Privacy policy
Last updated September 27, 2026.
The short version. We help companies measure and improve their growth. We look at public websites, and, when a client connects them, the client's own tools. We act on our clients' behalf for their customers' data, we use it only to do the work they hired us for, never for another client, and never to train AI models. Deletion requests are handled within seven days.
Who we are
This service is run by Lee Flannery Consulting LLC. Questions about privacy go to hello@leeflanneryconsulting.com.
Two kinds of data
Data about our clients. When your company works with us, we hold the names and email addresses of the people on your team who sign in, and a record of what they do in the app (for example, marking a finding fixed). We are responsible for this data.
Data about our clients' customers. When a client installs our site tag or connects a source such as Stripe, we process data about that client's own customers on the client's behalf. The client decides what is collected and why, we follow their instructions. If you are a customer of one of our clients, that company is responsible for your data and is the first place to ask about it. We will help them answer you.
What we collect and why
- Public web pages. We read public, logged-out pages of a client's website and related public sources to produce a report. We never read pages behind a login.
- Sign-in details. Your email address, used to send you a sign-in link. There are no passwords.
- Site tag events. The tag keeps its identifiers in first-party cookies on the client's own site for 90 days. It sets no third-party cookies and does no fingerprinting. It records page views and conversions on their site, with browser and ad-click identifiers, so the client can see which channels bring customers.
- Connected sources. When a client connects Stripe, Google Analytics, Google Ads or Meta, we read what the connection allows (read-only where the platform offers it) to answer the checks in their report. Keys are stored encrypted and are never shown back.
- Customer records a client shares. Used to match results to real customers. When we send data to an ad platform on a client's behalf, we send only hashed identifiers, and only for people who bought or opted in.
We do not buy data about people who have not transacted with or opted in to our client, and we do not build profiles of individuals from community or social posts.
Services we use
We use a small number of providers to run the service. Supabase (database and sign-in), Anthropic (AI models that draft and check reports), our hosting provider, and, only when a client connects them, Stripe, Google and Meta. Each provider receives only what it needs for its part of the work.
How long we keep data
- A client's customer records: for the engagement and 90 days after it ends, then deleted, unless the client asks for an export first.
- Site tag events that never matched a customer: 90 days.
- Team sign-in details: while your company works with us.
- Public web observations: kept as a dated history, since they describe companies, not private individuals.
Your rights
You can ask to see, correct or delete personal data we hold about you. If you are a client's customer, you can ask the client or write to us, we act on a deletion within seven days across our store, and send deletion requests to the ad platforms where their tools allow. We log that a deletion happened, not what was deleted. Depending on where you live (for example California or the EU), you may have further rights, write to hello@leeflanneryconsulting.com and we will answer.
Changes
If we change this policy in a way that matters, we will tell clients before it takes effect.