AuditPilot Logo AuditPilot ← Back to Overview
Compliance & Data Protection

Privacy Policy

Last Updated: September 25, 2026 • Effective Immediately

1. Overview & Core Philosophy

AuditPilot ("we", "our", or "the Extension") is an AI-powered website conversion and CRO audit tool built for consultants, digital agencies, and web designers. We are committed to absolute data minimization. We do not track personal web browsing, do not monitor private web sessions, and do not monetize, sell, or trade any user information to third parties or advertising brokers.

2. Chrome Extension Permissions Justification

AuditPilot utilizes Chrome Manifest V3 with the minimum permissions strictly necessary to generate website audits:

  • activeTab: This permission only activates when you explicitly click the AuditPilot extension icon or trigger an audit action. It grants temporary access to read the active tab's URL and title for audit diagnosis. It never operates in the background on arbitrary tabs.
  • scripting: Used solely to inject the defensive content extractor script into the tab you have chosen to audit. The script extracts publicly visible HTML elements (headings, buttons, CTAs, and visible body copy) to diagnose conversion health.
  • storage: Used strictly to save your account API authentication token, white-label agency branding profile (e.g. your agency name, email, and Calendly link), and recent audit history locally on your device within chrome.storage.local.

3. Data Collection & Processing

When you trigger an audit, AuditPilot transmits the following page data to our secure backend API:

  • The public URL and domain of the audited webpage.
  • Extracted public DOM text, including page title, heading tags (<h1>–<h6>), button label copy, and visible text sample.
  • Client viewport dimensions and layout heuristics.

Zero Sensitive Data: AuditPilot specifically ignores and filters out input passwords, form field inputs, payment card details, cookies, and local session tokens.

4. AI Provider & Inference Safety

Audit analysis is processed using enterprise LLM API endpoints (such as Google Gemini and OpenAI). Page text transmitted for inference is processed ephemerally to generate scores, roadblock evidence, and copy rewrites. In accordance with enterprise API data terms, customer audit data is never used to train public foundational AI models.

5. Data Retention & Deletion Rights

Audit deliverables and tokenized report links are stored securely in encrypted databases. You retain complete ownership of your generated audit reports. To request complete deletion of your user account, stored branding, and audit history, email our privacy team at privacy@auditpilot.dev.

6. Contact Information

If you have questions regarding this Privacy Policy or compliance with Chrome Web Store Developer Program policies, please contact:

AuditPilot Legal & Compliance Team
Email: privacy@auditpilot.dev
Website: https://auditpilot.dev