PRIVACY POLICY
Your data in Redirect Desk
Effective September 11, 2026
Who operates the product
Joseph Benjamin Warren, a sole proprietor doing business as Utility Grove in Huntsville, Alabama, United States, operates Redirect Desk. Contact utilitygrove@outlook.com about privacy or your data.
Local files and saved previews
The free CSV checker and inventory matching run in your browser memory. Choosing files, analyzing them, and editing decisions does not upload their contents. These operations do not send inventories to an AI service or crawl your website.
When you authorize storage and create an export preview, your old and new CSV inventories and decisions are sent to the server. The server validates them and stores a normalized snapshot containing URLs, page titles, supplied HTTP status/canonical/indexability/robots data, recommendations, approvals, exclusions, reasons, and preview results. The original CSV files are not separately stored. Do not include credentials, private access links, or personal customer records.
Cloudflare R2 stores the snapshot and generated ZIP. Cloudflare D1 stores job and access metadata: job ID, recovery-token hash, payment mode, checkout/transaction identifiers and status, acquisition label, and creation/expiry times. These are used to deliver and recover your export and prevent unpaid access.
Acceptance and payment records
When you accept the Terms at checkout, we separately store the affirmative acceptance status, server timestamp, terms and acknowledgment versions, exact acknowledgment and Terms document, hashes of the Terms and approved snapshot, and job, checkout, and verified payment identifiers. This record documents the agreement and its associated transaction. A snapshot hash is a digital fingerprint, not the inventory contents or a recovery secret. We do not add an IP address or browser fingerprint to this acceptance record.
Live payments are disabled. The $0 simulator asks for no card or billing details and sends no payment to a processor. If a Lemon Squeezy test checkout is configured, it runs in test mode. The server sends that provider a job ID, checkout nonce, product/price information, and the recovery URL for returning to the product and receipt access. Signed payment notifications may contain customer/billing details; the app validates the event and stores the transaction identifiers and status, not the complete notification or card details. The provider may retain data independently under its own policy.
Before real purchases open, this policy and checkout will identify the actual provider and describe the final integration. Do not enter real payment details into the current simulation.
Private recovery
The recovery link contains a secret in its URL fragment. It is not sent as part of a normal webpage request; the app sends it in an authorization header when accessing your job. The database stores a hash of the secret. If a provider test checkout is used, the full recovery URL is shared with that provider for return/receipt links. Anyone with the full link can access your job. Do not share it in screenshots, messages, or public pages.
No customer account or recovery email is created. The app does not place inventories or recovery secrets in browser local storage or cookies. Your browser may retain the recovery URL in its history. Downloaded files, browser history, or copies you share are under your control.
Retention and deletion
Access ends seven days after preview creation. Payment or download does not restart that clock. The deadline is shown before checkout.
Seven days is an access window, not a guaranteed physical-deletion deadline. On creation of a new preview, the app deletes expired snapshots and ZIPs in batches of up to 20 jobs and then removes their job metadata. There is no scheduled daily deletion task. With no new previews, expired data may remain stored until a later cleanup. Failed deletion is retried by later cleanup attempts. Access remains blocked after expiry.
Minimal acceptance records are kept separately for transaction evidence, accounting, disputes, and legal claims. They become eligible for deletion seven years after acceptance; cleanup removes eligible records in batches during new preview creation, so physical deletion can occur later. These records do not contain the uploaded inventories, generated ZIP, or recovery secret. Aggregate analytics have no fixed deletion schedule. Request-limit entries expire after approximately two minutes and are also removed in batches during preview creation.
Hosting providers may retain backups, security records, or operational logs separately under their own policies; the app’s deletion does not promise immediate removal from every provider backup. Clearing local data does not delete an already saved server job. Contact us to request deletion sooner; we may need to verify your access without asking you to email a full recovery link, and may retain limited records where needed for legal obligations or claims. Mandatory data rights remain available.
Analytics and service providers
We keep daily aggregate counts for checker use, workflow entry, checkout initiation, and test completion, grouped by a short optional acquisition label such as “guide.” Do not put personal information in acquisition labels. The counters do not contain inventories, emails, full referring URLs, or recovery links. We do not use advertising pixels, cross-site tracking, or analytics profiles.
Short-lived abuse limits use a hash of the network address combined with the current minute. The host necessarily processes network addresses and ordinary connection information. Cloudflare and the Sites hosting platform process data to operate, secure, and deliver the service; providers may process data outside your country. Support email is handled through Microsoft Outlook and is retained as needed to resolve requests and maintain business records, without an automatic deletion schedule.
We do not sell inventories or use them for advertising. Data may be disclosed to service providers for the purposes described here, where legally required, or to address misuse and protect legal rights. For applicable privacy laws, processing supports your requested service and agreement, service security, and legal recordkeeping. You may contact us to request access, correction, deletion, or exercise other applicable rights, including complaints to a competent authority.
Changes
We update this policy when practices change and display the effective date. Material changes affecting new purchases will be disclosed before checkout.