Last updated:
This page covers PiScan when you use it inside ChatGPT or another app that connects to our MCP server at https://dijitalpi.com/api/mcp. PiScan is operated by DijitalPi. The general privacy policy covers the rest of dijitalpi.com.
Privacy
What PiScan receives
When ChatGPT calls PiScan, we receive the tool arguments: the web address you asked to scan and the report language. ChatGPT may also send request metadata such as your locale; we use the locale to pick the report language and do not store it. We do not receive your conversation, your name, your email address or your ChatGPT account details. The PiScan endpoint does not set cookies.
What PiScan does with the address
PiScan fetches the public page at that address, its robots.txt, llms.txt and sitemap, and a few internal pages from the same site. It requests the page once as a regular browser and once with the user-agent string of each AI crawler it tests (for example GPTBot, ClaudeBot and PerplexityBot), so it can compare what each one receives. It only fetches public http and https addresses on standard ports.
What we store
- A record of each completed scan: the scanned address and host, the final address after redirects, the score and grade, the number of critical findings and warnings, the word count, how long the scan took, the report language, the time, the channel ("mcp") and a 12-character code derived from the requesting IP address with a secret key. We do not write the IP address itself. Requests from ChatGPT come from OpenAI's servers, so this code identifies the server that called us, not you.
- Abuse protection: to enforce rate limits, the requesting IP address is held in memory for up to 24 hours. It is not written to disk.
- Report cache: the finished report is kept in memory for 10 minutes so a repeated request for the same address does not hit the site again.
Why we use it
We use this data to produce the report, to stop the service from being used to flood other sites with requests, and to see how PiScan is used and how scores are distributed. We do not sell it, we do not use it for advertising and we do not build profiles of the people who use PiScan.
Who can see it
Scan records stay on our own server and are visible only to the DijitalPi team. The hosting provider that runs the server processes the data on our behalf. We share data with authorities only when the law requires it.
How long we keep it
Scan records stay in the active log for 90 days. After that they are moved to a compressed archive on the same server. In-memory data (IP addresses for rate limits and cached reports) disappears within 24 hours and 10 minutes respectively, and on every server restart.
Your choices
If you want the records for a site you control removed, write to info@dijitalpi.com with the domain name and we will delete them from the active log and the archive.
Terms of use
- Scan sites you are allowed to assess. Use PiScan on your own sites or on sites you have permission to check. Do not use it to put load on a site or to get around its access rules.
- Limits. PiScan is free and rate-limited. Through ChatGPT, it runs at most 10 new scans per minute and 300 per day in total, and the same site can be scanned at most 5 times per minute through ChatGPT and the PiScan website combined. A request that hits a limit gets an error asking you to try again later.
- What is not scanned. PiScan does not scan private network addresses, pages behind a login, or gambling and adult sites.
- Results are estimates. The score and findings come from automated checks at the time of the scan. They do not guarantee how any search engine or AI product will treat a site, and a site can change after the scan.
- No warranty. PiScan is provided as is. We may change the checks, the limits or the service, or stop it, at any time.
- Changes to this page. When we change these terms, we update the date at the top of this page.
Contact and support
Questions about PiScan, this page or your data: info@dijitalpi.com or the contact page.
