The calculators and decision tools can be used without creating an account, entering personal data, or completing a form. The optional review request builder runs locally.
Privacy
Privacy for public tools and review enquiries
SaaS Sentinel provides public decision tools and an optional human review service. The tools require no account. Complete calculator constraints and imported files stay in the browser, while the bounded public or coarse dimensions described under “Analytics status” are sent automatically. Opening a generated review draft transfers the displayed brief to your chosen email application or webmail, but does not send it to SaaS Sentinel; sending remains your choice.
Summary
What matters most
A review enquiry is sent only through the requester's chosen email provider. The site does not upload an imported dossier or collect payment in the browser.
External email, provider, LinkedIn or partner destinations apply their own privacy and tracking policies once opened.
Operational data
What may be processed
Server and hosting logs
Hosting infrastructure can process basic technical logs such as URL, IP address, user agent, and timestamps for delivery, security, and the limited first-party product measurement described below.
Calculator, Decision Room, Provider Response Room, Review Scope Room, Review Delivery Room, Assurance Room, and Decision Monitor inputs
Calculator values, Decision Room constraints, imported decision and assurance dossiers, provider evidence requests and responses, review-scope routing values, review-delivery acceptance references, findings and conclusions, monitor thresholds, commercial assumptions, evidence references, risk gates, and sign-off states are handled in the browser. Shared calculator, comparator and Decision Room scenarios are encoded after the # in the URL, which browsers do not send in the HTTP request; legacy calculator links with scenario fields in the query are migrated locally while unrelated campaign parameters remain intact. The Provider Response Room, Review Scope Room, Review Delivery Room, Assurance Room, provider evidence reviewer, and Decision Monitor do not put imported files or edits in the URL. Provider Response Room, Review Scope Room and Review Delivery Room do not call a provider API or send imported values to product analytics. The Decision Monitor requests only the public current catalog. JSON and Markdown dossiers, provider responses, provider evidence reviews, review-scope packs and review-delivery records are created locally. Acceptance references and findings may still be commercially sensitive, so redact them before sharing or committing an export. The site does not require these inputs to be submitted through an account.
Analytics status
The measurement script sends an automatic page_view event when it runs. It can also report filter changes; completed calculations and monitor runs; dossier exports; review-service, sample and draft actions; citation-brief copy requests; source or partner-link openings; scenario shares; and categorical LCP, INP and CLS ratings through the canonical /api/events/ endpoint. Every event request includes an allowlisted public page path, page type and page slug. Depending on the event, parameters can include provider, GPU, region and market labels; destination type; coarse usage-hour and referrer categories; result count; and web-vital ratings. The endpoint rejects unlisted fields and values. A copy-request event records the button action, not clipboard success or an external citation. These events do not prove that an email was sent or accepted. They do not include full workload constraints, imported decision or assurance dossier contents, provider requests or responses, review-form values, acceptance references, findings, conclusions, exact cost assumptions, evidence references, risk gates, sign-off states or artifact fingerprints.
Cookies, browser storage and rate limiting
This site's measurement code does not store its page-session identifier in cookies, local storage or session storage. It creates a random UUID in module memory; reloading or closing the page ends that browser-side instance. The endpoint reads the normalized IP supplied by the hosting platform only to key an in-memory abuse-rate bucket whose window is configured to one minute. The product-event record written by the application excludes the IP address, user agent, page-session identifier and analytics session timestamp. Hosting Runtime Logs remain separate hosting records and can contain standard request metadata associated with the endpoint invocation. This is pseudonymous operational data, not anonymous data.
Optional analytics destination
The read-only health response at /api/events/ reports the endpoint's currently configured destination mode; this notice does not freeze a point-in-time runtime status. If the optional Google Analytics credentials are configured and the runtime-log safety gate is confirmed, the server sends the allowlisted event name and dimensions to Google Analytics Measurement Protocol. The payload also contains the in-memory page-session UUID as client_id, the page-start timestamp as the event session_id, and non_personalized_ads: true. The application does not add the visitor's IP address or user agent to that payload. This does not make the payload anonymous or eliminate the network metadata of the server-to-server request.
Search Console demand evidence
Authorized maintenance workflows can retrieve query text, page URLs, clicks, impressions, click-through rate, position, sitemap status and URL-inspection results from Google Search Console. Before a new query-level report is persisted, a heuristic filter rejects values that look like email addresses, URLs or domains, IP addresses, phone numbers, credentials or secrets, and it strips query strings and fragments from first-party page URLs. The filter cannot guarantee that every name or other personal detail is detected. Filtered reports and derived aggregates can be processed by GitHub Actions and retained in the private Git repository and its history; there is no timed deletion promise for repository history. Separate GitHub Actions artifacts are configured to expire after one day for the validated SEO bundle; two days for both the near-real-time raw snapshot and its sanitized source-health sidecar; and thirty days for the historical-baseline, index-surface and performance-control-plane raw reports, each report's sanitized source-health sidecar, and the weekly Search Console source-health sidecar. The five source-health sidecars contain no Search Console query text, page URL, property identifier or arbitrary upstream error message; they retain only bounded status, receipt, freshness, count, schema and hash fields plus allowlisted finding codes. The weekly workflow temporarily processes a privacy-filtered validation witness solely to reconcile the candidate summary, then deletes it without uploading or committing it. A raw artifact is uploaded only after its exact schema and privacy contract pass and source health is not critical; the weekly summary is likewise committed only after its exact contract and witness pass. Artifact expiry does not delete committed history. Reports without a persisted privacy-filter receipt, including legacy snapshots, are treated as non-authorizing for buyer-intelligence actions.
Contact messages
The independent-review request builder validates and formats information in the browser. It has no form backend. Opening its generated mailto: draft hands the displayed brief to the chosen email application or webmail, which can process the draft before it is sent; it does not by itself send an email to SaaS Sentinel. If you send it to the published Gmail address, the relevant email providers, including Google for the recipient account, process the message, metadata, any attachments you deliberately add and the reply history. Imported dossier files are not attached or uploaded automatically. The Review Scope Room validates the downloaded request locally and exports a draft routing pack; it does not send, accept, sign, invoice, collect payment, or verify either party's identity. After a separate written acceptance, the Review Delivery Room can validate four locally selected artifacts and prepare a review record. Its acceptance attestation and fingerprint are operator-supplied controls, not proof of contract, identity, payment, delivery or purchasing authority.
Your information rights
Choices, recipients and rights
How data arises and what is required
Technical request data comes from the browser and hosting platform when a page or endpoint is requested. The measurement script generates its session identifiers and event dimensions automatically. Contact details and message contents come from an email the requester decides to send. No account or contact message is required to use the public tools. A network request is technically necessary to deliver a requested page or endpoint. If the generated review email is not sent, no review enquiry reaches the recipient for assessment.
Who receives data
The hosting provider receives page and endpoint requests and can record standard request metadata. Google receives the bounded measurement payload described above only if the optional server-side destination is configured; Google also supplies Search Console evidence and operates the published recipient Gmail account. GitHub processes maintenance workflows and stores committed filtered Search Console reports in the private repository. If you open a generated email draft, the chosen email application or webmail receives its contents; if you send it, the relevant email providers and intended recipient process the message and reply history. An external provider, LinkedIn or partner destination receives a browser request when its link is opened.
Your data-protection rights
Subject to the conditions and exceptions in applicable data-protection law, you may request access to, rectification or erasure of your personal data, restriction of its processing, or portability where applicable, and you may object to processing. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Send a request to enriqueluislloret@gmail.com. Information reasonably necessary to verify the requester's identity may be requested before responding.
You may lodge a complaint with a competent supervisory authority. In Spain, complaints can be submitted to the Spanish Data Protection Agency (AEPD).
No solely automated decisions about visitors
The public technical recommendations concern GPU and provider choices, not the visitor. The processing described on this page is not used to make a decision about a person based solely on automated processing that produces legal or similarly significant effects.
Retention and transfer boundary
The application does not create a user-account or review-message database. Runtime-log and email retention are controlled by the relevant hosting and mailbox account settings; exact periods are not fixed by this repository. Account-level processing regions, subprocessors and any international-transfer safeguards also require contract and account review. This notice does not claim that processing stays inside the European Economic Area.
Controller and legal-basis boundary
The public site names Enrique Luis Lloret Calbo as the founder and operator contact for SaaS Sentinel at enriqueluislloret@gmail.com. The complete statutory controller identity, service address and final legal-basis schedule cannot be inferred from source code and are not claimed here. Request those details before sending personal data for a paid engagement; until they are published, do not send unnecessary personal or confidential information.