Last updated 19 August 2026
The short version: we store your domain, whether it has a plan, and a count of how much you have used. We store your name and email only when you claim a website — never otherwise. We never store the pages you submit or the posts we write. There are no analytics and no advertising trackers on this site.
The registered domain — example.com, not the full URL you pasted — with its plan and
expiry, whether the free set is spent, and how many sets have been generated. Subdomains are
reduced to the site they belong to, so we never store which particular page you submitted.
A reference to your Paddle subscription, plus the plan and the status Paddle reports for it. We re-check that status with Paddle so a cancellation or refund takes effect. We never see or store your card. Your browser holds only an opaque session token, which grants nothing on its own.
Claiming a website means giving your name and email as you prove you own it. We store them, linked to that website, for one purpose: to email you a one-time sign-in link, so you sign in with a link rather than proving the domain by DNS on every device. We never send anything else to that address — no marketing, no newsletters. Sign-in links are sent through Resend, our email provider. One email is tied to one website, so a second site means a second email and the two are never joined. You can try the free set without giving an email at all, and you can ask us to delete your account and email at any time.
A one-way HMAC hash of your IP address with a counter attached. Never the address itself, and the hash cannot be reversed. The counters delete themselves after an hour, a day or a week.
Running this service means a few other companies are involved. Each one, and why:
| Who | What they receive | Why |
|---|---|---|
| OpenAI | The text of the page you submitted, and your notes | To write the posts. Sent through their API, under whichever data policy OpenAI applies to API traffic — we do not control it, so read theirs if it matters to you. |
| Upstash | Domain records, subscription references, hashed-IP counters | The database this all lives in. |
| Vercel | Ordinary web request data, including your IP | Hosting. Standard server logs. |
| Paddle | Your payment and billing details, and the website address the plan is for | They are the merchant of record: they take the payment, handle tax, and own cancellation. We never see your card. Their checkout script loads only when you open it. |
| Resend | Your email address, and only once you have claimed a website | To deliver your one-time sign-in link. No marketing, ever. |
| Cloudflare | A bot-check signal, and your IP, when Turnstile runs | To stop automated abuse of the free tier. Its script loads on the page; paid use is never challenged. |
Exactly the one URL you give us — not your sitemap, not other pages, nothing linked from it. The
crawler identifies itself as PostForSiteBot, refuses private network addresses, and
does not try to get past logins or paywalls.
Please only submit pages you are entitled to process. If a page is confidential, do not paste it here.
We store that the website was claimed and when. Which account it belongs to is recorded against the email you claimed with — nothing is stored about the browser or device you used, and no per-device token is kept.
Anyone can type any address into this tool, so we are careful about what the answer reveals. A website is only ever shown as one of two things: available for a free set, or already in use. That looks exactly the same whether the free set has simply been used or the site is on a paid plan — we never say which, which plan, when it renews, or how much of the allowance is left.
Sign in to the website and the real state appears for you. That way the address bar cannot be used to find out which businesses pay for their tools.
At most two, and only once you sign in or buy a plan: pfs_account, set when you
click a sign-in link, and pfs_session, set when a payment completes. Each holds a
long random token and nothing else. The token is meaningless on its own — it is matched to your
account on our side, so anyone reading the cookie learns nothing about you from it.
Both are HttpOnly (scripts cannot read them, so a cross-site script cannot steal them), Secure (sent only over HTTPS) and SameSite=Lax. They say which account you are signed in to; they carry no payment details and cannot change your billing, which lives with Paddle. Signing out deletes the session behind the cookie. There are no tracking or advertising cookies — which is why there is no cookie banner. There is nothing to consent to.
Email support@postforsite.com and we will tell you what is held against your domain and your email, correct it, or delete it. Deleting a paid domain's record ends its access, so we will check first.
If what we store or who receives it changes, the date at the top changes with it.