SiteRep Privacy Policy

A product of Bearz Solutions LLC

Effective Date: July 7, 2026 · Version 1.0 · U.S. & Asia-Pacific Edition

This Privacy Policy explains how Bearz Solutions LLC ("Company," "we," "us," or "our"), a Florida limited liability company, collects, uses, discloses, and protects personal data in connection with the SiteRep application — including the SiteRep mobile applications (iOS and Android), the SiteRep web application at siterep.bearzsolutionsllc.com, the SiteRep browser and Safari extensions, the SiteRep WhatsApp bot, and any associated APIs (collectively, "SiteRep" or the "Application"). It is a product-specific supplement to, and incorporates by reference, the Bearz Solutions LLC Master Terms of Service and its SiteRep Schedule. Other Bearz Solutions products are governed by their own privacy notices. This version of the Privacy Policy applies to users in the United States and the Asia-Pacific region. SiteRep is not offered or directed to individuals in the European Economic Area, the United Kingdom, or Switzerland, and is not intended for use by such individuals.

Your use of SiteRep constitutes acceptance of this Policy. If you do not agree, do not use the Application.

Quick Summary — Notice at Collection

This summary is provided for convenience and does not replace the full Policy below.

What we collectWhyDo we sell/"share" it?
Account data (email, optional display name, phone number), SSO identifiers, month and year of birthCreate and secure your account; authentication; account recoveryNo
URLs, links, and pages you submit (and, if you enable it, pages auto-scanned by the Safari extension)Core function: evaluate website trust and return a verdictNo
Device & technical data, IP address & approximate location, per-install identifierSecurity, rate limiting, fraud prevention, region-aware resultsNo
Usage & analytics dataOperate, debug, and improve the ApplicationNo
Payment identifiers (via Stripe)Process paid subscriptionsNo

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising or process it for targeted advertising, as those terms are defined under U.S. state privacy laws. Because we do not sell or share your data, an opt-out preference signal such as Global Privacy Control (GPC) has nothing to act on; we will honor such signals to the extent they apply to us. See Sections 5 and 9.

1. Information We Collect

1.1 Information You Provide Directly

Account Authentication, SSO, and Recovery

  • Email/password registration: your email address, an optional display name, and your mobile phone number, which you provide during account registration. Passwords are stored only as a cryptographically hashed value using an industry-standard one-way algorithm; we never store, log, or transmit your plaintext password.
  • Month and year of birth: collected during registration to confirm you meet the applicable minimum age, to determine whether you are an adult or a minor for Family Plus features, and to apply the transition to adult status when a minor member reaches the age of majority (see Sections 1.1 "Family Plan Safety Notifications" and 11). We collect only the month and year, not your full date of birth, and we rely on the information you provide without independently verifying it.
  • Sign in with Google: your Google account identifier, Google-verified email address, display name, and profile avatar URL. We never receive your Google password.
  • Sign in with Apple: your Apple account identifier and the email (real or Apple relay) associated with your Apple ID. We never receive your Apple password.
  • Account recovery and email verification: short-lived one-time passcodes (OTPs) sent via our transactional email provider. OTPs expire automatically and are not retained after use.
  • Family subscription groups: the email addresses of co-members and your role within the group, if you join or are invited to a Family plan. If your Family Plus plan has safety notifications turned on, we also process limited verdict information about other members of your group in order to alert the primary account holder, as described under "Family Plan Safety Notifications" below.

Family Plus Safety Notifications (Family Plus plan only)

Safety notifications are available only on our top-tier Family Plus plan; the standard Family plan does not include them. If you use a Family Plus plan, the plan owner (the primary account holder) can enable safety notifications for the group. When this feature is on and a group member submits a URL, link, or page (or, where that member has enabled automatic page scanning, has a page auto-scanned) that returns a "Risky" or "Restricted" verdict, we send a real-time alert to the primary account holder; "Suspicious" verdicts are not sent as individual alerts and are instead summarized once per day. We never notify the primary account holder of "Safe" results, and the feature never provides access to a member's full browsing activity or complete scan history. What we share depends on the severity of the verdict:

  • Suspicious: not sent as an individual alert. Suspicious results are collected into a once-daily summary to the primary account holder that lists, for each member, the registered domain of each Suspicious result from that day (for example, "example.com") — not the full path, query string, or page-specific parts of the URL.
  • Risky: a real-time alert containing the member, the verdict level, a timestamp, and the registered domain only (for example, "example.com") — not the full path, query string, or page-specific parts of the URL.
  • Restricted: a real-time alert containing the member, the verdict level, a timestamp, and the registered domain only (for example, "example.com") — not the full path, query string, or page-specific parts of the URL. Because this is our highest-severity verdict — and to avoid keeping a lasting record of a Restricted site — the alert is available in the primary account holder's in-app notification history for 24 hours and is then automatically deleted; it is not added to the member's scan history and is not retained beyond that 24-hour window.

Each member can see, within the Application, exactly what has been sent about them. Consent works differently depending on the member: adult members (18 or older) must opt in to be included in safety notifications and may opt out at any time in their settings; members who are minors (at or above the minimum age in Section 11) are included in safety notifications for the group and cannot opt out, and the primary account holder is responsible for holding any authority required under applicable law to receive a minor member's notifications. When a minor member reaches 18 (or the age of majority where they live), we treat them as an adult member: notifications about them are paused until they opt in, and they may opt out at any time. We rely on the age, identity, and relationship information that members and the primary account holder provide, and we cannot independently verify it. Every member is told that safety notifications are part of the plan when they join or are added. This feature is intended for families and similarly trusted groups and is not designed for covert monitoring. All Family plan members must meet the minimum age described in Section 11.

Payment Information

Payments are processed exclusively by Stripe, Inc. We never receive, store, or transmit raw card numbers, CVCs, or banking credentials. We retain only the Stripe customer ID, subscription ID, plan tier, status, and renewal period returned to us by Stripe.

Communications and Support

We collect communications you send us, including support requests and feedback.

Mobile Push Notifications

For the mobile applications, we collect device push-notification tokens used solely to deliver notifications you have enabled.

WhatsApp Bot

If you use the SiteRep WhatsApp bot, we collect your phone number to associate your bot conversations with a usage counter and, if you later sign in, to link prior bot analyses to your account.

1.2 Information Collected Automatically

1.2.1 URLs, Links, and Content Submitted for Analysis

When you submit a URL, link, or web page for analysis, that content is transmitted to our servers and to the third-party large-language-model (LLM) providers and threat-intelligence sources we rely on for evaluation. This is the core functional data of the Application and may include: full URL strings and associated metadata (the registered domain, domain-registration and certificate signals, and page content used to evaluate the URL); and messages and links you forward to the SiteRep WhatsApp bot. Do not submit content containing your own sensitive personal information (for example, a message containing a Social Security or bank account number). We cannot be responsible for personal information you voluntarily embed in a Submission.

1.2.2 SiteRep Safari Extension — Automatic Page Scanning (Opt-In)

The SiteRep Safari browser extension offers an optional automatic page-scanning feature that you must affirmatively enable. When you turn on automatic scanning, the extension automatically sends the web address (URL) of each page you visit to our servers so we can evaluate whether the page is safe and return a verdict. This means that, while automatic scanning is enabled, we collect and process the URLs of the pages you browse — not only the URLs you manually submit. We use these URLs solely to perform the safety analysis, to return a verdict, and for the purposes described in Sections 1.2.1 and 2. Automatic scanning is off by default; you may enable or disable it at any time in the extension's settings, after which the extension returns to analyzing only the pages, URLs, or content you explicitly submit. We do not collect the full content of pages you visit through automatic scanning beyond what is necessary to evaluate the submitted URL.

1.2.3 Device and Technical Data

  • Device type, operating system, browser user agent, and (for mobile) app version and device model.
  • IP address of every analysis request, plus the country and city derived from it via geolocation lookup and approximate latitude/longitude, stored alongside each analysis record. Used for rate limiting, fraud prevention, abuse triage, and region-aware results — not for behavioral advertising.
  • Session identifiers, request timestamps, and a per-install identifier generated by the Application — a simple value assigned to each installation, used to enforce per-device guest analysis limits before sign-up and to bind guest analyses to your account when you register. It does not track you across other apps, websites, or devices.
  • Server-side error logs and request traces necessary to operate and debug the Application.

1.2.4 Usage and Analytics Data

  • Features accessed and frequency of use, when client-side analytics are enabled.
  • Aggregate analysis outcomes (verdict and trust score), recorded against your user account or guest per-install identifier to power your analysis history and audit detection quality.
  • Error rates and latency logged to operate, debug, and audit the quality of the Application. These operational logs do not include your account profile.

1.3 Information from Third-Party Sources

To produce verdicts, we transmit submitted content to third-party LLM and search providers and query public reputation and infrastructure data sources ("Threat Intelligence Sources"), currently including Anthropic (Claude), Google (Gemini), and Perplexity, plus publicly available domain-registration, certificate, and reputation data. Verdicts are informed by, and in some cases substantially derived from, these third-party sources, whose accuracy and timeliness we do not control.

These providers act as our service providers (processors) for this purpose, not independent recipients who receive your data for their own use. They receive only the URL, link, or page content to be evaluated — not your name, email, account identifier, or, on a Family plan, which member submitted it — and they are bound by written data-processing agreements that permit them to use that content solely to return a verdict to us and that prohibit any secondary use, profiling, advertising, or independent disclosure. This URL-evaluation step is the core security function you ask SiteRep to perform, and it works the same way for every check, regardless of plan type or the age of the person who submitted it. We do not build advertising or behavioral profiles of any user from this activity.

1.4 Information We Do NOT Collect

We do not collect, and the Application is not designed to access:

  • The full content of your emails, text messages, or other communications. Except where you enable automatic page scanning in the SiteRep Safari extension (Section 1.2.2), we ingest only what you affirmatively submit. When automatic scanning is enabled, the Safari extension additionally sends us the URLs of pages you visit.
  • Your contacts list, calendar, photos library, microphone data, or device sensors. Our extensions request only the host permissions needed to analyze pages and content.
  • Precise real-time GPS geolocation. We infer only approximate location (country, city, approximate latitude/longitude) from your IP address.
  • Knowingly, any personal data from children under 13 (see Section 11).

One exception applies to Family Plus plans. Where a Family Plus plan has safety notifications enabled (Section 1.1), we disclose limited verdict information about a member's flagged checks to the primary account holder — a once-daily summary listing the registered domain of each Suspicious result, and for Risky and Restricted results a real-time alert containing the member, verdict level, timestamp, and the registered domain, as detailed in Section 1.1. This is a disclosure between members of the same group at the plan owner's direction; it is not a sale of personal data and not a "share" for cross-context behavioral advertising (see Sections 5, 6, and 9).

2. Categories of Personal Data (U.S. State Law Disclosure)

The following table describes the statutory categories of personal data we collect, our purposes, and the parties to whom we disclose each category for a business purpose. We do not sell personal data or share it for cross-context behavioral advertising.

Statutory categoryExamples in SiteRepBusiness purposeDisclosed to
IdentifiersName/display name, email, phone number, SSO IDs, IP address, per-install identifier, month and year of birthAccount creation, authentication, securityHosting (AWS), email (Resend), SSO providers
Commercial informationSubscription plan, status, renewal, transaction historyProcess paid subscriptionsPayment processor (Stripe)
Internet/network activitySubmitted URLs, analysis history, usage and log data, device/browser dataProvide and improve the core serviceLLM/search providers, AWS, PostHog
Geolocation dataApproximate location derived from IP (country, city)Security, fraud prevention, region-aware resultsHosting (AWS)
Customer recordsAccount credentials (hashed), support communicationsAccount administration and supportHosting (AWS)
InferencesTrust verdicts and scores associated with your accountProvide analysis history and audit qualityInternal only / de-identified. For Family Plus plans with safety notifications enabled, flagged verdicts (Suspicious, Risky, or Restricted) are also disclosed to the primary account holder (see Section 1.1).

3. How We Use Your Information

  • Provide, operate, secure, and improve the core threat-detection functionality of SiteRep.
  • Analyze submitted URLs and content against Threat Intelligence Sources and AI models to generate trust classifications.
  • Authenticate your identity (including via Google and Apple SSO) and deliver account-recovery communications.
  • Maintain and improve detection accuracy using aggregated, de-identified data (see Section 4).
  • Send transactional communications (verification, password reset, account security alerts) and, if you opt in, promotional communications (you may opt out anytime).
  • Prevent fraud and abuse, enforce our Terms, comply with law, and protect the rights, property, and safety of the Company, our users, and the public.
  • Operate Family Plus safety notifications — where a plan owner has enabled the feature, alert the primary account holder when a group member's check returns a Suspicious, Risky, or Restricted verdict.

We also aggregate or de-identify personal data so that it no longer identifies you and use that information for the purposes above; we maintain such information in de-identified form and do not attempt to re-identify it except as permitted by law.

4. AI Processing, Classifications, and Automated Decisions

SiteRep uses machine-learning models, third-party LLM inference, and a proprietary scoring engine to generate verdicts labeled "Safe," "Suspicious," "Risky," or "Restricted." These are probabilistic, time-stamped opinions, not human review, legal findings, or verified facts. The legally operative definitions and disclaimers are set out in the SiteRep Schedule to the Master Terms of Service.

Model training. We do not train our own large-language or other AI models on your data. We may retain de-identified analysis records (domains queried and verdict outcomes) to improve detection quality. We do not include your name, email, or other directly identifying account fields in this data, and we de-identify records before any such use outside the live request/response path. You may opt out of having your submitted content used for this de-identified tuning by contacting admin@bearzsolutionsllc.com; opting out may reduce detection quality over time.

No automated decisions with legal effect. SiteRep does not make automated decisions that produce legal or similarly significant effects on you (such as credit, employment, or access to public services). Verdicts are advisory tools intended to inform your own decision-making.

5. Cookies, Tracking Technologies, and Your Signals

  • Session cookies: Strictly necessary for authentication and maintaining your session; cannot be disabled without breaking core functionality.
  • Persistent cookies: Store preferences (e.g., notification settings) and expire after a set period.
  • Analytics: When enabled, the web application may load a third-party product-analytics service for autocaptured pageviews and interaction events. When analytics are not configured, no third-party analytics calls are made.
  • Per-install identifier: A simple value assigned to each installation, used to enforce guest analysis limits and associate guest analyses with a registered account. It does not contain your name or email in isolation and is not used to track you across other apps, websites, or devices.

Global Privacy Control (GPC) and Do Not Track. SiteRep does not sell personal data or share it for cross-context behavioral advertising, so there is no such activity for an opt-out preference signal to stop. To the extent a recognized signal such as GPC applies to us under the law of your state, we will treat it as a valid opt-out request. Because industry "Do Not Track" browser standards are not uniform, we do not separately respond to DNT signals.

6. How We Disclose Personal Data

We do not sell, rent, or trade your personal information. We disclose personal data only as described below.

RecipientPurpose
AI & search providers — Anthropic (Claude), Google (Gemini), Perplexity, TavilyEvaluate submitted URLs and content; bound by their terms / data-processing agreements prohibiting secondary use. They act as our service providers (processors): they receive only the content to be analyzed, not your identity or which member submitted it, and may not use it for any other purpose. Same model for all users, including minors.
Cloud hosting — Amazon Web Services (United States)Host production services and stored data
Payment — Stripe, Inc.Process paid-subscription transactions; we never receive raw card data
Email delivery — ResendSend transactional email (verification, OTPs, invitations, notifications)
Analytics — PostHog; internal LLM monitoringProduct analytics (when enabled); observability of LLM cost/latency/quality
Legal & safetyDisclose where required by law or legal process, to protect rights or safety, or to investigate fraud or security incidents
Business transfersIn a merger, acquisition, reorganization, bankruptcy, or asset sale, with notice before your data becomes subject to a different policy
Family Plus — primary account holderWhere a Family Plus plan has safety notifications enabled, deliver alerts about a group member's Suspicious, Risky, or Restricted verdicts to the primary account holder. This is a disclosure within your group at the plan owner's direction, not a sale and not a "share" for cross-context behavioral advertising

7. Data Retention

Data typeRetention
Account informationDuration of your account plus a reasonable period to meet legal obligations, resolve disputes, and enforce our Terms
Your URL scan history and submitted content (URLs, links, scanned-page data)Automatically deleted within 30 days of collection. There is no in-app control to delete individual scan history, but you can request earlier deletion by emailing support@bearzsolutionsllc.com. You can delete your entire account at any time from within the app (Section 8)
De-identified classification recordsMay be retained indefinitely for scoring-rule tuning, regression testing, and quality auditing
Family Plus safety-notification recordsNotification records (the daily Suspicious count, and the Risky and Restricted alert content described in Section 1.1) are cleared on the same 30-day cycle as the backend evaluation cache above, and the full URL associated with a Restricted alert is not retained in scan history. Because Risky and Restricted alerts are delivered in real time, clearing this data does not retract an alert already sent to, or mirrored to, the relevant member and the primary account holder.
Transaction recordsAs long as required by applicable tax, accounting, and financial-reporting laws (Stripe is system of record)
Server logsTypically no more than 90 days, except where longer is required for security investigations

Your scan history (your account). When you run an analysis, the result is saved to your account so you can review it as your scan history. We keep only the most recent 25 scans per verdict category — Safe, Suspicious, and Risky — in your history (up to 25 in each category); once a category exceeds 25 entries, the oldest entry in that category drops off automatically. Your scan history is tied to your account: you can remove it by deleting your account at any time from within the app (which removes your account and associated personal data as described in Section 8), or by requesting deletion of specific records at support@bearzsolutionsllc.com.

Backend evaluation library (user-agnostic cache). Separately from your personal history, each analysis result is also written to a backend evaluation library that is not tied to you or to any other user. This library is keyed to the scanned URL itself and lets SiteRep return faster, more consistent results when the same URL is checked again. The library stores the analysis result for a given URL for 30 days; after 30 days the cached result is cleared or marked stale, so the next time anyone checks that URL, SiteRep runs a fresh evaluation and re-caches the updated result. Only the analysis result is subject to this 30-day cycle. The scanned URL record in the library is not deleted on this schedule; however, because the library is user-agnostic, it does not contain your name, email, account identifier, or any indication of who submitted the URL, and it is not personal data about you.

Certain data may be retained beyond these periods where required by law or to resolve active disputes. When data is no longer needed, we delete, destroy, or irreversibly de-identify it.

8. Your Privacy Rights and Choices

Subject to applicable law and verification of your identity, you may exercise the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate personal data.
  • Deletion: Delete your account at any time directly in the app, which removes your account and associated personal data. You may also request deletion of specific personal data by contacting us; to request deletion of your scan history, email support@bearzsolutionsllc.com. Deletion applies to the scan history in your account; the user-agnostic backend library described in Section 7 contains no information that identifies you.
  • Opt-out of marketing: Unsubscribe from promotional communications at any time via the link in any email or in app settings.
  • Portability: Where technically feasible, request a portable copy of your data.

How to exercise. Submit requests to admin@bearzsolutionsllc.com. We will verify your identity before processing and may deny requests where we cannot verify identity or where an exception applies. To request deletion of your scan history specifically, email support@bearzsolutionsllc.com. Authorized agents may submit a request on your behalf with proof of authorization, and we may still require you to verify your identity. Appeals. Where the law provides a right to appeal a decision on your request, you may appeal by replying to our decision or emailing admin@bearzsolutionsllc.com. We do not discriminate against you for exercising your rights.

9. Additional U.S. State Privacy Rights

Residents of states with comprehensive privacy laws — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas, Oregon, Montana, and other states as such laws take effect — have rights that may include the right to know/access, to delete, to correct, to data portability, to opt out of sale, sharing, or targeted advertising, and to be free from discrimination for exercising these rights.

  • We do not sell personal data and do not share it for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes that require a right to limit under applicable state law, and we do not process personal data to infer characteristics for targeted advertising.
  • California residents may also request, twice per 12-month period, the categories and specific pieces of personal information collected, the sources, the business purposes, and the categories of third parties to whom it was disclosed (see Sections 2 and 6).

To exercise these rights, contact admin@bearzsolutionsllc.com. We will respond within the timeframe required by the applicable law (for example, 45 days under the CCPA, extendable as permitted).

10. International Data Transfers and Asia-Pacific Rights

If you are located in the Asia-Pacific region, you may have rights under your local data-protection law — for example, Japan's Act on the Protection of Personal Information (APPI), South Korea's Personal Information Protection Act (PIPA), Singapore's Personal Data Protection Act (PDPA), Hong Kong's Personal Data (Privacy) Ordinance (PDPO), or India's Digital Personal Data Protection Act (DPDP Act). Depending on the law that applies to you, these may include the rights to access, correct, and delete your personal data and to withdraw consent you have given. Where your local law requires your consent for a particular use of your personal data, we will obtain it. To exercise any of these rights, contact us at admin@bearzsolutionsllc.com and we will respond as required by your applicable law.

SiteRep is operated from the United States, and our cloud infrastructure and service providers process data in the United States. If you access SiteRep from outside the United States — including from the Asia-Pacific region — your personal data will be transferred to and processed in the United States and in other jurisdictions where our providers operate, where data-protection laws may differ from those in your country. Where your local law requires it, we apply reasonable safeguards to such transfers and obtain your consent. By using SiteRep, you understand and agree that your information will be processed in the United States.

11. Children's Privacy

SiteRep is not directed to children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children below the applicable minimum age. If you are a parent or guardian and believe we have collected such data without verifiable parental consent, contact admin@bearzsolutionsllc.com and we will promptly delete it. Family plans do not change this. Every member of a Family plan — including any member invited or added by the primary account holder — must meet the applicable minimum age, and a Family plan may not be used to create or operate an account for a child below that age. Where a Family plan member is a minor at or above the minimum age, the primary account holder is responsible for having any authority required under applicable law to receive that member's safety notifications. We confirm age using the month and year of birth only; we do not request government identification or use third-party identity-verification services. When a minor member at or above the minimum age runs a check, that check is evaluated exactly as it is for any other user: the URL or page content is processed by our service providers solely to return a safety verdict, those providers do not receive the member's name, account, or identity, and they may not use the content for any other purpose. We do not build advertising or behavioral profiles of any member, including minors. We do not knowingly collect personal data from children under 13.

12. Sensitive Personal Information

SiteRep is not designed to collect sensitive personal information (such as government identifiers, precise geolocation, health, biometric, or financial-account data). Payment-card data is handled entirely by Stripe and never reaches our servers. You should not submit sensitive personal information within content you ask SiteRep to analyze. We do not use or disclose any sensitive personal information for purposes other than those permitted under applicable law, and we do not sell or share it.

13. Data Security

We implement administrative, technical, and physical safeguards designed to protect your information, including: encryption of data in transit (TLS) and of sensitive data at rest; passwords stored only as cryptographic hashes; need-to-know access controls with secrets managed through a dedicated secrets-management service; regular review of our security posture and dependencies; and documented incident-response procedures. No security measure is perfect; we cannot guarantee that unauthorized parties will never defeat our safeguards. In the event of a breach likely to create risk to your rights, we will notify affected users and regulators as required by law.

14. Changes to This Privacy Policy

We may update this Policy to reflect changes in our practices, legal requirements, or the Application. We will update the Effective Date and may post a notice in the Application and/or email you. Material changes — including any change to what data we collect or how we use it (such as enabling new automatic data collection) — will be communicated before they take effect where required by law. Continued use after the effective date constitutes acceptance.

15. Contact Information

The business responsible for your personal data is Bearz Solutions LLC. For privacy requests, legal notices, or questions about this Policy:

Bearz Solutions LLC
3564 Avalon Park E Blvd, STE 1 Z3190, Orlando, Florida 32828
Privacy/Legal Email: admin@bearzsolutionsllc.com
Scan-History Deletion Requests: support@bearzsolutionsllc.com
Website: www.bearzsolutionsllc.com

For California residents who cannot resolve a complaint directly with us, the California Department of Consumer Affairs — Consumer Information Division may be contacted at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or (800) 952-5210.

Bearz Solutions LLC · SiteRep Privacy Policy (U.S. & Asia-Pacific) · July 7, 2026 · Version 1.0