Privacy
2026-08-20
Who we are
Sichta Web is operated by Gigliotti Software, Lugano, Switzerland. Contact: hello@gigliotti.software.
What we store about you
Your email address, an optional name, your language preference, and a Stripe customer identifier. There is no password: you sign in either with a one-time link sent to your address, or with your Google account.
If you sign in with Google, we receive your email address, your name and the fact that Google has verified that address — nothing else. We do not receive your password, your contacts, your files or anything else in your Google account, and we ask for no ongoing access: the sign-in is a single identity check, and we store no Google token afterwards. Your email address is what identifies your account, whichever way you sign in.
For each site you add: its hostname, a verification token, its subscription status, and the results of every check we run.
What we fetch from your site
To check a site we request its homepage, robots.txt, sitemap.xml, llms.txt, llms-full.txt and a small number of /.well-known/ paths, plus up to 25 links found in llms.txt. Requests identify themselves as SichtaWebBot and are capped at 30 per check.
To generate files we crawl up to 200 URLs from your sitemap and read their titles, meta descriptions and headings. We store the generated files, not copies of your pages.
Server logs you upload
If you upload access logs for a traffic report, the file is parsed in memory and never written to disk. We keep only aggregate counts: requests per AI agent, the top paths each requested, and error statuses served to them.
The parser does not read the IP address field. No visitor-level data is extracted, stored or shown.
Managed serving, and what we count
If you use managed serving, requests for your conformance files — llms.txt, llms-full.txt and .well-known/security.txt — are answered by us rather than by your server. That is the only traffic we see, and the only traffic we count.
For each of those requests we record three things: which known AI agent asked, which of those files it asked for, and the date. Nothing else. There is no IP address field, no cookie, no session identifier and no stored user-agent string anywhere in that data.
A request from anything we do not recognise as a known AI agent — a person's browser, an unknown script — is not recorded at all. It is not counted under “other”; it leaves no trace.
We keep the counts as daily per-agent totals, and we never see or count traffic to the rest of your site.
Sign-in links, check results, drift alerts and changelogs are sent via Amazon SES in the EU (eu-central-1). Bounces and complaints are recorded so we can stop emailing an address that rejects us.
Where it runs
Application servers and the database are in the EU. Payment processing is by Stripe; we store only their customer and subscription identifiers and never see your card details.
Your rights
You can ask for a copy of your data or its deletion at hello@gigliotti.software. Deleting your account removes your sites, check history, generated files and traffic aggregates.