Privacy Policy
Last updated 12 August 2026
This policy explains what personal information BClear (“we”, “us”) collects when you use bclear.app, why we collect it, and what rights you have over it. We’ve written it to describe what the service actually does rather than to cover every hypothetical.
BClear does two things: it grades a website you submit, and — if you sign in and connect Google Search Console — it turns your search performance data into content plans and keyword ideas. You can use the grader without an account.
Who we are
BClear is operated by Tyson Monteiro, a sole trader established in South Africa. Tyson Monteiro is the responsible party under South Africa’s Protection of Personal Information Act (POPIA), and the data controller under the UK and EU GDPR, for the personal information described in this policy.
Most of our users are in South Africa, so this policy is written primarily around POPIA. If you are in the UK or EEA, the GDPR also applies to you and we honour it too — the rights below cover both.
As a sole trader, Tyson Monteiro is also the designated Information Officer for POPIA purposes. You can reach us about anything in this policy, including to exercise your rights, at taysongermano@gmail.com.
What we collect and why
We collect only what the grader needs to work. There is no advertising network, no cross-site tracking, and no sale of personal information.
The website address you submit
When you grade a site, we send that URL to Google PageSpeed Insights and fetch the page itself to analyse its content. If you submit a URL that contains personal data (for example a link with a token or an identifier in the query string), that data will be included in what we send and store. Please submit only public page URLs.
Your IP address
We record the IP address of each grading request. It is used for two things: enforcing rate limits (3 per hour, 6 per day, 15 per month) so the service isn’t abused, and keeping a durable log of scans for usage tracking and abuse detection.
Your email address
You only give us an email address if you ask us to send you the full PDF report. We use it to send that report, and we store it as a contact so we can send you related updates about BClear. We do not send a separate confirmation email before adding you, so you are added on the strength of the request itself — you can unsubscribe at any time using the link in any email we send, or by emailing us.
Scan results
We store the score, the detected sector, and the URL for each scan, alongside the IP address and, if you requested a report, your email address. If you have an account, your saved reports are stored against it so you can revisit them.
Your account
Accounts are created by signing in with Google. We receive your name, email address, and profile picture from Google, and store them along with a session so you stay signed in. We never receive or store your Google password. Signing in requests only basic profile and email access — nothing more.
Google Search Console data
Connecting Search Console is optional and separate from signing in. We ask for it only when you choose to connect, and we request a single scope:
https://www.googleapis.com/auth/webmasters— lets us read your Search Console data and manage the sitemaps registered for your properties.
What we read.Your search performance rows — queries, pages, clicks, impressions, CTR, and position by date — which we store in our database so we can analyse trends over time and generate your content plans, keyword ideas, and checklists. A daily background sync keeps this up to date while your connection is active. We also read the index status of individual pages you ask us to check, and the list of sitemaps registered for your properties.
What we change.Only sitemaps, and only when you explicitly ask us to: submitting a sitemap URL you enter, or removing one you choose to remove. We never change your site's content, settings, users, or any other part of your Search Console account, and we never submit or remove anything on our own initiative.
Google grants this as one combined permission — there is no narrower scope that allows sitemap management alone. If you'd rather not grant it, you can still connect with read-only access: everything except sitemap management continues to work.
We use your Search Console data only to provide the features you see in the app. We do not sell it, use it for advertising, or use it to train generative AI or machine learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google issues us access and refresh tokens so the background sync can run. These are encrypted at rest. You can disconnect at any time from your Google account permissions page, which immediately revokes our access, or by asking us to delete your account.
Analytics
We use Vercel Web Analytics to understand aggregate traffic. It is privacy-focused: it does not use cookies and does not build a cross-site profile of you.
Cookies and local storage
We use no advertising or tracking cookies. The only cookie we set is a strictly necessary one: a session cookie that keeps you signed in after you log in. Without it, accounts could not work. If you never sign in, we set no cookies at all.
We also use your browser’s local storage, which stays on your device and is never transmitted to us, for:
- Report history— the reports you’ve run, so you can find them again on the Past reports page.
- Theme preference— whether you chose light or dark mode.
- Sidebar preference— whether you expanded or collapsed the navigation.
You can clear all of this at any time by clearing site data in your browser, and you can delete individual reports from the Past reports page.
Why we are allowed to process your information
POPIA (section 11) and the GDPR (Article 6) both require a justification for each use of personal information. Ours line up as follows:
| What | POPIA justification | GDPR lawful basis |
|---|---|---|
| Grading a URL you submit | Necessary to perform under a contract with you — s11(1)(b) | Performance of a contract (Art. 6(1)(b)) |
| Sending the PDF report you requested | Necessary to perform under a contract with you — s11(1)(b) | Performance of a contract (Art. 6(1)(b)) |
| IP-based rate limiting and abuse prevention | Our legitimate interests in keeping the service available — s11(1)(f) | Legitimate interests (Art. 6(1)(f)) |
| Scan logging and aggregate analytics | Our legitimate interests in understanding and improving the service — s11(1)(f) | Legitimate interests (Art. 6(1)(f)) |
| Creating and running your account | Necessary to perform under a contract with you — s11(1)(b) | Performance of a contract (Art. 6(1)(b)) |
| Reading and analysing your Search Console data | Your consent, given when you connect — s11(1)(a); withdrawable at any time | Consent (Art. 6(1)(a)); withdrawable at any time |
| Marketing emails about BClear | Your consent, given when you request a report — s11(1)(a), and direct marketing under s69; withdrawable at any time | Consent (Art. 6(1)(a)); withdrawable at any time |
Who we share data with
We do not sell your personal information or share it for advertising. We use the following processors and sub-processors, each of which handles data on our instructions:
| Provider | Purpose | Data |
|---|---|---|
| Vercel | Hosting and web analytics | IP address, request metadata |
| Google (PageSpeed Insights) | Performance analysis of the submitted URL | The URL you submit |
| Resend | Sending report emails and storing contacts | Email address, report contents |
| Upstash | Rate limiting and caching of grade results | IP address, submitted URL |
| Turso | Database: scan log, accounts, saved reports, Search Console data | IP address, URL, score, sector, email, account profile, Search Console rows, encrypted OAuth tokens |
| Google (Search Console API) | Reading your search performance data, if you connect it | OAuth tokens issued to us by Google on your authorisation |
We may also disclose data where we are legally required to do so, or to establish, exercise, or defend legal claims.
Transfers outside South Africa
The providers above are located outside South Africa, mainly in the United States and the European Union. This means your personal information is stored and processed outside the country.
Section 72 of POPIA permits this, and we rely on it on two grounds. First, each provider is bound by a written data processing agreement imposing protections substantially similar to POPIA’s conditions for lawful processing, and restricting onward transfers. Second, for the parts of the service you actively request — sending your report, or syncing Search Console — the transfer is necessary to perform our contract with you.
For users in the UK or EEA, the same transfers are covered by the safeguards required under Article 46 of the UK/EU GDPR — in practice the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as incorporated into each provider’s data processing agreement.
How long we keep it
- Rate-limit counters— automatically expire after their window (one hour, one day, or 30 days).
- Scan log records(IP, URL, score, sector, email) — retained while the service operates, for usage tracking and abuse detection. Ask us and we will delete yours.
- Email contacts— kept until you unsubscribe or ask us to delete them.
- Account data, saved reports, and checklists— kept while your account is open, and deleted when you close it.
- Search Console data and OAuth tokens— kept while your connection is active. Revoking access stops the sync; ask us and we will delete the data already synced.
- Local storage on your device— until you clear it.
Your rights
Under POPIA (sections 23 to 25 and 11(3)) you have the right to:
- Ask whether we hold personal information about you, and request a copy of it.
- Ask us to correct or delete information that is inaccurate, irrelevant, out of date, incomplete, misleading, or obtained unlawfully.
- Ask us to destroy or delete information we are no longer authorised to keep.
- Object, on reasonable grounds, to processing we base on legitimate interests.
- Withdraw consent at any time, without affecting processing already carried out.
- Object at any time to receiving direct marketing.
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you. BClear’s scores and recommendations are advisory only and do not make decisions about you.
- Complain to the Information Regulator, and to seek relief from a court.
If you are in the UK or EEA, the GDPR gives you the equivalent rights of access, rectification, erasure, restriction, objection, and data portability.
To exercise any of these, email taysongermano@gmail.com. We will respond as soon as reasonably possible, and within one month at the latest. Because we identify records by email address or IP address, we may need you to tell us which one to look up. POPIA lets you make a formal access request on Form 2, but a plain email to us is enough — we won’t insist on the form.
If you think we’ve handled your information improperly, you can complain to the Information Regulator (South Africa) at inforegulator.org.za, or by email to POPIAComplaints@inforegulator.org.za. If you are in the UK, you can complain to the Information Commissioner’s Office at ico.org.uk; elsewhere in the EEA, to your local supervisory authority. We’d appreciate the chance to address it first.
Children
BClear is a business tool and is not directed at children. Under POPIA a child is anyone under 18, and processing their personal information generally requires a parent or guardian’s consent. We do not knowingly collect information about children. If you believe a child has provided us information, contact us and we will delete it.
Security
Data is transmitted over HTTPS and held by the providers listed above under their own security controls. Google OAuth tokens are encrypted at rest. No service can promise perfect security, but we keep the data we collect deliberately minimal, which is the most effective protection we can offer.
If personal information under our control is accessed or acquired by an unauthorised person, POPIA section 22 requires us to notify the Information Regulator and you as soon as reasonably possible after discovering it. We will tell you what happened and what you can do to protect yourself.
Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes affecting how we use your data will be communicated by email where we hold your address.
See also our Terms of Service.