Your data
Privacy
Version: 5 October 2026 · first release draft
Who is responsible?
Stefan Mayr, sole proprietor, Wittenbauerstraße 61, 8010 Graz, Austria, is the controller for Source of Trust. Contact: office@stmayr.com. See the Imprint for business details.
Website requests and security
Operating the website involves technical request data such as IP addresses, request times, URLs, browser information and response status. We use necessary technical logs to diagnose failures, protect the service and prevent abuse. A pseudonymous, keyed representation of the client IP is used for short-lived request and scan limits; it is not used to build an advertising profile.
The basis is our legitimate interest in a secure, reliable service (Article 6(1)(f) GDPR). Security data is kept only for the operational, incident-response or legal period for which it is needed.
URLs, public content and analysis results
When you request a scan, Source of Trust retrieves the publicly accessible page you selected and processes its content to produce scores, findings and recommendations. The analyzed page may itself contain personal data. Please do not submit private content, credentials, sensitive information or URLs containing secret access tokens.
We store the submitted URL, associated site and page records, active-page records, analysis status, results and necessary diagnostic records. Results are not made public by this funnel. Requested analyses and account features are provided under Article 6(1)(b) GDPR; security and troubleshooting rely on Article 6(1)(f). Public personal data incidental to analysis is processed for the legitimate interest in assessing the requested public page, subject to applicable rights.
Guest sessions and necessary cookies
The website uses the strictly necessary __Host-sot_scan cookie for scan continuity, secure account access and abuse protection. It contains an opaque signed session identifier, not your email or analysis report. It is HttpOnly, Secure and SameSite=Lax, with a maximum lifetime of seven days. Local development uses a non-production cookie name.
Server-side session state expires with that seven-day session. Short-lived sign-in continuations last up to 15 minutes. Abuse buckets expire after their applicable short-lived window. Expiry of a session does not by itself erase associated analysis records.
No marketing cookies, advertising pixels or visitor analytics are included in this website. No newsletter subscription is created by signing in. Necessary cookies support the service you request; they are not optional marketing tracking.
Email, verification and account data
We use your email address to send transactional, single-use sign-in links, verify access and associate your account with saved sites, pages and results. A link expires after 15 minutes. Verification and authentication records include token hashes, expiry and use status; the central authentication session has a maximum duration of 30 days, while this website's browser session expires after seven days. Signing out revokes the active authentication session.
Account data, ownership associations and saved analyses are retained while needed to provide your account and its history. Unclaimed guest access is temporary. Deletion of a cookie or expiry of a login is not account deletion. To request deletion of account or analysis data, contact us; applicable legal retention and security requirements may limit immediate deletion. There is no newly promised automatic audit-history deletion schedule.
Service providers and recipients
We use contracted infrastructure, transactional email, analysis-processing and search-information services to operate Source of Trust. Relevant technical data, selected public page content and contextual search queries may be processed by those services for the requested analysis. Your account email is used for authentication and delivery, not sent as input to content analysis. This does not authorize those providers to publish your reports.
Our current technical services include Cloudflare for hosting, storage and transactional delivery, OpenAI for content-analysis processing, and Google services for search information. Provider disclosure here explains data handling, not our proprietary analysis methodology.
International processing may occur. Before public launch, the applicable processor agreements, locations and transfer safeguards must be confirmed and this notice finalized. Where required, transfers must rely on an applicable adequacy decision or appropriate safeguards such as standard contractual clauses. We do not claim that unverified contracts or transfer mechanisms are already in place.
Your rights
Subject to the GDPR's conditions, you may request access, correction, deletion, restriction, or portability of your personal data. You may object to processing based on legitimate interests. If processing relies on consent, you may withdraw it without affecting prior lawful processing. No marketing consent is requested in this release.
You may complain to the Austrian Datenschutzbehörde or your competent supervisory authority. Contact us at the address above to exercise your rights. We may need to verify your identity.
Choices and changes
You can browse public product pages without creating an account. Email verification is necessary to access protected account features. Analyses support your decisions; they do not make automated decisions with legal or similarly significant effects about individuals. We update this notice when the actual service or its processing changes.
Moving from a product page to a scan
When you submit a page URL on a product page, necessary tab-local browser storage briefly holds that URL and the submission time. The scan entry consumes and removes it before starting the requested analysis; an intent older than one minute is not executed. It contains no account credentials or saved report. If this storage is unavailable, you can submit the prefilled URL manually.