Last updated: September 2026
To crawl and fix your site, Crawlmend requests access to: your GitHub repository (via OAuth, scoped to read code and open pull requests — Crawlmend never pushes directly to a branch and never auto-merges), your Google Search Console property (read-only performance data: impressions, clicks, and position), and your site's public PageSpeed data.
We store your account details (name, email, a salted hash of your password — never the password itself), connected repo and Search Console property identifiers, crawl results and the SEO opportunities derived from them, the pull requests Crawlmend has opened on your behalf, and a record of which AI-assisted actions your account has used. We do not store your source code beyond what is needed to generate and display a diff.
Your GitHub and Google Search Console access tokens are stored encrypted and are used only to make the specific API calls described above.
We use PostHog to understand how the product is used — which pages get visited, where people drop off during signup, and which features (crawling, generating a fix, opening a pull request) get used and how often. For a signed-in account, these events are tied to your account so we can see a full journey (for example: signed up → connected GitHub → ran a crawl → opened a pull request) rather than anonymous, disconnected page hits.
We do not use this data to build advertising profiles, and we do not sell it. It is used to decide what to build and fix next, and to see where the product is confusing or broken.
Crawlmend sets a session cookie to keep you signed in, and short-lived cookies during a GitHub or Google OAuth connection to prevent request forgery. PostHog sets its own cookie to recognize repeat visits from the same browser. None of these are used for third-party advertising.
We use Grafana Cloud to monitor the health of the service — request rates, error rates, response times, and system logs. This is operational data about our servers, not a record of your personal browsing; log entries can include technical details like an IP address and the API path called, kept only long enough to debug and resolve incidents.
We don't sell your data. We share it only with the providers that run the product on our behalf:
Crawl history and opportunity data are retained for as long as your account is active. You can disconnect your GitHub or Search Console connection, or delete your account entirely, from Settings at any time — this removes stored crawl data and revokes our access. Analytics events already recorded in PostHog are not automatically deleted when you delete your account; email privacy@crawlmend.com to request their removal.
You can review, correct, export, or delete your account data at any time from Settings, or by emailing privacy@crawlmend.com. If you'd rather we didn't track product usage against your account, email us and we'll exclude it going forward.
Crawlmend is a developer tool and is not directed at, or knowingly used by, children under 16.
If we materially change what we collect or how we use it, we'll update the date at the top of this page and, for significant changes, notify active accounts by email.
Questions about this policy, or a request about your data: privacy@crawlmend.com
This page describes Crawlmend's actual data practices in plain language. It has not been reviewed by a lawyer and is not a substitute for legal advice — have it reviewed before it needs to satisfy a specific law (e.g. GDPR, CCPA) that applies to your users.