Cookie Policy
This Cookie Policy explains how AI Crawler Check (aicrawlercheck.com), operated by Horatos.ai, uses cookies and similar technologies. It is written to satisfy the EU/UK GDPR and the ePrivacy Directive, Singapore's Personal Data Protection Act 2012 (PDPA), and US state privacy laws including the CCPA/CPRA.
The short version
We set no cookies at all until you press Accept. Nothing on this page is used for advertising, and we never sell or share your personal information. You can change or withdraw your choice at any time, in one click, from the button in section 8.
1. Who Is Responsible for Your Data
The data controller (GDPR Art. 4(7)) and the organisation responsible under the PDPA is:
- Horatos Pte. Ltd. (trading as Horatos.ai), Singapore.
- Data Protection Officer, as required by PDPA s.11(3): dpo@horatos.ai
- General privacy contact: hello@horatos.ai
If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with your national supervisory authority (GDPR Art. 77) or with the UK Information Commissioner's Office. If you are in Singapore, you may refer the matter to the Personal Data Protection Commission.
2. What Are Cookies and Similar Technologies?
Cookies are small text files stored on your device by your browser. This policy also covers technologies that behave like cookies for legal purposes, in particular localStorage, which is how we record your consent choice. Storing or reading anything on your device requires either your consent or a strict-necessity exemption, so we treat localStorage exactly as we treat a cookie.
3. Cookies and Storage We Use
3.1 Strictly necessary (no consent required)
These are exempt from the consent requirement because the service cannot be provided without them (ePrivacy Art. 5(3), PDPA First Schedule).
| Name | Type | Purpose | Retention | Provider |
|---|---|---|---|---|
cookie_consent | localStorage | Stores your consent decision and the policy version it was given against, so we can prove what you agreed to and stop asking. | Until you clear it or the policy version changes | Us (first party) |
This entry is stored in localStorage, not a cookie, which means it is never transmitted to our servers. Earlier versions of this policy described it as a 365-day cookie. That was inaccurate, and correcting it is one of the reasons this policy is at version 3.0.
3.2 Analytics that store data on your device (consent required, off by default)
These load only after you press Accept. If you reject or ignore the banner, they never run and none of the entries below are ever created. Separately, our hosting provider runs a cookieless measurement tool that stores nothing on your device at all; it is described in 3.3 so that this inventory is complete.
| Name | Purpose | Retention | Provider |
|---|---|---|---|
_ga | Distinguishes unique visitors | 2 years | Google Analytics 4 |
_ga_* | Maintains session state | 2 years | Google Analytics 4 |
_gid | Distinguishes visitors | 24 hours | Google Analytics 4 |
_gat | Throttles the request rate | 1 minute | Google Analytics 4 |
_clck | Persists a Clarity visitor ID | 1 year | Microsoft Clarity |
_clsk | Groups page views into one session | 24 hours | Microsoft Clarity |
CLID | Identifies the first-time visit | 1 year | Microsoft Clarity |
The processors for the cookies above are Google Ireland Limited (Google Analytics 4, loaded through Google Tag Manager) and Microsoft Corporation (Microsoft Clarity). Clarity also records aggregated interaction data such as scroll depth and click heatmaps. Both act as processors under GDPR Art. 28 and as data intermediaries under the PDPA.
3.3 Cookieless traffic measurement (runs for everyone, stores nothing)
Our hosting provider, Cloudflare, Inc., provides a privacy-focused measurement tool called Cloudflare Web Analytics. We want to be straightforward about how this one differs from the tools above, because it behaves differently in a way that matters to you.
- It sets no cookies and writes nothing to your device. There is no identifier to store, so there is no entry for it in any table on this page.
- It runs for every visitor, including those who reject the banner. It is added by our host's network after our pages are built, so our consent banner cannot switch it off. We would rather tell you this plainly than imply a control we do not have.
- It cannot follow you. With nothing stored on your device, there is no way to recognise you on a later visit or on any other website.
- What it counts: page views, referring site, country, browser and device type, and page load speed, all in aggregate.
We rely on legitimate interest (GDPR Art. 6(1)(f)) for this measurement rather than consent, because it stores and reads nothing on your device and so falls outside the ePrivacy Art. 5(3) consent requirement. Our interest is in knowing whether the site works and how many people reach it; the impact on you is minimal because no identifier about you exists. If you would prefer not to be counted at all, section 8 explains how to block it.
3.4 What analytics collects
- Pages viewed and time spent on each page.
- How you arrived (search engine, direct, referral, social).
- Approximate location at country or city level, derived from a truncated IP address.
- Device type, browser and operating system.
- Interactions with our tools, such as a check being run or a report exported.
IP anonymisation is enabled, so we never receive your full IP address. We do not attempt to identify you from this data, and it is never combined with any account record.
3.5 What we deliberately do not use
- No advertising, retargeting or marketing cookies.
- No social media tracking pixels.
- No third-party targeting or data-broker cookies.
- No device fingerprinting or cross-site tracking.
- No cookies are placed on the sites you submit to our scanner, and we never touch your visitors' devices.
4. Legal Basis for Each Purpose
| Purpose | GDPR basis (Art. 6) | PDPA basis |
|---|---|---|
| Remembering your consent choice | Art. 6(1)(f) legitimate interests, and a legal obligation under Art. 7(1) to demonstrate consent | Legitimate interests (First Schedule Part 3) |
| Analytics and product improvement | Art. 6(1)(a) consent | Consent (s.13), notified under s.20 |
Because analytics runs on consent, you can withdraw it at any time with no detriment and no loss of functionality (GDPR Art. 7(3), PDPA s.16). Withdrawal is not retroactive: it does not affect processing already carried out lawfully before you withdrew.
5. International Transfers
We are based in Singapore, and our analytics processors operate globally. Data may therefore be transferred outside your home jurisdiction, including to the United States.
- From the EEA and UK: transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by the processors' own certification under the EU-US Data Privacy Framework.
- From Singapore: transfers meet the Transfer Limitation Obligation in PDPA s.26, because each recipient is contractually bound to a standard of protection comparable to the PDPA.
6. Retention
Each cookie expires on the schedule in the tables above. Analytics event data is retained by our processors for a maximum of 14 months and then deleted automatically. Your consent record persists locally on your own device until you clear it, or until we publish a new policy version, at which point it is treated as expired and you are asked again.
7. Your Rights
If you are in the EEA or UK (GDPR Art. 15-22), you have the right to access your data, to rectification, to erasure, to restrict or object to processing, to data portability, and to withdraw consent.
If you are in Singapore (PDPA), you have the right to request access to your personal data (s.21), to request correction (s.22), and to withdraw consent (s.16).
If you are a US resident (CCPA/CPRA in California, and comparable laws in Colorado, Connecticut, Texas, Virginia and other states), you have the right to know what is collected, to delete it, to correct it, and to opt out of sale, sharing and targeted advertising.
Notice of Right to Opt Out of Sale or Sharing
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We have not done so in the preceding twelve months, including for anyone we know to be under 16. There is consequently no "Do Not Sell or Share My Personal Information" mechanism to operate. If that ever changes, this policy will be versioned and you will be asked to consent again before anything new runs. We also honour the Global Privacy Control (GPC) signal as a valid opt-out request.
To exercise any right, email dpo@horatos.ai. We respond within 30 days (GDPR Art. 12(3) and CCPA both allow extension where a request is complex, and we will tell you if we need it). We will not discriminate against you for exercising a right.
8. Managing Your Choice
You are in control at all times:
- Change or withdraw consent here: This reopens the banner so you can switch your answer.
- Browser settings: every major browser can block or delete cookies and clear site storage. Blocking everything is safe here, because the tools do not depend on analytics.
- Google Analytics opt-out: install the Google Analytics Opt-out Browser Add-on.
- Microsoft Clarity opt-out: see the Microsoft Privacy Statement.
- Cloudflare Web Analytics: because it stores nothing on your device, there is no opt-out cookie to set and the consent banner cannot disable it. Any content blocker or privacy-focused browser that blocks
static.cloudflareinsights.comwill stop it, and blocking it has no effect on the site's functionality. - Global Privacy Control: if your browser sends a GPC signal, we treat it as a rejection automatically and you never need to touch the banner.
9. Children
This site is a professional tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided data to us, email dpo@horatos.ai and we will delete it.
10. Policy Versions and Changes
This policy is versioned so you can tell exactly which text you consented to. A major version change means something material changed, such as a new processor, a new cookie or a new purpose. When that happens your stored consent is invalidated and the banner reappears, so consent is always freshly given against the current text. A minor change is a clarification that does not alter what we collect.
| Version | Date | What changed |
|---|---|---|
| 3.0 (current) | August 11, 2026 | Disclosed Cloudflare Web Analytics as a third processor: a cookieless measurement tool added by our hosting provider that stores nothing on your device and runs for every visitor, including those who reject the banner. Added section 3.3 explaining it, its legal basis and how to block it; scoped the 3.2 heading to analytics that do store data on your device, so that promise stays precise. A new processor is a material change, so consent given against version 2.0 was invalidated and the banner reappears. |
| 2.0 | August 10, 2026 | Disclosed Microsoft Clarity and its cookies; corrected cookie_consent from "cookie" to localStorage; added controller identity and DPO contact; added GDPR legal bases, data subject rights, international transfer mechanism and retention periods; added PDPA and CCPA/CPRA sections; added GPC handling, consent-withdrawal control and this version history. |
| 1.0 | March 18, 2026 | Initial policy. Covered Google Analytics cookies only. |
11. Contact
Horatos Pte. Ltd. (Horatos.ai), Singapore
Data Protection Officer: dpo@horatos.ai
General enquiries: hello@horatos.ai
Related: Privacy Policy · Terms of Service