Privacy Policy

Version 2026-10 · Effective 1 October 2026 · Anvilfy Ltd

In short

  • Anvilfy Ltd is responsible for your personal data when you use EyeCaptain.
  • We collect what we need to run your account, produce your reports, take payment and, with your permission, send you news.
  • We do not sell personal data. We do not use your content to train third-party AI models.
  • You can access, correct, delete or export your data and object to marketing at any time by writing to hello@eyecaptain.io.

This summary is for convenience and is not part of the privacy policy.

01Who we are

EyeCaptain is operated by Anvilfy Ltd, a company registered in England and Wales (company number 17352045), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the controller of the personal data described in this policy.

Contact us about privacy at hello@eyecaptain.io.

This policy explains how we handle personal data under the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR) and, where it applies, the EU GDPR.

02When we are a controller and when we are a processor

We are the controller for data about our website visitors, account holders, team members, leads and customers, as described below.

When you ask us to analyse a web page, the page may contain personal data about other people (for example names, photos or reviews). We process that data only to produce your report, on your instructions, and act as your processor. The Data Processing Addendum governs that processing. If you are a person whose data appeared on a page someone analysed, please contact the owner of that website or our customer; we will help them respond.

03What we collect

CategoryExamplesWhere it comes from
Account dataName, email address, password (stored hashed), company, role, language, two-factor settingsYou, or Google if you sign in with Google
Workspace and team dataWorkspace name, invited members and their roles, client foldersYou and your team
Content and reportsURLs you submit, business context you enter, screenshots and content of analysed pages, generated reports, share linksYou and the pages you ask us to analyse
Billing dataBilling name and address, VAT number, plan, invoices, payment status (card details are held by Stripe, not us)You and Stripe
Free audit and newsletter dataEmail address, the URL you audited, whether you opted in to the newsletterYou
CommunicationsMessages to support, the website chat, booking requests, sales enquiriesYou
Connected servicesIf you connect Google Analytics or Google Search Console: account and property identifiers and the analytics data you choose to import, plus access tokens (stored encrypted)Google, with your authorisation
Usage and device dataPages viewed, features used, IP address, browser and device type, referring page and campaign parametersYour browser, our servers, and cookies where you allow them
Business contact enrichmentPublicly available professional information such as job title, company and LinkedIn profile URLPublic web sources and business data providers such as Apollo.io

We do not knowingly collect special category data, and we ask you not to submit it. The Service is not intended for children under 18.

04How we use it and our legal bases

PurposeLegal basis
Creating and running your account, producing reports, providing supportContract
Taking payment, invoicing, keeping accounting and tax recordsContract and legal obligation
Sending your free audit results and service messages (security, billing, report ready)Contract, or our legitimate interest in delivering what you asked for
Newsletter and product newsYour consent, or for existing customers our legitimate interest in telling you about similar services (you can opt out in every email)
Onboarding and lifecycle emails that help you get value from your accountLegitimate interests (you can opt out)
Business contact enrichment to understand who our leads and customers areLegitimate interests (you can object at any time)
Website analytics and marketing cookiesYour consent through our cookie banner
Counting visits without cookies when analytics is off (a one-day hash, nothing stored on your device, no IP address or account kept; see the Cookie Policy)Legitimate interests in knowing how the site is used
Preventing fraud and abuse (for example limits on free audits and referral rewards), securing the ServiceLegitimate interests
Improving the Service with aggregated, de-identified statisticsLegitimate interests
Complying with law and responding to lawful requests; establishing or defending legal claimsLegal obligation and legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights. You can ask us for details at hello@eyecaptain.io.

05AI and automated processing

Reports are produced by sending the content and screenshots of the analysed page, and the business context you give us, to AI models through our providers listed on the Sub-processors page. We do not use your content to train third-party AI models and choose provider settings that do not allow it where available.

We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. Automated checks limit free audits and detect abuse; if you think one has affected you wrongly, contact us and a person will review it.

06Google user data

If you connect Google Analytics or Google Search Console, we only request read access, use the data only to show it to you inside the Service and to inform your reports, and do not transfer it to others except as needed to provide the Service, comply with law, or with your consent. We do not use it for advertising and do not allow humans to read it except with your consent, for security, or to comply with law. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect at any time in your settings or in your Google account.

07EyeCaptain for Chrome

Our browser extension works only on the tab you open it on, and only when you click its icon, press its keyboard shortcut or choose it from the right-click menu. It does not read your browsing history, other tabs, or pages in the background. The one exception is a funnel you choose to record, described below.

When you run an audit with it, it captures that page as your browser shows it: screenshots, the visible text, the layout and position of elements, colours, and the page address and title, together with the window size and browser language. Before capturing, it clears what you typed into form fields and puts it back afterwards, so those values are neither photographed nor sent. A page you are signed in to can still show your own details (for example your name or basket); do not audit a page that shows personal information you do not want in a report. What it sends is processed and kept exactly like any other audit.

A Quick Check reads the same kinds of information from the page (the text, position and colours of its buttons, headings, prices, ratings, forms and images, and how many fields each form has, never what is typed in them) and takes one screenshot of the first screen. We keep the result, the page address and the counts for your account's history and the daily free allowance; the screenshot is sent to our AI provider for the check and is not stored by us.

The extension works with an EyeCaptain account. Until you connect one, it does not check or capture any page; it only offers to create an account or sign in. Heatmap, content and technical audits started from the extension send only the page address: our servers open the public page themselves, exactly as for audits started in the app.

When you record a funnel, you first allow the extension to see one site (Chrome asks you). While the recording runs, and only on that site in that tab, it notes the address and title of each page you open and the text of the link or button you click to move on. Form values are never read. When you press Stop it sends that path to your account to run the analysis, and removes the site access. Cancel discards the recording.

Findings you choose to show on a page are drawn by the extension inside that tab only; the page itself cannot read them.

The popup can show short EyeCaptain offers in a rotating banner (our own, never third-party ads). To choose them, the extension asks our server for the current offers, with your account's access token when a browser is connected so we can tell a Free plan from a paid one; nothing about the page you are on is sent. We count when an offer is shown, clicked or hidden, together with the offer's tracking code and a random id the extension makes for that browser (it is not linked to the pages you visit and it contains nothing about you). The offer's link carries the same tracking code in its UTM tags. When you connect the browser to an account, we link that random id to the account, so we can tell which offer led to a sign-up, a free CRO audit or a purchase. We use this only to measure our own offers. Closing the banner hides it for 24 hours; that choice is remembered on your computer only.

In the browser it stores only an access token for your account (never your password), your last choice of account, workspace and report language, the audits and funnel analyses you started until they finish, a funnel while you are recording it, your last Quick Check result for each open tab until the browser closes, which offers you have seen or hidden, and the random id described above (removed with the extension). The access token stays valid while you use the extension and expires after a year without use. You can disconnect a browser at any time in Settings > Chrome extension, or remove the extension.

The use of information received through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements: it is used only to provide the audit you asked for, it is not sold, not used for advertising or to determine creditworthiness, and people do not read it except with your permission, for security, or to comply with law.

08Who we share it with

  • Service providers who process data for us under contract, listed on our Sub-processors page (hosting, capture, AI models, payments, email).
  • People you choose: anyone you give a share link or embed to, and members of your workspace.
  • Professional advisers such as accountants, lawyers and insurers, under confidentiality.
  • Authorities where the law requires it.
  • A buyer or successor if our business or its assets are sold or reorganised, under the same protections.

We do not sell personal data and do not share it for cross-context behavioural advertising except through the advertising cookies you allow.

09International transfers

Our main database is hosted in the European Union (Frankfurt). Some providers process data in the United States and other countries. When personal data leaves the UK or the EEA, we rely on adequacy regulations or decisions (including the EU-US Data Privacy Framework and its UK Extension where the provider is certified), or on the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, with supplementary measures where needed. You can ask us for a copy of the relevant safeguards.

10How long we keep it

DataKept for
Account, workspace, content and reportsWhile your account is open. Deleted within 30 days after you close it or ask us to, and from backups within a further 90 days
Working files from an analysis (raw page captures and intermediate screenshots the report does not show)30 days after the analysis finishes. The report and its page screenshots stay with the account
Free audit reports and leads without an account12 months after your last interaction, unless you ask us to delete them sooner
Billing and accounting records6 years after the end of the financial year they relate to, as UK law requires
Marketing preferences and suppression listsAs long as needed to respect your choice not to receive marketing
Support, chat and sales messagesUp to 2 years after the conversation ends
Website analyticsUp to 6 months in our own systems. Google Analytics keeps event data for 14 months
Security and audit logsUp to 6 months
Server, error and delivery logsUp to 3 months

11Your rights

You have the right to:

  • access the personal data we hold about you and get a copy;
  • correct data that is inaccurate or incomplete;
  • have your data deleted in certain circumstances;
  • restrict or object to our processing, including at any time to direct marketing and to processing based on legitimate interests;
  • receive data you gave us in a portable format;
  • withdraw consent at any time, without affecting processing that happened before.

To use your rights, write to hello@eyecaptain.io from the email address on your account. We may ask you to confirm your identity. We reply within one month, which we can extend by two months for complex requests, and we will tell you if we do. There is no fee in most cases.

You can also delete projects and your account in the app, change email preferences from the link in any email, and change cookie choices at any time from the cookie settings.

If you are unhappy with how we handle your data, please contact us first. You have the right to complain to the UK Information Commissioner's Office (ico.org.uk, 0303 123 1113) or, if you live in the EU, to the data protection authority where you live or work (in Greece, the Hellenic Data Protection Authority, dpa.gr).

12Security

We protect personal data with measures that include encryption in transit, encryption of stored access tokens, access controls and row-level security in our database, two-factor authentication for accounts that enable it, rate limits and logging. No system is perfectly secure; if a breach affects your data and is likely to create a high risk to you, we will tell you without undue delay.

13Cookies

We use strictly necessary cookies to run the Service and, only with your consent, analytics and marketing cookies. Details and choices are in our Cookie Policy.

14Changes to this policy

We will update this policy when our processing changes. If a change is significant, we will tell account holders by email or in the app before it takes effect. The version and date are at the top of this page.

15Contact

Anvilfy Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Email: hello@eyecaptain.io.