Last updated 20 August 2026
Who this covers
Three different groups of people show up in A/Bee, and what we hold about each is very different. The first group matters most, because those people never chose us.
- Visitors to a website that runs A/Bee. You did not sign up for anything. Our script was on a page you visited.
- People who run a free teardown. You pasted a URL and got a report back.
- Account holders. You signed up, and may be paying us.
- People we emailed first. You never contacted us. We looked at your website and got in touch.
1. If you visited a site that uses A/Bee
Our script records two things: which version of a piece of copy you were shown, and whether you completed an action the site owner asked us to measure, such as reaching a checkout or submitting a form. It also records the path of the page you were on.
So that you keep seeing the same version from one page to the next, we store a random identifier in your browser, in local storage with a cookie copy. It is a random string. It is not derived from anything about you, it means nothing on any other website, and it identifies a browser rather than a person.
We do not collect:
- Anything you type. Not form contents, not field values, not keystrokes, and nothing entered into a checkout or a payment field.
- Heatmaps, session recordings, scroll tracking or mouse movement.
- A profile of you, or any record that follows you from one site to another.
- Query strings. We record the path of a page and never the part after the question mark, so an email address or a token carried in a link is not captured.
- Your name, your email address, or any other contact detail.
We do not sell this data and we do not share it with advertisers. The site owner sees counts and results for their own site. If you would rather not take part, clearing your browser storage for that site removes the identifier.
2. If you ran a free teardown
We fetch the public page at the URL you give us, generate a report, and store the URL, the page name and the report itself so the link you get back keeps working. No account is required and we do not ask who you are.
Your IP address is used to rate-limit the scanner, so that one person cannot exhaust it for everyone. It is held only for the length of that rate-limit window, and it is not attached to the report or to any experiment data.
3. If you have an account
There is no password. You sign in with a one-time link sent to your email address, or with Google. We never ask you to create a password, so there is not one to store, leak or reset.
We hold what an account needs and nothing beyond it:
- Your email address. On this service that is your identity.
- Your name and profile image, if you signed in with Google and it gave us them.
- Short-lived sign-in tokens for the emailed links. They expire, and they are single use.
- A session cookie, which keeps you signed in until you sign out.
- Your Stripe customer reference and your current subscription status.
- The sites, experiments, goals and results you create, and when you last signed in.
We never see your card details. Payments go directly to Stripe, who hold the card number and the security code. We store a reference to your Stripe customer record and nothing else about the instrument.
We do not collect a postal address or a phone number, and we do not ask for one.
4. If we emailed you and you never signed up
We sometimes email business owners who have not heard of us, to offer them a free teardown. We look at a public website, run the same scan you can run yourself from this site, and write about what we found on it. There is nothing to buy and no account to make. If that is how you got here, this is what is behind it.
- Where your address came from. It was published on your own website or on a public business listing. We do not buy lists, we do not scrape private data, and we do not guess addresses.
- What we keep. The website address, the published contact address, and the report we generated for that page. Nothing else about you, and nothing from anywhere else.
- How to stop it. Reply once and say so, or use the unsubscribe link. We remove the address and do not contact it again. You do not have to give a reason.
- We do not sell or share these addresses, and we do not pass them to anyone else.
The other direction is worth saying plainly: we do not send marketing email to people who have accounts with us. If you sign up, the only email you get from us is about your own sites, experiments and billing. Creating an account is not consenting to a newsletter, because there is not one.
5. Who else sees any of it
- An AI provider. To write hypotheses and variations we send the text of the pages being tested, together with any brief you write, to a third-party AI provider. We currently use Google, and we may change or add providers as the models change. Do not put anything in a brief that you would not want processed by a third party.
- Stripe. Payments and subscription state.
- Cloudflare. Hosting, storage and content delivery.
- Our email provider. Account and transactional email.
That is the list. We do not sell personal data, we do not share it with advertisers, and we do not run other companies' advertising or analytics trackers on our own site.
6. Keeping it, and deleting it
Account data is kept while the account exists. Experiment and conversion records are kept while the site they belong to exists, and are deleted with it. Teardown reports are kept so that shared links keep working.
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it, by writing to the address below. Deleting an account deletes its sites and their results.
7. Changes, and how to reach us
If this policy changes in a way that affects what we collect, we will update the date at the top and say what changed. Questions about any of it can go to privacy@abee.pro.