Privacy
This page says what Crownler collects, what each piece is for, who we share it with and what you can ask us to do. It is written for someone who works in marketing, not for a lawyer, and every line describes what the system does today.
Last reviewed 2 September 2026
The short version
This site has no tracker, no third party pixel and no advertising cookie. When you open a page on crownler.com, no request leaves for another company: the fonts, the brand mark and the sharing image are our own files.
We do not sell anyone's data, we do not build a market database out of what our clients analyse, and we do not use client data to train AI models.
Everything we keep is listed below, situation by situation. Each line describes what the software does today, not what would be nice for it to do.
Who answers for this data
Crownler is run by the company behind the product, which decides what is collected and why. Brazilian law calls that the controller; so does the GDPR.
To talk about your data, use the form on this site or the support desk inside the app, which opens a ticket with the team. We do not publish an email address on an open page because spam robots harvest them, and a message lost in a spam folder is not a channel.
- Legal name
- NETLINKS CORP.
- Company registration
- Folio 155762268 · RUC 155762268-2-2025
- Address
- 50th Street, PH Plaza 2000, 17th Floor, Panama City, Republic of Panama
- Data protection officer
- NETLINKS CORP., through the contact form on this site
When you only visit the site
The public pages set no cookies. There is no Google Analytics, no social network pixel, no heatmap and no session recorder on this site.
The server that delivers the pages runs on Google Cloud and keeps an access log, the way any web server does: IP address, browser, page requested, date, time and response code. It is there to diagnose errors and to contain abuse, and nobody uses it to build a profile of a visitor.
Fonts are served from our own domain, so opening a page here does not tell any other company that you were here.
When you leave your details in the form
The form on this site is the only door that stores anything before you have an account. Field by field, this is what it keeps.
- Name and email
- Required. They are how we reply.
- Company
- Optional.
- How you work
- Agency, company, consultant or other. It changes the conversation: an agency asks about a portfolio and white label, a company asks about one site.
- How many sites you would follow
- Optional, a number.
- Message
- Optional, whatever you want to write.
- Language and page of origin
- Which language you were reading in and which page you sent it from. The language decides which language your confirmation arrives in.
- A code derived from your IP address
- Not the address: a one way code (SHA-256 with a secret that lives on the server). It exists for a single count, how many submissions came from the same place in the last hour, and the cap is five. Without the secret the code does not turn back into an address, and the address itself is never stored.
The contact is stored first and the emails go out after: a notice reaches the team and a confirmation reaches you, in the language of the page you were reading. Replying to that message goes straight to the person who will answer you. The basis for handling it is your own request to be contacted and our legitimate interest in replying. If you no longer want to be on that list, ask and we delete it.
When you use the app
Here there is already an account and a workspace, and what we keep is what makes the product work.
- Your account
- Name, email and the date of your last sign in. The password is handled by Google Identity Platform and never reaches us: we do not store it, do not see it and cannot recover it.
- The workspace
- Name, plan, limits and, when an agency turns white label on, its brand: logo, colours and signature.
- Who has access
- The people invited, the role each one holds and which projects they reach.
- The projects
- The sites you follow, the clients they belong to and everything the product measures about them.
- Usage
- Every paid call that goes out (provider, model, tokens and cost) becomes a log line. That is how the monthly allowance is counted and how the numbers add up.
- Support
- The ticket you open, the messages in the conversation and the screen you were on when you opened it.
- App cookies
- Three, all functional: the session, the active workspace and the language you picked. None is for advertising and none travels to a third party.
What the tool reads from the site you analyse
Our crawler identifies itself as CrownlerBot/0.2 and obeys the robots.txt of the site. It reads public pages: address, title, text, internal links, outgoing links and whatever the technical audit rules need to check.
Search Console and Analytics are optional and connected by you, with your own Google account, in read only permission and nothing else. The authorisation is stored encrypted and you can revoke it whenever you want, inside the app or in your Google account.
If a public page on the analysed site carries personal data, it comes in with what was read. We do not look for it, do not separate it and do not use it for anything beyond that project. If you are an agency, you are the one who answers for your client's data and we handle it on your instructions.
Who we share it with, and what for
No data is sold, traded or handed over for advertising. What exists are suppliers who do one part of the work, and each of them receives only the piece it needs.
- Google Cloud
- Where the product runs and where the data lives: Cloud Run, Cloud SQL, Cloud Storage, Secret Manager and Identity Platform.
- Google Vertex AI
- The Gemini models, which draft content and read pages.
- Anthropic
- The Claude model, used in writing and in measuring presence in AI answers.
- OpenAI
- The GPT models, used to measure presence in ChatGPT and to generate images.
- DataForSEO
- SERP, backlinks and search volume, bought at the moment of the click. It receives the query and the domain, never data from your account.
- Google Search Console and Google Analytics
- Only when you authorise it, read only, and only what your own account already reaches.
- Google PageSpeed Insights
- The speed measurement of a page, when you ask for it.
- Google Workspace
- The delivery of the product's emails.
The AI calls go out through those suppliers' business APIs, whose default is not to train models on what is sent. We do not authorise training on client data anywhere.
Where the data sits
Application, database and files sit on Google Cloud, in the us-central1 region, in the United States. The AI and search data suppliers process wherever their own infrastructure is.
If you are in the European Union, that is an international transfer. It happens under the European Union standard contractual clauses, which are part of those suppliers' contracts.
How long we keep it
There is no automatic purge routine today. Deletion happens when someone asks for it, done by a person on the team.
- Details left on this site
- For as long as the commercial conversation makes sense. Ask us to delete it and we delete it.
- Account and workspace
- For as long as the account exists.
- What the product measured
- The measurement history does not delete itself, by design: it is what lets the product say the position is 4 today and was 7 thirty days ago. It dies with the project.
- Access and cost logs
- Kept for security and for accounting.
- After you leave
- You can export reports and deliverables before going. Once deletion is requested, we delete what can be deleted within 30 days and keep only what the law requires us to keep.
Your rights, and how to use them
Brazilian law (LGPD) and the European GDPR say almost the same thing in different words. In plain terms, you can do this.
- Know what we hold
- Ask what exists about you and where it came from.
- Correct it
- Fix what is wrong or out of date.
- Delete it
- Ask us to erase what we are not required to keep.
- Take it with you
- Reports, deliverables and your workspace's own API export what is yours, in a format another tool can read.
- Withdraw an authorisation
- Disconnect Search Console and Analytics, in the app or in your Google account.
- Object and complain
- Object to a use you disagree with, and complain to the authority: the ANPD in Brazil, your country's data protection authority in Europe.
The way to ask is the form on this site or the support desk inside the app, which opens a ticket with the team. We check who is asking before touching someone else's account. Where the law sets a deadline, we meet the deadline the law sets. We do not invent one here, because a promised turnaround written into a system is a debt on the first busy day.
How we protect it
No system is unbreakable. If an incident happens with risk to you, we tell you and we tell the authority, and we say what actually happened.
- Passwords
- Handled by Google Identity Platform. We do not store passwords.
- Session
- A host cookie, httpOnly, tied to the app subdomain. The public site cannot reach it, which is why the app lives on a subdomain of its own.
- Google authorisation
- The long lived token is encrypted with AES-256-GCM and the key lives in Secret Manager.
- Secrets
- API keys and supplier credentials live in Secret Manager, never in code and never in a log.
- Access
- Which workspace you belong to and what you may see is checked on every request, not once at sign in.
Under age
Crownler is a work tool and is not meant for minors. We do not knowingly collect a child's data. If you learn that an account was opened by a minor, write to us through the form and we delete it.
When this page changes
The date at the top says when this text was last reviewed. A change that alters what we do with your data is announced by email to clients before it takes effect.
Something missing
If a line here does not answer what you need to know, ask. It reaches the same people who built the product.