SCANNER
How the scan works
We check how websites set up their tracking and consent, the same way any visitor's browser would see it. If our scanner visited your site, it read your home page and a handful of public files, from the outside, once. It signed in to nothing, filled in nothing, and read nothing behind a login.
Below is what it fetched, what it cannot see, how to recognise it in your logs, and how to have us stop and delete what we hold.
What we read
For a single website, in one pass, we fetch:
- your home page;
robots.txt,ai.txt,llms.txt, and your sitemap;- one plain
http://request to your site; - your Google Tag Manager container file — the public file every visitor's browser downloads, fetched from Google's own servers at
googletagmanager.comrather than from you; - your public DNS records — address, mail, SPF, DKIM, DMARC — read from public DNS, not from your server.
We also load the home page once in a real browser. That renders the page the way a visitor's browser does, so your own analytics will record it as one visit. It is also how we take the picture of your home page that appears on a results page.
What we cannot see
- Anything behind a login. We have no credentials and we do not attempt any.
- Any form. We do not submit them and we do not fill them in.
- Any page other than your home page, when we are checking a site nobody asked us about. A visitor who asks for a check of their own site gets their own page checked.
- Anything about your visitors. We see what your tags are configured to do. We do not see who came to your site, and we do not receive your analytics unless you grant us access yourself.
- Anything behind a bot wall. If your site refuses automated visitors, we record that it does and move on, ungraded — we do not rotate through a pool of addresses to get around it. The one thing we do try is reading the page from an ordinary home internet connection, described below.
What we store
The result of the check: which tools we found and their account IDs, your container IDs, whether a consent platform was detected, the DNS and security-header findings, and the score. When somebody asked for a check of your site — the case where we load it in a real browser — we also keep a picture of the home page for their results page. A site we looked at on our own gets no picture, because that pass never opens a browser. We keep one result per website address, and a new check replaces the old one.
No page on our site lists the sites we have checked, and no result is published. One thing worth saying plainly rather than letting you find it: a home-page picture is served from a plain web address with no sign-in on it. It is a photograph of a public page, so there is nothing in it a visitor could not see — but it is not behind a lock, and we would rather tell you that than call it private.
We never take a name, an email address or a phone number off a page we read, and we never build a mailing list out of one. Our own outreach goes only to people who already subscribed to us.
How our scanner identifies itself
Our fetches carry this user agent:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 CleanDataRoadmapBot/1.0
The part to match on is CleanDataRoadmapBot.
Some visits come from an ordinary home internet connection, in a normal browser. Those look like an ordinary Chrome visitor, because that is what they are — a real browser on a real connection. That is the one case where you will not see our token in your logs.
How often
- If someone asks for a check of a site, we run it then. A recent result is reused rather than fetching your site again, and so is a recent picture of your home page.
- For our own research we read one page per site, as a plain fetch rather than a browser, and we read a small number of sites at a time. We do not crawl a site.
If you connect Google
The paid roadmap can read your own Google Analytics and Tag Manager, and only if you approve it. Two read-only permissions, and nothing else.
https://www.googleapis.com/auth/analytics.readonly— view your Google Analytics datahttps://www.googleapis.com/auth/tagmanager.readonly— view your Google Tag Manager containers
Neither can write. We cannot change a tag, a property or a report, and there is no code path in the app that tries. What we read with them:
- Your GA4 settings. The property's name, currency and time zone; your data streams and their enhanced-measurement settings; your Google Ads links; your BigQuery links; your custom dimensions, custom metrics and key events.
- Two aggregate reports, over the last 28 days. Event names with their counts and values, and session source, medium and campaign with session counts. Totals only — no user ID, no client ID, no page-by-page history, no demographics, no audience.
- Your live Tag Manager container. Its tags, triggers and variables, as published.
- One browser reading of your site. We load it and record the tracking requests it makes. The page's own HTML is read in memory and not kept, and a stored request URL keeps only the account-identifier parameters — the visitor identifiers other tracking tools would keep are dropped.
Disconnect Google whenever you like, from your site's page in the app or from your own Google account. Either one stops any further reading. What we have already read, and how long we keep it, is in the privacy policy.
How to ask us to stop
Tell us which domain it is, and show us you speak for the site — a message from an address at that domain is the simplest proof. Write to us at app@measureu.com. We will stop checking it, and delete what we have stored about it if you ask in the same message.
We keep that list by hand today, so a person reads your message and acts on it. Worth knowing before you try something faster: we read your robots.txt, but we do not yet treat it as an instruction — so a rule in there will not stop us, and we would rather tell you that than let you think the job was done.
What we will not do with it
We do not sell it. We do not pass it to advertisers or data brokers. When we publish research from it, we publish counts and percentages only — never a named site, and never a group smaller than ten sites.
Contact
Removals, opt-outs, a question about a visit in your logs, or a security report — write to us at app@measureu.com.
What we hold and what we do with it is in the privacy policy. What you get when you buy is in the terms.