Trust center: data, AI use and security at Specoria
What we measure, which data we process and who processes it for us, where we use AI and where we don’t, and how to reach us about security. Plain language; the privacy notice, the Terms of Service, the sales documents and the Data Processing Addendum are the binding texts.
Our principles
No claim without measurement
Scores come from fixed, published rules (score model v2.4). A criterion we couldn’t verify never counts as passed, and never as zero.
Nothing published without your approval
We have no write access to your store or website today. Fixes are code and steps that you or your team apply; we never post, publish or change anything in your name. Optional write-back to Shopify and WooCommerce is coming: each change only with your approval, with one-click undo.
The simulator stops at checkout
Agents we send never place orders, pay, or type personal or card details; on hotel and service sites they type nothing into forms and never submit them.
Your data doesn’t train AI
We don’t train AI models on your data, and we don’t sell it or hand it to anyone for training. Every model call through OpenRouter carries a setting that routes it only to providers that, under their policies as listed by OpenRouter, don’t train on prompts.
We say who we are
One request of the free test identifies itself openly as SpecoriaBot; we never impersonate another company’s bot.
Open prices, easy cancellation
Prices are on the pricing page. You cancel from the panel in one click; your plan stays open until the end of the paid period.
How we use AI
AI helps us test your site the way shopping agents do. It doesn’t decide your score.
- Agent simulator
- AI models drive a real browser on your public site, like a customer: search, open a product or room, choose options, go as far as checkout or a form, and stop there.
- AI visibility measurement (paid plans)
- We ask ChatGPT, Perplexity and Gemini questions through their official APIs (8 questions by default, each asked 3 times) and record whether your brand appears and which sources are cited.
- Free test, one small call
- The free test may make one small model call to phrase the product category and a realistic shopping question, and to read return and shipping wording that our rules couldn’t parse. The values it returns are checked; if the call fails or the budget is used up, the test continues on rules alone.
Where we don’t use AI
- Computing your score and deciding whether a check passed: both are rules in code, versioned, the same for every site.
- Writing to your store, sending messages or submitting forms on your behalf.
- Making up figures: every statistic on our site carries its source and date, and our own measurements carry the sample size.
What goes into model calls
- Content and screenshots of your public pages, product or category names, our test questions, and the task you write yourself for a live simulation.
- We don’t put your account details (name, email, payment data) into model calls. Model spend is capped per project, and free use has an overall cap.
What data we process
- Free test: only the scanned domain and the check results are stored on our side; nothing that identifies you. Your browser keeps a copy so the page can show it.
- Your IP address isn’t stored. The public simulator keeps a salted one-way hash of it, only to enforce the daily run limit.
- Server logs for agent traffic analysis, uploaded or (on paid plans) sent continuously: the full IP is read only in memory to check a bot against its provider’s published IP ranges, then cut to its network (/24 for IPv4, /48 for IPv6); query strings are dropped, and continuously sent logs are kept only as hourly totals.
- Deep audit and project panel: the email you give us, your account, and what we measure on your public pages, including screenshots of the real-browser steps.
- Payments: taken through Stripe only; card details go directly to Stripe and never reach us.
Read the full privacy notice →
Sub-processors
Providers that process data on our instructions to run the service. We don’t sell data.
| Provider | What for | What data | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database, file and backup storage, security; the bot check on our forms (Turnstile); the real browser used by audits and the simulator; cookieless usage counting (Workers Analytics Engine) and cookieless site analytics (Web Analytics) | Everything the service stores; pages and screenshots of the sites we test; connection data during a visit (IP address, briefly, for security) | USA; Cloudflare’s global network |
| Resend | Sending service emails (reports, confirmations, invitations, password resets, subscription notices) and the newsletter to people who opted in | Email address, name (if given), email content, delivery records | USA; sending from the EU region (Ireland) |
| Stripe, Inc. and its affiliates | Card payments, subscriptions, refunds and fraud prevention (for some processing Stripe acts as an independent controller) | Email, name, billing details, card details (entered directly with Stripe, never reaching Specoria), payment records | USA, Ireland |
| OpenRouter, Inc. | Access to AI models for the simulator, visibility measurement, audits and the free test’s small call. Every request carries data_collection: deny, so OpenRouter routes it only to providers that, under the provider policies it lists, don’t collect prompts or train on them | Public page content and screenshots, measurement questions, the simulation task you write; never your name, email or account details | USA |
| AI model providers (Anthropic, OpenAI, Google, Perplexity) | Run the models: through OpenRouter or, when enabled experimentally for the simulator, through their own APIs (the provider’s API terms then apply) | Same as OpenRouter | USA |
Stripe receives data only when you pay. Transfers outside Türkiye rely on the standard contracts required by Turkish data protection law (Law No. 6698, article 9) and, where it applies, the GDPR safeguards. The full list, with transfer safeguards and the services you connect yourself, is on the Subprocessors page. Subprocessors →
How long we keep data
- Report and deep audit requests: up to 2 years, then deleted automatically.
- Your email and name on a deep audit: deleted automatically after 2 years; results measured from your public pages stay with the project.
- Panel account: until you ask us to delete it.
- Invoices and subscription records: 10 years, as Turkish tax and commercial law requires.
Security
- HTTPS everywhere, with HSTS. Our pages run only our own scripts, plus Cloudflare’s bot check on forms (Turnstile) and its cookieless analytics beacon, all allow-listed in our Content Security Policy; other sites can’t frame them.
- Passwords are stored only as one-way hashes; panel sessions use __Host- cookies; sign-in attempts are limited.
- Forms are protected by rate limits and a bot check.
- We read only public pages of the sites we test, with small GET requests; no logins, no form submissions.
Certifications
We don’t hold security certifications such as ISO 27001 or SOC 2 today, and we don’t show badges we don’t have. If that changes, it will be stated here with the certificate’s scope and date.
Security contact
Found a vulnerability or something that looks wrong? Write to contact@specoria.com with the details, the time and the address involved. We’ll confirm we received it and keep you posted. Please don’t access other people’s data or disrupt the service while testing. Our contact details are also published in /.well-known/security.txt.
Your rights and requests
To see, correct or delete your data, or to withdraw consent, write to contact@specoria.com. We answer within 30 days, free of charge.
Don’t want your site tested? See how to opt out on our crawler page →