Pesky collects little, keeps it for a reason, and never sells it. This page says exactly what, why, and for how long. Questions: ruz@pesky.ai.
1. Who is responsible
Pesky OÜ, Tallinn, Estonia, is the data controller for pesky.ai. We are an EU company and the GDPR applies to everything below, wherever you are.
2. What we collect, and why
When you run the free scan
- The website you typed, the result we showed, when, and whether it came from the cache. We keep this so a shared link shows the same card, so support can see what you saw, and so we can improve the scan.
- A short anonymous visitor hash made from your IP address and browser, plus your country and city as our hosting provider reports them. We keep the hash instead of the IP address. It exists to enforce the rate limit and to spot abuse.
When you leave your email
- Your email address and which plan you were interested in, when you use “notify me” or submit interest in a plan. We use it to tell you when that thing launches. Nothing else.
- Your message, if you write to us from the Contact tab, so we can reply.
When you have an account
- Sign in with Google: we receive your name, email address, and profile picture from Google to create and sign you into your account. We do not ask for access to your Gmail, contacts, calendar, or files. If a future feature needs more, it will ask you separately, explain why, and you can say no. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
- Email sign-in: your email address and a sign-in link or code.
- Your plan and billing status. Card details go straight to our payment processor; we see the last four digits and the expiry at most.
- The companies you track and the reports we generate for you. That is the product.
Everyone
- Product analytics, done by us: which pages you open and which buttons you press (a scan started, a result shared, a plan tapped, and so on), the domain you scanned, your screen size and browser. We record this on our own servers with the same anonymous visitor hash as the scan, so there is no analytics cookie, no analytics identifier in your browser, and no third-party analytics script on the page. We use it to see what works.
- Server logs for security and debugging, kept briefly.
3. What we do not do
- We do not sell personal data, and we do not share it with advertisers.
- We do not build profiles of the people at the companies we scan. Pesky looks at companies and public websites.
- We do not read your inbox, your files, or your private systems.
4. The legal bases
Running the scan, keeping accounts, and billing: performing our contract with you. Rate limiting, security, analytics, and improving the scan: our legitimate interest in running a small service well, balanced against your privacy, which is why the visitor hash replaces the IP address. Launch emails and anything optional: your consent, which you can withdraw by replying or clicking unsubscribe.
5. Who else sees it
Pesky runs on rented infrastructure like every small company. Categories of providers that process data on our behalf: hosting and edge network, database, email delivery, payment processing, and the AI model providers that help judge which company is a competitor. Each of them acts only on our instructions under a data-processing agreement. Some are in the United States; transfers rely on the EU-US Data Privacy Framework or standard contractual clauses. Email ruz@pesky.ai for the current list of sub-processors.
To run a scan we send the website address you typed and public text about it to those providers. We do not send your email address or your account details to the AI model providers.
We share data when the law requires it, or to protect Pesky or its users from abuse.
6. How long we keep it
- Scan results: one week in the cache; the scan log for up to 24 months, then deleted or anonymised.
- Visitor hash, country, city: with the scan log, same period.
- Launch-list emails: until the launch email is sent and you have had a chance to unsubscribe, or until you ask.
- Account data: while your account exists, then 30 days.
- Billing records: as long as Estonian accounting law requires, currently seven years.
- Analytics events: 12 months.
7. Your rights
You can ask us what we hold about you, get a copy, correct it, have it deleted, restrict or object to how we use it, and take it elsewhere. Email ruz@pesky.ai; we answer within 30 days and we do not charge for it. If you are unhappy with our answer you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the authority where you live.
8. Cookies
pesky.ai sets no advertising cookies and no analytics cookies or identifiers. The only cookies are the technical ones needed to keep you signed in when you have an account. Your browser's settings let you block or clear them; the site keeps working, the scan included.
9. Children
Pesky is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you think we have, email us and we will delete it.
10. Changes
If this policy changes in a way that matters, we email account holders before the change takes effect and move the date at the top. Old versions are available on request.
11. Contact
Pesky OÜ, Tallinn, Estonia. ruz@pesky.ai.