuration and a one-way hash of any scoped decision key. An authorized customer integration may submit minimized decision attributes such as HTTP method, URL path without query string, provider label, agent label, purpose category, and identity-confidence level. Decision request bodies and decision outputs are processed transiently and are not stored as traffic history.

Management keys and policy decision keys are not designed for analytics. A decision key is returned in plaintext only when it is issued or rotated; AIWebSignals stores its hash. Agent Policy does not require provider account API credentials and does not persist raw user-agent strings, client IP addresses, cookies, query strings, request bodies from the customer site, or private model prompts.

AI Revenue and x402 payments

Effective September 1, 2026. When a site owner enables AI Revenue, AIWebSignals may process x402 payment requirements, client payment authorization payloads, facilitator verification responses, and settlement responses for that owner's connected traffic configuration.

Payment authorization payloads and payer wallet addresses are processed transiently and are not persisted by AIWebSignals. Successful settlement evidence may retain the query-free resource path, network, asset, atomic amount, asset display metadata, settlement timestamp, and public transaction identifier so the site owner can reconcile measured machine-access revenue. Failed verification and failed settlement attempts are not counted as revenue.

AIWebSignals does not custody customer funds, payer funds, wallet private keys, seed phrases, or blockchain signing keys. Payment-facilitator credentials are kept separate from customer configurations and are never exposed to customers or payment clients.

Subscription and sponsorship data

AIWebSignals uses Square-hosted checkout for paid subscriptions. Square processes payment-card information; AIWebSignals receives only the identifiers and subscription state needed to provide paid access. We do not receive or store full payment-card numbers or card security codes.

If you submit a sponsorship inquiry, we store the company name, contact email, optional website, message, submission time, and inquiry status so we can respond to the request. Research and guide sponsorships are kept separate from product measurements and editorial conclusions.