BClear

Privacy Policy

Last updated 12 August 2026

This policy explains what personal information BClear (“we”, “us”) collects when you use bclear.app, why we collect it, and what rights you have over it. We’ve written it to describe what the service actually does rather than to cover every hypothetical.

BClear does two things: it grades a website you submit, and — if you sign in and connect Google Search Console — it turns your search performance data into content plans and keyword ideas. You can use the grader without an account.

Who we are

BClear is operated by Tyson Monteiro, a sole trader established in South Africa. Tyson Monteiro is the responsible party under South Africa’s Protection of Personal Information Act (POPIA), and the data controller under the UK and EU GDPR, for the personal information described in this policy.

Most of our users are in South Africa, so this policy is written primarily around POPIA. If you are in the UK or EEA, the GDPR also applies to you and we honour it too — the rights below cover both.

As a sole trader, Tyson Monteiro is also the designated Information Officer for POPIA purposes. You can reach us about anything in this policy, including to exercise your rights, at taysongermano@gmail.com.

What we collect and why

We collect only what the grader needs to work. There is no advertising network, no cross-site tracking, and no sale of personal information.

The website address you submit

When you grade a site, we send that URL to Google PageSpeed Insights and fetch the page itself to analyse its content. If you submit a URL that contains personal data (for example a link with a token or an identifier in the query string), that data will be included in what we send and store. Please submit only public page URLs.

Your IP address

We record the IP address of each grading request. It is used for two things: enforcing rate limits (3 per hour, 6 per day, 15 per month) so the service isn’t abused, and keeping a durable log of scans for usage tracking and abuse detection.

Your email address

You only give us an email address if you ask us to send you the full PDF report. We use it to send that report, and we store it as a contact so we can send you related updates about BClear. We do not send a separate confirmation email before adding you, so you are added on the strength of the request itself — you can unsubscribe at any time using the link in any email we send, or by emailing us.

Scan results

We store the score, the detected sector, and the URL for each scan, alongside the IP address and, if you requested a report, your email address. If you have an account, your saved reports are stored against it so you can revisit them.

Your account

Accounts are created by signing in with Google. We receive your name, email address, and profile picture from Google, and store them along with a session so you stay signed in. We never receive or store your Google password. Signing in requests only basic profile and email access — nothing more.

Google Search Console data

Connecting Search Console is optional and separate from signing in. We ask for it only when you choose to connect, and we request a single scope:

What we read.Your search performance rows — queries, pages, clicks, impressions, CTR, and position by date — which we store in our database so we can analyse trends over time and generate your content plans, keyword ideas, and checklists. A daily background sync keeps this up to date while your connection is active. We also read the index status of individual pages you ask us to check, and the list of sitemaps registered for your properties.

What we change.Only sitemaps, and only when you explicitly ask us to: submitting a sitemap URL you enter, or removing one you choose to remove. We never change your site's content, settings, users, or any other part of your Search Console account, and we never submit or remove anything on our own initiative.

Google grants this as one combined permission — there is no narrower scope that allows sitemap management alone. If you'd rather not grant it, you can still connect with read-only access: everything except sitemap management continues to work.

We use your Search Console data only to provide the features you see in the app. We do not sell it, use it for advertising, or use it to train generative AI or machine learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google issues us access and refresh tokens so the background sync can run. These are encrypted at rest. You can disconnect at any time from your Google account permissions page, which immediately revokes our access, or by asking us to delete your account.

Analytics

We use Vercel Web Analytics to understand aggregate traffic. It is privacy-focused: it does not use cookies and does not build a cross-site profile of you.

Cookies and local storage

We use no advertising or tracking cookies. The only cookie we set is a strictly necessary one: a session cookie that keeps you signed in after you log in. Without it, accounts could not work. If you never sign in, we set no cookies at all.

We also use your browser’s local storage, which stays on your device and is never transmitted to us, for:

You can clear all of this at any time by clearing site data in your browser, and you can delete individual reports from the Past reports page.

Why we are allowed to process your information

POPIA (section 11) and the GDPR (Article 6) both require a justification for each use of personal information. Ours line up as follows:

WhatPOPIA justificationGDPR lawful basis
Grading a URL you submitNecessary to perform under a contract with you — s11(1)(b)Performance of a contract (Art. 6(1)(b))
Sending the PDF report you requestedNecessary to perform under a contract with you — s11(1)(b)Performance of a contract (Art. 6(1)(b))
IP-based rate limiting and abuse preventionOur legitimate interests in keeping the service available — s11(1)(f)Legitimate interests (Art. 6(1)(f))
Scan logging and aggregate analyticsOur legitimate interests in understanding and improving the service — s11(1)(f)Legitimate interests (Art. 6(1)(f))
Creating and running your accountNecessary to perform under a contract with you — s11(1)(b)Performance of a contract (Art. 6(1)(b))
Reading and analysing your Search Console dataYour consent, given when you connect — s11(1)(a); withdrawable at any timeConsent (Art. 6(1)(a)); withdrawable at any time
Marketing emails about BClearYour consent, given when you request a report — s11(1)(a), and direct marketing under s69; withdrawable at any timeConsent (Art. 6(1)(a)); withdrawable at any time

Who we share data with

We do not sell your personal information or share it for advertising. We use the following processors and sub-processors, each of which handles data on our instructions:

ProviderPurposeData
VercelHosting and web analyticsIP address, request metadata
Google (PageSpeed Insights)Performance analysis of the submitted URLThe URL you submit
ResendSending report emails and storing contactsEmail address, report contents
UpstashRate limiting and caching of grade resultsIP address, submitted URL
TursoDatabase: scan log, accounts, saved reports, Search Console dataIP address, URL, score, sector, email, account profile, Search Console rows, encrypted OAuth tokens
Google (Search Console API)Reading your search performance data, if you connect itOAuth tokens issued to us by Google on your authorisation

We may also disclose data where we are legally required to do so, or to establish, exercise, or defend legal claims.

Transfers outside South Africa

The providers above are located outside South Africa, mainly in the United States and the European Union. This means your personal information is stored and processed outside the country.

Section 72 of POPIA permits this, and we rely on it on two grounds. First, each provider is bound by a written data processing agreement imposing protections substantially similar to POPIA’s conditions for lawful processing, and restricting onward transfers. Second, for the parts of the service you actively request — sending your report, or syncing Search Console — the transfer is necessary to perform our contract with you.

For users in the UK or EEA, the same transfers are covered by the safeguards required under Article 46 of the UK/EU GDPR — in practice the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as incorporated into each provider’s data processing agreement.

How long we keep it

Your rights

Under POPIA (sections 23 to 25 and 11(3)) you have the right to:

If you are in the UK or EEA, the GDPR gives you the equivalent rights of access, rectification, erasure, restriction, objection, and data portability.

To exercise any of these, email taysongermano@gmail.com. We will respond as soon as reasonably possible, and within one month at the latest. Because we identify records by email address or IP address, we may need you to tell us which one to look up. POPIA lets you make a formal access request on Form 2, but a plain email to us is enough — we won’t insist on the form.

If you think we’ve handled your information improperly, you can complain to the Information Regulator (South Africa) at inforegulator.org.za, or by email to POPIAComplaints@inforegulator.org.za. If you are in the UK, you can complain to the Information Commissioner’s Office at ico.org.uk; elsewhere in the EEA, to your local supervisory authority. We’d appreciate the chance to address it first.

Children

BClear is a business tool and is not directed at children. Under POPIA a child is anyone under 18, and processing their personal information generally requires a parent or guardian’s consent. We do not knowingly collect information about children. If you believe a child has provided us information, contact us and we will delete it.

Security

Data is transmitted over HTTPS and held by the providers listed above under their own security controls. Google OAuth tokens are encrypted at rest. No service can promise perfect security, but we keep the data we collect deliberately minimal, which is the most effective protection we can offer.

If personal information under our control is accessed or acquired by an unauthorised person, POPIA section 22 requires us to notify the Information Regulator and you as soon as reasonably possible after discovering it. We will tell you what happened and what you can do to protect yourself.

Changes to this policy

If we change this policy we will update the date at the top of this page. Material changes affecting how we use your data will be communicated by email where we hold your address.

See also our Terms of Service.

Back to the grader