Privacy

What CSS Radar handles.

CSS Radar audits public pages without an account. This page explains how the submitted URL and required report email are used, who can open a report, and when CSS Radar's temporary records expire.

Last updated August 13, 2026

When you start an audit

Your browser sends the submitted public URL and email address to api.cssradar.com. The audit service opens that URL in Chrome, inspects the rendered page and relevant HTML, CSS, and JavaScript, observes safe interactions, and builds the report. It does not sign in or try to bypass access controls.

Do not submit private URLs, signed links, or URLs containing passwords, access tokens, or other secrets.

What is stored

  • Private audit record: the submitted URL, report email address, audit status, timestamps, and technical result references are stored in Google Cloud Firestore. This record is scheduled to expire 31 days after the audit finishes, fails, or is canceled.
  • Report file: a completed report is stored as an HTML file in Google Cloud Storage. It is scheduled for automatic deletion after 30 days.
  • Kit subscriber: the email address is added to Kit with the radar tag for occasional CSS Radar and modern CSS emails. Kit keeps that subscriber record until the person unsubscribes or asks CSS Radar to delete it.
  • Daily limit: CSS Radar derives a pseudonymous identifier from the visitor's IP address with a keyed hash. The raw IP address is not stored in the application's rate-limit record. That record is scheduled to expire within 48 hours.

The 30-day deletion rule covers the generated report file. Standard infrastructure logs kept by the service providers below are separate and follow each provider's own retention terms.

Who can open a report

Anyone with the report URL can open it without an account. CSS Radar does not list reports on the site or include them in its sitemap, but the link is not an access-control mechanism. Do not share it with people who should not see the report.

To request deletion before the automatic deadline, email hey@theosoti.com and include the report URL.

How the email address is used

CSS Radar uses the submitted email address to send the requested report or to say when the audit could not be completed. It also adds the address to Kit with the radar tag for occasional CSS Radar and modern CSS emails. Marketing emails include an unsubscribe option. The address does not appear in the generated report.

Mailjet, a Sinch brand, receives the address and message content to deliver the report or failure notice. Its delivery records are separate from CSS Radar's 30-day report file and follow Mailjet's own retention terms.

Kit receives the email address to maintain the subscriber list and apply the radar tag. To request complete deletion instead of unsubscribing, email hey@theosoti.com.

Landing-page analytics

The public landing page loads Fairlytics to count visits and understand which pages are used. According to Fairlytics, its hosted service uses no cookies. It receives the current CSS Radar page URL, the referrer, and request data such as the IP address, browser, and operating system. Fairlytics says it uses the IP address to derive approximate location and a daily hashed visitor identifier, then discards the raw IP.

The URL and email address typed into the audit form are not sent to Fairlytics as analytics events, and generated reports do not load Fairlytics. Fairlytics stores its audience records separately. Its public documentation does not state a fixed retention period, so the 30-day report rule does not cover those analytics records.

Read Fairlytics' data explanation and terms.

Service providers and contact

  • Netlify serves the public website.
  • Google Cloud runs the audit service and stores temporary audit records and reports.
  • Fairlytics provides the landing-page audience measurement described above.
  • Mailjet delivers report emails and audit failure notices.
  • Kit stores report recipients as subscribers and manages later email updates and unsubscribes.

CSS Radar is operated by Theo Soti. For a privacy question, subscriber-deletion request, or an early report-deletion request, email hey@theosoti.com.