A product of Bearz Solutions LLC
Effective Date: July 7, 2026 · Version 1.0 · U.S. & Asia-Pacific Edition
This Privacy Policy explains how Bearz Solutions LLC ("Company," "we," "us," or "our"), a Florida limited liability company, collects, uses, discloses, and protects personal data in connection with the SiteRep application — including the SiteRep mobile applications (iOS and Android), the SiteRep web application at siterep.bearzsolutionsllc.com, the SiteRep browser and Safari extensions, the SiteRep WhatsApp bot, and any associated APIs (collectively, "SiteRep" or the "Application"). It is a product-specific supplement to, and incorporates by reference, the Bearz Solutions LLC Master Terms of Service and its SiteRep Schedule. Other Bearz Solutions products are governed by their own privacy notices. This version of the Privacy Policy applies to users in the United States and the Asia-Pacific region. SiteRep is not offered or directed to individuals in the European Economic Area, the United Kingdom, or Switzerland, and is not intended for use by such individuals.
Your use of SiteRep constitutes acceptance of this Policy. If you do not agree, do not use the Application.
This summary is provided for convenience and does not replace the full Policy below.
| What we collect | Why | Do we sell/"share" it? |
|---|---|---|
| Account data (email, optional display name, phone number), SSO identifiers, month and year of birth | Create and secure your account; authentication; account recovery | No |
| URLs, links, and pages you submit (and, if you enable it, pages auto-scanned by the Safari extension) | Core function: evaluate website trust and return a verdict | No |
| Device & technical data, IP address & approximate location, per-install identifier | Security, rate limiting, fraud prevention, region-aware results | No |
| Usage & analytics data | Operate, debug, and improve the Application | No |
| Payment identifiers (via Stripe) | Process paid subscriptions | No |
We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising or process it for targeted advertising, as those terms are defined under U.S. state privacy laws. Because we do not sell or share your data, an opt-out preference signal such as Global Privacy Control (GPC) has nothing to act on; we will honor such signals to the extent they apply to us. See Sections 5 and 9.
Account Authentication, SSO, and Recovery
Family Plus Safety Notifications (Family Plus plan only)
Safety notifications are available only on our top-tier Family Plus plan; the standard Family plan does not include them. If you use a Family Plus plan, the plan owner (the primary account holder) can enable safety notifications for the group. When this feature is on and a group member submits a URL, link, or page (or, where that member has enabled automatic page scanning, has a page auto-scanned) that returns a "Risky" or "Restricted" verdict, we send a real-time alert to the primary account holder; "Suspicious" verdicts are not sent as individual alerts and are instead summarized once per day. We never notify the primary account holder of "Safe" results, and the feature never provides access to a member's full browsing activity or complete scan history. What we share depends on the severity of the verdict:
Each member can see, within the Application, exactly what has been sent about them. Consent works differently depending on the member: adult members (18 or older) must opt in to be included in safety notifications and may opt out at any time in their settings; members who are minors (at or above the minimum age in Section 11) are included in safety notifications for the group and cannot opt out, and the primary account holder is responsible for holding any authority required under applicable law to receive a minor member's notifications. When a minor member reaches 18 (or the age of majority where they live), we treat them as an adult member: notifications about them are paused until they opt in, and they may opt out at any time. We rely on the age, identity, and relationship information that members and the primary account holder provide, and we cannot independently verify it. Every member is told that safety notifications are part of the plan when they join or are added. This feature is intended for families and similarly trusted groups and is not designed for covert monitoring. All Family plan members must meet the minimum age described in Section 11.
Payment Information
Payments are processed exclusively by Stripe, Inc. We never receive, store, or transmit raw card numbers, CVCs, or banking credentials. We retain only the Stripe customer ID, subscription ID, plan tier, status, and renewal period returned to us by Stripe.
Communications and Support
We collect communications you send us, including support requests and feedback.
Mobile Push Notifications
For the mobile applications, we collect device push-notification tokens used solely to deliver notifications you have enabled.
WhatsApp Bot
If you use the SiteRep WhatsApp bot, we collect your phone number to associate your bot conversations with a usage counter and, if you later sign in, to link prior bot analyses to your account.
1.2.1 URLs, Links, and Content Submitted for Analysis
When you submit a URL, link, or web page for analysis, that content is transmitted to our servers and to the third-party large-language-model (LLM) providers and threat-intelligence sources we rely on for evaluation. This is the core functional data of the Application and may include: full URL strings and associated metadata (the registered domain, domain-registration and certificate signals, and page content used to evaluate the URL); and messages and links you forward to the SiteRep WhatsApp bot. Do not submit content containing your own sensitive personal information (for example, a message containing a Social Security or bank account number). We cannot be responsible for personal information you voluntarily embed in a Submission.
1.2.2 SiteRep Safari Extension — Automatic Page Scanning (Opt-In)
The SiteRep Safari browser extension offers an optional automatic page-scanning feature that you must affirmatively enable. When you turn on automatic scanning, the extension automatically sends the web address (URL) of each page you visit to our servers so we can evaluate whether the page is safe and return a verdict. This means that, while automatic scanning is enabled, we collect and process the URLs of the pages you browse — not only the URLs you manually submit. We use these URLs solely to perform the safety analysis, to return a verdict, and for the purposes described in Sections 1.2.1 and 2. Automatic scanning is off by default; you may enable or disable it at any time in the extension's settings, after which the extension returns to analyzing only the pages, URLs, or content you explicitly submit. We do not collect the full content of pages you visit through automatic scanning beyond what is necessary to evaluate the submitted URL.
1.2.3 Device and Technical Data
1.2.4 Usage and Analytics Data
To produce verdicts, we transmit submitted content to third-party LLM and search providers and query public reputation and infrastructure data sources ("Threat Intelligence Sources"), currently including Anthropic (Claude), Google (Gemini), and Perplexity, plus publicly available domain-registration, certificate, and reputation data. Verdicts are informed by, and in some cases substantially derived from, these third-party sources, whose accuracy and timeliness we do not control.
These providers act as our service providers (processors) for this purpose, not independent recipients who receive your data for their own use. They receive only the URL, link, or page content to be evaluated — not your name, email, account identifier, or, on a Family plan, which member submitted it — and they are bound by written data-processing agreements that permit them to use that content solely to return a verdict to us and that prohibit any secondary use, profiling, advertising, or independent disclosure. This URL-evaluation step is the core security function you ask SiteRep to perform, and it works the same way for every check, regardless of plan type or the age of the person who submitted it. We do not build advertising or behavioral profiles of any user from this activity.
We do not collect, and the Application is not designed to access:
One exception applies to Family Plus plans. Where a Family Plus plan has safety notifications enabled (Section 1.1), we disclose limited verdict information about a member's flagged checks to the primary account holder — a once-daily summary listing the registered domain of each Suspicious result, and for Risky and Restricted results a real-time alert containing the member, verdict level, timestamp, and the registered domain, as detailed in Section 1.1. This is a disclosure between members of the same group at the plan owner's direction; it is not a sale of personal data and not a "share" for cross-context behavioral advertising (see Sections 5, 6, and 9).
The following table describes the statutory categories of personal data we collect, our purposes, and the parties to whom we disclose each category for a business purpose. We do not sell personal data or share it for cross-context behavioral advertising.
| Statutory category | Examples in SiteRep | Business purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Name/display name, email, phone number, SSO IDs, IP address, per-install identifier, month and year of birth | Account creation, authentication, security | Hosting (AWS), email (Resend), SSO providers |
| Commercial information | Subscription plan, status, renewal, transaction history | Process paid subscriptions | Payment processor (Stripe) |
| Internet/network activity | Submitted URLs, analysis history, usage and log data, device/browser data | Provide and improve the core service | LLM/search providers, AWS, PostHog |
| Geolocation data | Approximate location derived from IP (country, city) | Security, fraud prevention, region-aware results | Hosting (AWS) |
| Customer records | Account credentials (hashed), support communications | Account administration and support | Hosting (AWS) |
| Inferences | Trust verdicts and scores associated with your account | Provide analysis history and audit quality | Internal only / de-identified. For Family Plus plans with safety notifications enabled, flagged verdicts (Suspicious, Risky, or Restricted) are also disclosed to the primary account holder (see Section 1.1). |
We also aggregate or de-identify personal data so that it no longer identifies you and use that information for the purposes above; we maintain such information in de-identified form and do not attempt to re-identify it except as permitted by law.
SiteRep uses machine-learning models, third-party LLM inference, and a proprietary scoring engine to generate verdicts labeled "Safe," "Suspicious," "Risky," or "Restricted." These are probabilistic, time-stamped opinions, not human review, legal findings, or verified facts. The legally operative definitions and disclaimers are set out in the SiteRep Schedule to the Master Terms of Service.
Model training. We do not train our own large-language or other AI models on your data. We may retain de-identified analysis records (domains queried and verdict outcomes) to improve detection quality. We do not include your name, email, or other directly identifying account fields in this data, and we de-identify records before any such use outside the live request/response path. You may opt out of having your submitted content used for this de-identified tuning by contacting admin@bearzsolutionsllc.com; opting out may reduce detection quality over time.
No automated decisions with legal effect. SiteRep does not make automated decisions that produce legal or similarly significant effects on you (such as credit, employment, or access to public services). Verdicts are advisory tools intended to inform your own decision-making.
Global Privacy Control (GPC) and Do Not Track. SiteRep does not sell personal data or share it for cross-context behavioral advertising, so there is no such activity for an opt-out preference signal to stop. To the extent a recognized signal such as GPC applies to us under the law of your state, we will treat it as a valid opt-out request. Because industry "Do Not Track" browser standards are not uniform, we do not separately respond to DNT signals.
We do not sell, rent, or trade your personal information. We disclose personal data only as described below.
| Recipient | Purpose |
|---|---|
| AI & search providers — Anthropic (Claude), Google (Gemini), Perplexity, Tavily | Evaluate submitted URLs and content; bound by their terms / data-processing agreements prohibiting secondary use. They act as our service providers (processors): they receive only the content to be analyzed, not your identity or which member submitted it, and may not use it for any other purpose. Same model for all users, including minors. |
| Cloud hosting — Amazon Web Services (United States) | Host production services and stored data |
| Payment — Stripe, Inc. | Process paid-subscription transactions; we never receive raw card data |
| Email delivery — Resend | Send transactional email (verification, OTPs, invitations, notifications) |
| Analytics — PostHog; internal LLM monitoring | Product analytics (when enabled); observability of LLM cost/latency/quality |
| Legal & safety | Disclose where required by law or legal process, to protect rights or safety, or to investigate fraud or security incidents |
| Business transfers | In a merger, acquisition, reorganization, bankruptcy, or asset sale, with notice before your data becomes subject to a different policy |
| Family Plus — primary account holder | Where a Family Plus plan has safety notifications enabled, deliver alerts about a group member's Suspicious, Risky, or Restricted verdicts to the primary account holder. This is a disclosure within your group at the plan owner's direction, not a sale and not a "share" for cross-context behavioral advertising |
| Data type | Retention |
|---|---|
| Account information | Duration of your account plus a reasonable period to meet legal obligations, resolve disputes, and enforce our Terms |
| Your URL scan history and submitted content (URLs, links, scanned-page data) | Automatically deleted within 30 days of collection. There is no in-app control to delete individual scan history, but you can request earlier deletion by emailing support@bearzsolutionsllc.com. You can delete your entire account at any time from within the app (Section 8) |
| De-identified classification records | May be retained indefinitely for scoring-rule tuning, regression testing, and quality auditing |
| Family Plus safety-notification records | Notification records (the daily Suspicious count, and the Risky and Restricted alert content described in Section 1.1) are cleared on the same 30-day cycle as the backend evaluation cache above, and the full URL associated with a Restricted alert is not retained in scan history. Because Risky and Restricted alerts are delivered in real time, clearing this data does not retract an alert already sent to, or mirrored to, the relevant member and the primary account holder. |
| Transaction records | As long as required by applicable tax, accounting, and financial-reporting laws (Stripe is system of record) |
| Server logs | Typically no more than 90 days, except where longer is required for security investigations |
Your scan history (your account). When you run an analysis, the result is saved to your account so you can review it as your scan history. We keep only the most recent 25 scans per verdict category — Safe, Suspicious, and Risky — in your history (up to 25 in each category); once a category exceeds 25 entries, the oldest entry in that category drops off automatically. Your scan history is tied to your account: you can remove it by deleting your account at any time from within the app (which removes your account and associated personal data as described in Section 8), or by requesting deletion of specific records at support@bearzsolutionsllc.com.
Backend evaluation library (user-agnostic cache). Separately from your personal history, each analysis result is also written to a backend evaluation library that is not tied to you or to any other user. This library is keyed to the scanned URL itself and lets SiteRep return faster, more consistent results when the same URL is checked again. The library stores the analysis result for a given URL for 30 days; after 30 days the cached result is cleared or marked stale, so the next time anyone checks that URL, SiteRep runs a fresh evaluation and re-caches the updated result. Only the analysis result is subject to this 30-day cycle. The scanned URL record in the library is not deleted on this schedule; however, because the library is user-agnostic, it does not contain your name, email, account identifier, or any indication of who submitted the URL, and it is not personal data about you.
Certain data may be retained beyond these periods where required by law or to resolve active disputes. When data is no longer needed, we delete, destroy, or irreversibly de-identify it.
Subject to applicable law and verification of your identity, you may exercise the following rights:
How to exercise. Submit requests to admin@bearzsolutionsllc.com. We will verify your identity before processing and may deny requests where we cannot verify identity or where an exception applies. To request deletion of your scan history specifically, email support@bearzsolutionsllc.com. Authorized agents may submit a request on your behalf with proof of authorization, and we may still require you to verify your identity. Appeals. Where the law provides a right to appeal a decision on your request, you may appeal by replying to our decision or emailing admin@bearzsolutionsllc.com. We do not discriminate against you for exercising your rights.
Residents of states with comprehensive privacy laws — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas, Oregon, Montana, and other states as such laws take effect — have rights that may include the right to know/access, to delete, to correct, to data portability, to opt out of sale, sharing, or targeted advertising, and to be free from discrimination for exercising these rights.
To exercise these rights, contact admin@bearzsolutionsllc.com. We will respond within the timeframe required by the applicable law (for example, 45 days under the CCPA, extendable as permitted).
If you are located in the Asia-Pacific region, you may have rights under your local data-protection law — for example, Japan's Act on the Protection of Personal Information (APPI), South Korea's Personal Information Protection Act (PIPA), Singapore's Personal Data Protection Act (PDPA), Hong Kong's Personal Data (Privacy) Ordinance (PDPO), or India's Digital Personal Data Protection Act (DPDP Act). Depending on the law that applies to you, these may include the rights to access, correct, and delete your personal data and to withdraw consent you have given. Where your local law requires your consent for a particular use of your personal data, we will obtain it. To exercise any of these rights, contact us at admin@bearzsolutionsllc.com and we will respond as required by your applicable law.
SiteRep is operated from the United States, and our cloud infrastructure and service providers process data in the United States. If you access SiteRep from outside the United States — including from the Asia-Pacific region — your personal data will be transferred to and processed in the United States and in other jurisdictions where our providers operate, where data-protection laws may differ from those in your country. Where your local law requires it, we apply reasonable safeguards to such transfers and obtain your consent. By using SiteRep, you understand and agree that your information will be processed in the United States.
SiteRep is not directed to children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children below the applicable minimum age. If you are a parent or guardian and believe we have collected such data without verifiable parental consent, contact admin@bearzsolutionsllc.com and we will promptly delete it. Family plans do not change this. Every member of a Family plan — including any member invited or added by the primary account holder — must meet the applicable minimum age, and a Family plan may not be used to create or operate an account for a child below that age. Where a Family plan member is a minor at or above the minimum age, the primary account holder is responsible for having any authority required under applicable law to receive that member's safety notifications. We confirm age using the month and year of birth only; we do not request government identification or use third-party identity-verification services. When a minor member at or above the minimum age runs a check, that check is evaluated exactly as it is for any other user: the URL or page content is processed by our service providers solely to return a safety verdict, those providers do not receive the member's name, account, or identity, and they may not use the content for any other purpose. We do not build advertising or behavioral profiles of any member, including minors. We do not knowingly collect personal data from children under 13.
SiteRep is not designed to collect sensitive personal information (such as government identifiers, precise geolocation, health, biometric, or financial-account data). Payment-card data is handled entirely by Stripe and never reaches our servers. You should not submit sensitive personal information within content you ask SiteRep to analyze. We do not use or disclose any sensitive personal information for purposes other than those permitted under applicable law, and we do not sell or share it.
We implement administrative, technical, and physical safeguards designed to protect your information, including: encryption of data in transit (TLS) and of sensitive data at rest; passwords stored only as cryptographic hashes; need-to-know access controls with secrets managed through a dedicated secrets-management service; regular review of our security posture and dependencies; and documented incident-response procedures. No security measure is perfect; we cannot guarantee that unauthorized parties will never defeat our safeguards. In the event of a breach likely to create risk to your rights, we will notify affected users and regulators as required by law.
We may update this Policy to reflect changes in our practices, legal requirements, or the Application. We will update the Effective Date and may post a notice in the Application and/or email you. Material changes — including any change to what data we collect or how we use it (such as enabling new automatic data collection) — will be communicated before they take effect where required by law. Continued use after the effective date constitutes acceptance.
The business responsible for your personal data is Bearz Solutions LLC. For privacy requests, legal notices, or questions about this Policy:
Bearz Solutions LLC
3564 Avalon Park E Blvd, STE 1 Z3190, Orlando, Florida 32828
Privacy/Legal Email: admin@bearzsolutionsllc.com
Scan-History Deletion Requests: support@bearzsolutionsllc.com
Website: www.bearzsolutionsllc.com
For California residents who cannot resolve a complaint directly with us, the California Department of Consumer Affairs — Consumer Information Division may be contacted at 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834, or (800) 952-5210.
Bearz Solutions LLC · SiteRep Privacy Policy (U.S. & Asia-Pacific) · July 7, 2026 · Version 1.0