Privacy, explained around the product that exists today.
How CheckMyHelpCenter handles public scans, optional read-only platform connections, Cloudflare request data, and Google Analytics data.
Scope at a glance
The free scanner does not require an account and does not retain raw article text or report history. A pre-release connected mode uses platform OAuth, encrypted tokens, and strictly read-only scopes for administrator-requested audits.
Who this notice covers
This notice covers CheckMyHelpCenter, a DocSanity AI branded service available at checkmyhelpcenter.com. The legal name and registered address of the service operator have not yet been published; the release-readiness notice below identifies this as a required item before a marketplace listing is submitted.
Questions and privacy requests can be sent to support@willgo.tech.
The current public scanner
You can use the free scanner without creating an account or signing in. When you submit a URL, we process the URL, publicly accessible article text and metadata, pages discovered during the bounded crawl, and the findings needed to return the report. Please submit only public Help Center URLs that you are authorized to analyze.
Raw page content is processed transiently for the scan and is not intentionally stored by the application in a report database after the response is generated. The report is returned to your browser; the current service does not provide account-based report history. Normal network and security logs may still contain request metadata as described below.
- Submitted public URL and redirect destination.
- Public article titles, text, links, visible dates, and platform metadata needed for analysis.
- Automated findings, coverage counts, errors, and timing needed to return the report.
- No private articles, macros, tickets, saved replies, or support conversations in the current scanner.
Cloudflare infrastructure and operational data
The service runs on Cloudflare infrastructure. Cloudflare may process standard connection, delivery, security, and diagnostic data such as IP address, request time, requested path, headers, device or network information, response status, and threat signals. We use this data to deliver the service, prevent abuse, diagnose failures, and protect the site.
Anonymous audit rate limits store secret-keyed SHA-256 hashes derived from the visitor network address and target hostname in one-hour windows. Each row becomes eligible for cleanup about one minute after its window ends and is opportunistically purged by later audit traffic. Operational-log retention is controlled separately by the production Cloudflare account and must be verified before marketplace submission.
Google Analytics 4
We use Google Analytics 4 (measurement ID G-10J83CSMEB) to understand visits and product usage. Google may receive online identifiers and information about pages viewed, browser or device characteristics, approximate location derived from IP address, referrer, and interaction events. This helps us understand whether the site works and which resources are useful; we do not use the site to sell personal information or serve targeted advertising.
Google processes Analytics data under its own terms and privacy documentation. You can limit Analytics through browser privacy controls, content blockers, or Google's opt-out tools. The GA4 property-level event retention setting and any consent requirements for the launch regions must be verified before marketplace submission.
Pre-release OAuth-connected audits
The application includes pre-release Zendesk and Gorgias connection flows, but they are not available to customers until production credentials, sandbox review, marketplace approval, and the release-readiness items on this page are complete. Zendesk requests hc:read, macros:read, and users:read. Gorgias requests openid, offline, account:read, users:read, and macros:read. The users:read permission is used only to verify the current authorizing user's platform ID and administrator role; it is not used to enumerate or retain a user directory. This release does not request tickets, customers, attachments, article or Macro write access, or Shopify account access.
Connected mode stores a platform account key and URL, the verified administrator's platform user ID, approved scopes, installation status, token expiry, an encrypted OAuth access and refresh token set, and a random application-session hash. The administrator role is checked during authorization but is not stored as a user-directory record. The service processes Guide articles and Macros from Zendesk, or Macros from Gorgias, in memory only when that verified administrator runs an audit. Raw document bodies and generated connected reports are not persisted by the current implementation; audit events retain counts and operational outcomes, not article or Macro bodies, and a daily retention task removes those events after 90 days.
OAuth states expire after 10 minutes. Connected sessions expire after eight hours and after one hour of inactivity; disconnect and reauthorization invalidate earlier sessions. Tokens remain until disconnect, self-service deletion, platform expiry, or revocation. Disconnect immediately disables local use and attempts remote revocation with the supported Zendesk or Gorgias endpoint. If that request fails, only the platform account key and encrypted token material move to a separate revocation queue that cannot authorize a scan; the daily task retries with backoff and deletes the job after successful revocation. The administrator can also revoke the grant in the platform. Tenant deletion removes installations, sessions, audit events, and every other tenant-scoped record immediately; no tenant-linked deletion receipt remains.
Sharing, retention, and deletion boundaries
We disclose data to infrastructure and analytics providers only as needed to operate, secure, and understand the service, or when required by law. We do not sell personal information. Public Help Center content remains the responsibility of its publisher and is not made private merely because it is analyzed.
For public and connected audits, raw article or Macro text and generated reports are not intentionally retained in an application database after the response. Connected authorization records follow the lifecycle above; Cloudflare logs and Google Analytics events follow their separately configured retention controls. See the Data Deletion page for self-service and email request steps.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about disclosures. Send a request to support@willgo.tech with enough detail for us to locate the relevant record. We may need to verify identity and authority before acting, and some data may be retained where required for security, legal compliance, or dispute handling.
This service is intended for business users and is not directed to children. Do not submit personal data, credentials, private support content, or confidential URLs through the public scanner.
Changes and contact
We will update this page whenever processing changes materially and before these authenticated integrations are enabled for customers. The effective date at the top identifies the current version. Privacy questions and requests: support@willgo.tech.