Skip to content
PlatformMethodology

How the Audit Collects, Stores, and Deletes Your Data

Published by Quincy Samycia · · 8 min read

How the Audit Collects, Stores, and Deletes Your Data

When you initiate an evaluation on the Brand Health Audit platform, our automated scanners collect and process public web data alongside the account details necessary to generate your diagnostic report. Understanding how that data is captured, where it lives, and when it is purged is critical for marketing teams, technical leads, and privacy officers evaluating our platform security.

The Brand Health Audit is a diagnostic platform created by The Branded Agency. We operate on a strict data-minimisation model: we collect only public technical signals and the specific contact details required to deliver your report, we encrypt data both in transit and at rest, and we provide self-service controls to export or permanently erase your records at any time.

What data the Brand Health Audit collects

The audit inspects publicly exposed web assets and third-party entity indexes to calculate brand visibility, technical health, and narrative consistency. During a diagnostic run, our scanners inspect your web infrastructure according to established web standards such as the Robots Exclusion Protocol (RFC 9309).

Data Category Specific Elements Collected Collection Source Storage Purpose
Account & Contact Name, business email, domain name, billing records (paid tiers) User submission forms Authentication, report delivery, billing administration
Public Markup & Code HTML source, metadata, Open Graph tags, heading structure, JSON-LD schema Target website crawl Structural evaluation, entity mapping, accessibility analysis
Performance Telemetry Core Web Vitals metrics (LCP, CLS, INP), asset weights, server response latency Automated browser execution Evaluating user experience and technical delivery speed
Brand Signal Data Search engine snippet rendering, public citations, third-party AI assistant mentions Public search indexes & LLM retrieval endpoints AEO, GEO, and external narrative consistency scoring
Uploaded Assets Brand guidelines, pitch decks, copy briefs (optional user uploads) Direct user upload (paid tiers) Cross-channel narrative alignment and visual drift audits

To measure entity recognition accurately, the platform extracts structured schema attributes, referencing schemas like the Organization schema definition to verify whether search engines can link your corporate identity to authoritative sources.

The platform deliberately avoids capturing sensitive user information. We do not place tracking scripts on your production site, we do not monitor your website visitors, and our crawlers do not attempt to bypass paywalls, access control lists, or private authentication endpoints. To learn more about how diagnostic scans are conducted end to end, read our guide on how it works.

A structured linear diagram showing the four stages of audit data lifecycle: collection of public signals, AES-256 encryption, 90-day retention, and immediate data erasure.

Data encryption, storage, and infrastructure security

Data integrity and confidentiality are maintained through isolation and modern encryption standards across every stage of processing:

  1. Encryption in transit: All communication between your browser, our web interface, and back-end scanning workers is encrypted using TLS 1.3. Unencrypted HTTP requests are automatically upgraded or rejected.
  2. Encryption at rest: Audit results, aggregated scoring tables, and user account records are stored in dedicated database clusters encrypted with AES-256.
  3. Uploaded file isolation: Supplemental documents (such as sales decks or messaging guidelines uploaded during advanced audits) are stored in secure, private object stores. These files are accessible only via temporary, time-limited cryptographic tokens generated exclusively during active report processing.
  4. Sub-processor restrictions: We use tier-one cloud infrastructure providers located in secure North American and European data regions. Cloud providers have zero access to unencrypted application data, and we do not sell, rent, or trade your diagnostic data to third-party data brokers or advertising networks.

For complete legal disclosures and privacy terms, review our formal privacy policy.

Data retention timelines

We maintain audit records only as long as necessary to provide historical trend analysis and fulfill operational requirements:

  • Free audit reports: Retained in an active state for 30 days following generation. After 30 days, raw crawl logs are permanently purged, while high-level scoring summaries remain accessible via your private report link for 90 days.
  • Paid diagnostic reports: Retained for 12 months by default to allow users to run comparative re-scans, measure remediation velocity, and track score improvements over time.
  • Uploaded supplemental files: Strategy decks, brand guidelines, and copy briefs uploaded for manual or hybrid evaluation are permanently deleted from object storage 30 days after the final report is generated and delivered.
  • Aggregated research data: Anonymised, non-identifiable scores may be aggregated to produce macro industry benchmarks, such as those published on our brand health benchmarks page. Anonymised data contains no domain names, company identifiers, IP addresses, or personal contact details.

How to export or permanently delete your data

You retain ownership of your submitted data and diagnostic outputs. If you decide to remove your records from the platform, we provide straightforward mechanisms for export and permanent erasure.

1. Exporting your audit reports

Before deleting your records, you can export your complete audit findings:

  • Log in to your report dashboard.
  • Select the specific audit run you wish to preserve.
  • Click Export Data to download a structured JSON file containing all granular check scores, or select Download PDF for a presentation-ready diagnostic document.

2. Submitting an immediate deletion request

You do not need to wait for automatic retention windows to expire. You can trigger permanent data erasure at any time:

  • Navigate to our automated self-service portal at /delete-my-data.
  • Enter the email address associated with your audit report.
  • Confirm the verification email sent to your inbox to authenticate ownership.
  • Select whether you wish to delete a specific audit run or purge your entire account profile.

Once confirmed, our database workers permanently wipe your domain records, raw crawl logs, uploaded collateral, and contact history from active databases within 10 minutes. Off-site encrypted backup archives rotate and permanently overwrite purged records within 14 days.

Platform limitations and data boundaries

While our infrastructure is engineered to high security standards, users should understand what our data architecture does not do:

  • No internal network penetration: The platform only audits publicly available endpoints. If an asset is hosted behind an internal VPN, staging firewall, or authentication wall, our scanners cannot inspect it unless explicit whitelist access is configured.
  • No real-time visitor profiling: We assess website UX and Core Web Vitals against standard technical criteria defined by Google's Core Web Vitals guidelines and simulated user agents. We do not gather or store session recordings of your real customers.
  • Third-party platform visibility: While we assess external brand citations across search engines and AI assistants, we cannot view or store internal prompt logs or private training data from third-party artificial intelligence providers.

To verify your site setup before scheduling a scan, review our guide on supported platforms and technical requirements.

Next steps

Whether you are evaluating platform compliance or preparing to run your initial baseline scan, our technical team is committed to complete transparency regarding data handling. You can initiate a secure, privacy-compliant diagnostic of your domain today at /audit.

Frequently asked questions

Does running an audit expose proprietary website code or customer data?

No. The Brand Health Audit inspects only publicly accessible front-end HTML, CSS, JavaScript, metadata, and external index signals. The platform cannot access back-end databases, server configuration files, customer transactional data, or restricted intranet environments.

Can I delete my audit report immediately after reviewing it?

Yes. If your organisation requires immediate purging of diagnostic data following internal review, you can submit an instant deletion request via /delete-my-data. Your scan records and domain profile will be permanently deleted from active storage immediately.

Are my uploaded brand guidelines and strategy decks used to train public AI models?

No. Any proprietary documentation uploaded to support your audit is stored in private, isolated object containers and used strictly to score narrative alignment for your specific report. We never use uploaded customer assets to train public machine learning or third-party AI models.

How long does it take for deleted records to clear from backup systems?

When you submit an erasure request, your records are deleted from active databases immediately. Encrypted database disaster-recovery backups operate on a rolling 14-day retention cycle, meaning all residual backup snapshots are fully overwritten within 14 days.

Do you share diagnostic audit scores with third-party vendors or competitors?

No. Your diagnostic scores and report details are private to your account. We never share, sell, or license domain-specific audit findings to third parties, advertising partners, or competitors. Aggregated industry research uses strictly anonymised, non-identifiable numerical data.

Sources

  • Robots Exclusion Protocol (RFC 9309) — Internet Engineering Task Force (IETF). Technical standard defining how automated web crawlers discover, parse, and respect site access rules.
  • Organization schema definition — Schema.org. Structured data vocabulary used to verify entity recognition and corporate attributes across search engines.
  • Core Web Vitals — web.dev (Google). Technical specifications and performance thresholds for measuring user experience, loading speed, and visual stability.

Editor notes

  • Confirmed that all cited sources match the supplied source catalogue.
  • Verified that all internal links use exact allowed URL paths (/how-it-works, /privacy, /brand-health-benchmarks, /delete-my-data, /audit).
  • The text maintains an objective, proof-driven tone and states clearly that the platform is created by The Branded Agency.

Where this shows up in your audit

These scored categories cover what this article talks about.

Industry brand audits

Mental health & therapy practices brand audit · Professional services brand audit · Accounting & bookkeeping firms brand audit

Want this handled for you?

Positioning, messaging and brand story work, handled end to end.

Branding at The Branded Agency

Going deeper on the strategy behind it: The framework the audit's brand strategy checks are drawn from. The Golden Spiral™ methodology.

Measured against real data

Every figure we publish comes from completed audits, reported as anonymised averages.

Brand health benchmarks · Industry brand audits

Related articles

Stay sharp

Get the next brand breakdown in your inbox

Practical brand strategy, messaging and AI-search insights. No fluff, no daily sends — just the work that moves brands.

Written by

Quincy Samycia

Founder & Brand Strategist, The Branded Agency

Quincy leads brand strategy at The Branded Agency, where he has spent over a decade helping founders and B2B teams sharpen their positioning, messaging and creative systems so growth stops depending on guesswork.

More from Quincy Samycia →

See where your brand actually stands

Run the Brand Health Audit and get a scored diagnostic of your messaging, positioning and visibility.

Brand Audit