Privacy Policy
Last updated: 6 August 2026
See also the Terms of Use.
Botmetria ("we") provides AI-traffic analytics for online stores: the botmetria.com website, the Botmetria cloud API (api.botmetria.com) and the Botmetria WordPress plugin. This page describes what data these components process. Botmetria is an independent project operated by Vitalii, a private individual (sole operator), who acts as the data controller. Contact: info@botmetria.com.
1. Data from connected stores (plugin / pixel)
When a store owner connects their site with an API key, the plugin (or tracking pixel) sends to our cloud:
- AI-bot visit events: bot name, bot user-agent string, bot IP address (used to verify the bot against its vendor's published IP ranges), requested URL path, page type, product ID, HTTP status, response time. These describe automated crawlers, not people.
- AI-referral events: referral source (e.g. "chatgpt"), landing URL, an anonymized session hash, and — for purchases — the order ID, order total and currency. The session hash is one-way and cannot be turned back into a person. We do not receive shopper names, e-mail addresses, delivery addresses or payment details.
- Human pageview and engagement events (pixel): page URL, an anonymized session hash, time on page and scroll depth. At the moment a pageview reaches our server we derive the visitor's country from the IP address and a coarse browser family, operating system and device class (desktop/mobile/tablet) from the User-Agent string — and then discard both: a visitor's raw IP address and raw User-Agent are never stored, only the coarse buckets (e.g. "MD", "Chrome", "Windows", "mobile"). This is the derive-and-discard model used by privacy-focused analytics such as Plausible. Country lookup runs locally on our server against the IP Geolocation by DB-IP database (CC BY 4.0); the IP is not sent to any third party. To tell a real visitor from an automated one (a bot or AI agent using an ordinary browser), the pixel also reports a small set of yes/no signals about the browser environment — for example whether it declares itself automation-controlled, whether it runs a real graphics stack, and whether the visit involved genuine interaction. These signals are evaluated the moment the pageview reaches our server to derive a single "human / suspected / automated" label, then discarded: we do not build or store a device fingerprint, and the signals cannot identify a person.
Nothing is transmitted until the store owner enters API credentials. Store data is used solely to provide analytics and reports to that store's owner and is never sold or shared with third parties.
2. Data from botmetria.com
- Audit requests: when you request an AI-readiness check, we fetch publicly accessible pages of the domain you submit (respecting a strict request budget) and store the resulting score and findings. If you leave an e-mail address, we store it to send you the full report and to follow up about the service.
- Owner dashboard: signing in stores a session token; the optional Google sign-in shares your name, e-mail and avatar with us as provided by Google. We set no advertising or cross-site trackers.
3. Cookies set on connected stores
The plugin/pixel sets two first-party cookies on the store's own domain:
bm_src (first AI referral source, 90 days) and
bm_sid (a random session identifier used to build the anonymized
session hash). They contain no personal data and are readable only by the
store's own site.
4. Retention and deletion
Concrete retention periods, enforced automatically:
- Raw AI-bot visit events: 12 months, then dropped (daily aggregate statistics are kept for reporting continuity).
- Raw pageview counters: 4 days (only daily totals are kept).
- IP address of an audit/lead requester: deleted after 30 days.
- Audit results: deleted after 180 days.
- Database backups: kept 14 days, so deleted data leaves backups within at most 14 days.
- Account data: kept while the account exists.
Store owners can request export or deletion of their account and their site's data, and leads can request deletion of their contact details, at info@botmetria.com. Requests are fulfilled within 30 days.
5. Anonymised network benchmarks
Aggregate, anonymised statistics from connected stores are used to compute network benchmarks — the medians a store is compared against ("your share of AI traffic vs the median of your vertical") and the public monthly AI Traffic Index.
Two guarantees apply, enforced in code rather than by policy:
- No individual store data leaves the aggregate. A cohort smaller than five stores is never computed, stored or published: from the median of a smaller group a specific store could be identified.
- Opt-out is available and mutual. A store owner can exclude their store from benchmarks in the dashboard at any time. The exclusion removes the store's data from all cohorts and, symmetrically, removes the comparison card from that store's dashboard.
The public index contains network-wide totals and cohort medians only — never a number attributable to one store.
6. Hosting and subprocessors
Data is processed on servers in the United States (hosting provider: Namecheap, Arizona). Botmetria does not collect shoppers' personal data — only AI-bot visits and anonymised session hashes; store-owner account and lead data is transmitted over encrypted HTTPS and event submissions are HMAC-signed.
We use the following service providers (subprocessors) to run the service:
- Namecheap, Inc. (USA) — server hosting for the API, database and website.
- Google LLC (USA) — optional "Sign in with Google" for the owner dashboard; Google shares your name, e-mail and avatar with us when you use it.
- Sendinblue SAS (Brevo) (EU) — transactional e-mail delivery (weekly reports, notifications).
- Anthropic PBC (USA) — optional AI-agent readiness simulation: when this add-on is enabled, the public product-page text of the audited store is sent to the model to check how an AI shopping agent reads it.
- Backblaze, Inc. (USA) — off-site storage of database backups; dumps are encrypted (AES-256) before upload.
- Cloudflare, Inc. (USA) — optional traffic collector: when a store connects via the Cloudflare Worker, request metadata passes through the store's own Cloudflare account on its way to our API.
For store owners who need a data-processing agreement (GDPR Art. 28), a DPA is available on request at info@botmetria.com.