Privacy Policy

Last updated: 23 July 2026

Litmus by Aivirex ("Litmus", "the Service", "we", "us") is operated by AiViREX Innovations LLP, registered office at 24th Street, Shankar Nagar, Pammal, Chennai, Tamil Nadu 600075, India. This Privacy Policy explains what personal data we collect through litmus.aivirex.in, why, how long we keep it, and the rights you have over it. We act as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, for visitors in the EU/EEA/UK, as a Data Controller under the GDPR.

We do not rely on "by using this Service you agree" as a basis for any processing that requires consent. Where consent is the legal basis (cookies, analytics, session recording), we ask for it first, via the cookie banner, and you can withdraw it at any time from the "Cookie Settings" link in the footer.

1. What Litmus does, in plain terms

You submit a URL. We crawl the publicly accessible pages of that site (HTML, robots.txt, sitemap, JSON-LD, rendered DOM) and run deterministic, rule-based scoring against it — no data about the site is sent to a third-party LLM. We show you the result and, if you choose, let you export it as a report.

2. Data we collect

2.1 Account data

Sign-in is via Google (Firebase Authentication). We receive your name, email address, and profile picture from Google — we never see or store your Google password. We store your Firebase user ID, email, current credit balance, and plan tier.

2.2 Scan data — your submissions

The URL(s) you submit, any competitor URLs you optionally add, your chosen scan depth, and the resulting audit (scores, flagged issues, recommendations, page-level detail, Lighthouse metrics). Only the latest 3 results per site you submit are retained; older scans of the same site are deleted automatically when a newer one completes.

2.3 Data collected from the site you ask us to scan

To score a site, our scanner reads whatever that site has already published publicly — page text, headings, meta tags, structured data (JSON-LD), and, where present, an author/byline name or social profile links ("sameAs") the site itself displays. This is the target site's own public content, not personal data you gave us about yourself, and we use it for exactly one purpose: computing that scan's score. We don't compile it into profiles, cross-reference it against other scans, or use it for any purpose beyond the audit you requested. You must only submit sites you own or are authorized to audit — see the Terms of Service.

2.4 Payment data

Payments are processed by Razorpay. We never receive or store your card, UPI, or bank details — Razorpay handles those under its own PCI-DSS-compliant systems and its own privacy policy. We store the order ID, amount, currency, plan purchased, and credits granted, for accounting and support purposes.

2.5 Analytics & session recording (cookie-gated)

If you accept the cookie banner, we use Google Analytics 4 (page views, funnel events like scan started/completed, checkout started/abandoned, exports) and Microsoft Clarity (session recordings, heatmaps, click/scroll behaviour, and its AI-assisted session insights). Neither loads, and neither sets a cookie, until you accept.

2.6 Technical/log data

Our hosting provider, Netlify, logs standard request data (IP address, timestamp, requested path, user agent) for security, abuse prevention, and debugging.

3. Lawful basis for processing

PurposeDataGDPR basisDPDP basis
Providing the Service (account, scans, exports)Account data, scan dataContract — Art. 6(1)(b)Performance of contract
Processing paymentsOrder/plan dataContract — Art. 6(1)(b)Performance of contract
Product analytics & session recordingGA4 / Clarity dataConsent — Art. 6(1)(a)Consent
Security, fraud/abuse preventionServer/request logsLegitimate interests — Art. 6(1)(f)Legitimate use
Legal compliance, dispute defenceAccount, billing, scan recordsLegal obligation — Art. 6(1)(c)Legal compliance

4. Cookies and trackers

Name / toolPurposeRetentionConsent required
_ga, _ga_*Google Analytics 4 — sessions, page views, funnel eventsUp to 2 years (cookie); event data 14 months (GA4)Yes
Microsoft Clarity cookiesSession recordings, heatmaps, interaction dataRecordings: 90 daysYes
Firebase Auth sessionKeeps you signed inUntil logout / expiryNo — strictly necessary
Razorpay checkoutCompleting a paymentSessionNo — strictly necessary
Netlify server logsSecurity, abuse preventionStandard hosting log retentionNo — strictly necessary

Manage your choice any time via "Cookie Settings" in the footer, or by clearing your browser's local storage — your choice is stored only in your browser, not on our servers.

5. Who we share data with

We don't sell personal data. It is shared only with the processors needed to run the Service:

  • Google LLC / Firebase — authentication, database (Firestore), file storage, Google Analytics 4. Processes data in the US and other Google regions. See Google's Privacy Policy.
  • Microsoft Corporation — Clarity session recordings and analytics. Processes data in the US. See Microsoft's Privacy Statement.
  • Razorpay Software Pvt. Ltd. — payment processing. Data stays within India. See Razorpay's Privacy Policy.
  • Netlify, Inc. — application hosting and server logs. Processes data in the US and other regions. See Netlify's Privacy Policy.

We may also disclose data where required by law: to comply with a court order, to respond to a lawful request from a government or regulatory authority, or to establish, exercise, or defend legal claims. If Aivirex's business (or this product line) is sold or transferred, account data may transfer to the successor entity, who would remain bound by this Policy.

6. Cross-border data transfers

Google, Microsoft, and Netlify process data on servers outside India (and outside the EEA). For EU/EEA/UK visitors, these transfers rely on Standard Contractual Clauses approved by the European Commission. For Indian users, transfers are made in accordance with the DPDP Act, 2023.

7. Data retention

  • Account data — kept while your account is active. You can delete your account and all associated data instantly and irreversibly from the "Danger zone" on your Dashboard, or by emailing us (below). Accounts with no sign-in for 12 consecutive months are deleted automatically by a scheduled job, on the same terms as a self-service deletion.
  • Scan results — only the latest 3 per site are kept; earlier ones are deleted automatically when superseded. A scan's in-progress job record is deleted the moment it finishes (or, if the server crashes mid-scan, by an automatic expiry safety net).
  • Billing/order records — kept for accounting and tax compliance for as long as legally required.
  • GA4 analytics — 14 months, then auto-deleted by Google.
  • Clarity recordings — 90 days, then auto-deleted by Microsoft.
  • Netlify logs — standard hosting-provider log retention.
  • Cookie consent choice — stored only in your browser until you clear it.

8. Your rights

Subject to applicable law, you can:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Erase your account and data — instantly, via Dashboard → Danger zone, or by emailing us.
  • Port your data in a structured, machine-readable format (GDPR Art. 20).
  • Object to processing based on our legitimate interests (GDPR Art. 21).
  • Restrict processing in certain circumstances (GDPR Art. 18).
  • Withdraw consent for analytics/session recording at any time, via Cookie Settings — this doesn't affect processing that already happened lawfully.
  • Nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act §14).
  • Grievance redressal — raise a complaint with our Grievance Officer (§9); if unresolved, with the Data Protection Board of India.
  • Lodge a complaint with your local data protection supervisory authority (EU/EEA/UK visitors, GDPR Art. 77).

To exercise any of these, email contactaivirex@gmail.com with subject line "Data Rights Request". We respond within 30 days.

9. Grievance Officer

In accordance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act, 2023:

  • Title: Grievance Officer, AiViREX Innovations LLP
  • Email: contactaivirex@gmail.com
  • Address: 24th Street, Shankar Nagar, Pammal, Chennai, Tamil Nadu 600075, India
  • Response time: acknowledged within 5 business days, resolved within 30 days.

10. Security

We use commercially reasonable safeguards — Firebase's access-control rules and encryption in transit, Google/Microsoft/Razorpay/Netlify's own security programs — but no method of transmission or storage is 100% secure, and we can't guarantee absolute security. Anyone with access to production data (us, or a contractor we engage) is bound by confidentiality obligations.

11. Children's privacy

Litmus isn't directed at children. We don't knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us and we'll delete it promptly.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date above; where required by law, we'll also notify you by email.

13. Contact us

Questions about this Policy: contactaivirex@gmail.com.
AiViREX Innovations LLP, 24th Street, Shankar Nagar, Pammal, Chennai, Tamil Nadu 600075, India.