Trust & how we scan
We built this scanner for compliance teams who need to know what a crawler saw — not a black-box score.
How we scan
When you submit a URL we fetch your publicly accessible pages (never more than your plan's page budget), parse the HTML, check image, audio and video files for C2PA/IPTC provenance marks, and run language-model analysis on visible text to identify EU AI Act transparency indicators. We identify ourselves honestly as EUAIScannerBot and respect robots.txt.
What we store
Page URLs, titles, and short text excerpts (≤2KB per page) as report evidence; media metadata only, never the image, audio or video files themselves; findings and the model rationale behind them; your account email and scan history. We never store full page copies or media bytes — files are analysed in memory and discarded. Report data is retained for 12 months on free accounts, then purged.
Data residency
Production data is stored in the EU. Analysis calls are processed via OpenRouter under our data-processing terms; page text sent for analysis is limited to what is publicly visible on your site.
Sub-processors
Supabase (database & auth), Netlify (hosting), OpenRouter (LLM analysis), Stripe (payments), Resend (email).
Opting out
Block EUAIScannerBot in your robots.txt and our crawler will not fetch your pages. See /bot for details.
Legal disclaimer: EU AI Scanner produces automated technical indicators, not legal advice. Findings are not legal determinations of compliance. Consult a qualified professional for advice on your obligations.