← ZUPZUP Analyzer

Privacy notice

Last updated: September 11, 2026

Core page analysis

The 84-check analyzer runs in your browser. It reads the current page structure and metadata to calculate diagnostics. It does not send passwords, form entries, cookies, session tokens or browsing history to us.

Operational data

On each analysis, we receive the hostname, page title, four-axis scores, the total number of failed issues, and up to 100 failed issue IDs with their weights. A truncation flag records whether the size limit omitted any issue IDs. The event also records the analyzer-set version, whether the page was classified as an article or a generic page, and each core analyzer's outcome: detected, clear, not applicable or check failed. Resource counts are included only when an analyzer measures them directly. We do not receive page body text, affected-element HTML or fix examples in this event. We also do not put an IP address, account or advertising identifier in the application event. Cloudflare may still process standard request metadata under its own policy to deliver and secure the service.

Optional AI question generation

Only after you select “Create five free questions,” we process the normalized public URL, title, H1 and up to 1,500 characters of visible page text. Navigation, headers, footers, forms, controls and hidden areas are excluded in the browser; email, phone and token-like strings are redacted on the server. Private addresses and sensitive account or payment paths are blocked. The context is sent through a dedicated Oracle Cloud relay to Anthropic Claude. We do not store the excerpt in our database. Generated questions, a context hash, cache and abuse-prevention records may be retained for up to 30 days.

Pulse Trial and citation checks

When you connect a Trial, we process your email, target public URL and domain, consent version, client type and a hash of a random installation identifier. For an explicit citation check, your selected questions, brand terms and target public URL are sent through a dedicated Oracle Cloud runner to OpenAI Codex web search. We store citation status, source URLs, result summaries, usage, question sets, report snapshots and change history in the connected Pulse workspace. Raw activation tokens are not stored in our database.

To reconnect a Pulse Trial or paid bookmarklet by email, we match a SHA-256 hash of the normalized address to an existing license. The submitted address is used to request the verification email and is not stored in the connection-intent table. Before confirmation, the connection token remains in browser storage for up to 30 minutes. After connection, it is included in the personal bookmark URL and may sync to other devices under the browser's bookmark-sync settings. Only the token hash is stored on the server.

The Trial write window starts on the first successful citation check and lasts 15 days. New snapshots and observations stop after that window. Existing dashboard data and history stay available read-only for a further 90 days. At the end of that read window, a non-converted Trial's raw email, target URL, questions, citations, snapshots and connection sessions are deleted or redacted automatically. We retain only a pseudonymous SHA-256 marker of the normalized email to prevent a duplicate Trial. A connected Trial that never starts a citation check receives the same treatment within 30 days after its connection window closes; an unverified Trial request is scrubbed after at most 30 days. Paid-customer records are retained as needed to provide the service, handle deletion requests or disputes, and meet legal obligations.

Aggregate acquisition events

When explicitly enabled for an environment, product, installation, SEO acquisition, Pulse and Trial pages record visits, store-link clicks, bookmarklet clicks or drags, installation-guide visits and demo clicks. A measurement version distinguishes legacy install_click/bookmarklet_click from extension_store_click, bookmarklet_action and bookmarklet_guide_click. Clicks do not prove installation or analysis completion. Events contain only allowlisted campaign values, landing path/version, interaction type, test status and a one-use random event ID. To preserve campaign context during navigation, campaign values, test status and an expiry time are stored in the same tab's session storage for up to 30 minutes. Expired context is removed on the next access; closing the tab clears it. Blocking storage does not prevent product use. We do not create an advertising identity in cookies or persistent local storage, or send referrers, advertising click IDs, email, analyzed URLs, page content or questions in these events. Store links carry only campaign source, medium and campaign for aggregate installation reporting. We do not create an identifier that follows a person from the landing page into the Chrome Web Store. An IP hash used only for request limiting expires within one hour and is not written to the application event. Detailed acquisition and Trial conversion events are retained for up to 180 days.

Invite-only Pulse experience interviews

Only after an invited user explicitly agrees and responds, we process descriptions of the job that prompted signup, previous workflows, product experience, actions after seeing a result, repeat-use conditions, plan-choice reasons, and an optional follow-up interview choice. Responses are linked to the internal identifier of the existing Pulse account; the page does not ask the user to enter an email address or target URL again. We store only a SHA-256 hash of the invitation token, not the raw token. The response page does not use Google Analytics or a third-party survey provider. Users may request access or deletion at support@vlyvly.me.

Service providers

We use Cloudflare for hosting, APIs, data storage and security; Oracle Cloud Infrastructure for the dedicated AI relay and runner; Anthropic Claude for question generation; OpenAI Codex for requested web citation observations; Resend for Trial, paid-bookmarklet and contact email; and Google Analytics (GA4) for aggregate page traffic and clicks on the extension-install or bookmarklet-start buttons. GA4 may process page views, acquisition source, device, operating system and start method under Google's cookie policy. We do not send the analyzed URL, page content or questions from the extension or bookmarklet to GA4. Each provider's processing is subject to its policy and the account or product settings used by VLYVLY.

Contact requests

If you use the contact form, we process the name, email address, message, analyzed URL and category you submit so we can reply. The paid-pilot form may also collect an optional phone number only when you want a call.

Retention and choices

We retain service data only as needed to provide, secure and improve the product or meet legal obligations. We do not sell personal information or send marketing email without a separate choice. You may request access, correction or deletion by emailing support@vlyvly.me.

Chrome extension permissions

The extension does not request persistent host access or the storage permission, and it does not inject a content script automatically. A random installation identifier and activation token are stored in the extension's own IndexedDB. The extension does not collect browsing history in the background or create an advertising identifier.

Product feedback

If you open Send feedback and consent to respond, we collect your optional company or brand name, email address, product experience, and willingness to take part in follow-up research. We also record whether the form was opened from the bookmarklet, extension, or a direct link, plus the app version. The page being analyzed and its content are not sent with the feedback. Unfinished responses are retained for up to 30 days; submitted responses and contact emails are retained for up to one year. You may request access or deletion at support@vlyvly.me.

Publisher

ZUPZUP Analyzer is published by VLYVLY. Questions about this notice can be sent to support@vlyvly.me.