Privacy policy.
Last updated: August 2026
The short version.
Wiley is built to be privacy-first. We don't use cookies. We don't collect personal data. We don't track visitors across sites. We don't sell data. The tracking script does the minimum necessary to coach website owners, nothing more.
What the tracking script collects.
When a visitor loads a page with the Wiley script, we record:
- The page URL and referrer
- UTM parameters if present
- Scroll depth and time on page
- Outbound link clicks
- Goal events you've tagged
- Viewport size (mobile/tablet/desktop)
- Country (derived from IP address, which is not stored)
- A daily anonymous fingerprint (see below)
We do not collect: names, email addresses, IP addresses (beyond country derivation), device identifiers, or any other personally identifiable information.
The anonymous fingerprint.
To distinguish unique visitors without cookies or personal data, Wiley generates a daily fingerprint: a hashed combination of signals like browser type and screen size, salted with the current date. This fingerprint resets every 24 hours and cannot be reversed to identify an individual. It's used only to count unique visitors within a day.
No cookies.
The Wiley tracking script sets no cookies, first-party or third-party. This means no cookie consent banner is required for Wiley's tracking under GDPR, ePrivacy Directive, or CCPA for most use cases. You should still consult your own legal counsel about your specific situation.
Data storage.
All event data is stored in Cloudflare's infrastructure. Data is associated with a site ID, never with a visitor identity. Wiley account holders can delete their site data at any time from the dashboard.
Public crawl data.
Wiley periodically crawls the public pages of sites enrolled in the service. This crawl behaves like any standard web crawler: it only accesses pages that are publicly available and respects robots.txt. No authentication is used and no private data is accessed.
Accessibility scanning (paid plans).
On paid plans, Wiley runs an accessibility scan against your site's public pages, cycling through your known pages roughly once a month. This has two layers:
- Structural checks: automated, rule-based checks (missing alt attributes, contrast ratios, heading structure, keyboard reachability, and similar) run against a rendered copy of the page. These never leave Cloudflare's infrastructure and don't involve any third party.
- AI-reviewed checks: a smaller set of checks that automated rules can't reliably catch (whether alt text is actually meaningful, whether color alone is used to convey information, whether text is baked into an image, and overall reading-level) are judged by sending screenshots of specific images and the page's visible text to Anthropic's Claude, via Cloudflare's AI Gateway. Only content already public on your site is sent, never visitor data, account details, or anything behind a login.
Claude's verdict for a given image is cached for up to 90 days, keyed to the image itself, so the same logo or photo reused across many pages of your site is only reviewed once rather than on every page it appears on. You can see everything this scan finds, including AI-reviewed findings, in the Accessibility tab of your dashboard, and mark issues as fixed once you've addressed them.
This scanning is automated and does not constitute a legal accessibility audit or compliance certification. See the disclosure shown alongside your results in the dashboard.
Do Not Track.
The Wiley script respects the Do Not Track browser setting. If a visitor has DNT enabled, no events are recorded for that visitor.
Account data.
When you create a Wiley account, we store your email address, your site domain, and your stated goal. We use your email to send the weekly Nudge and transactional emails (password reset, etc.). We don't send marketing email. We don't share your email with third parties.
You may also provide additional context: notes about your site, goals, or feedback on nudges. This is stored and used to improve the relevance of your nudges.
Content you create.
If you use Just Me (Wiley's page and blog publishing feature), we store the content you write: page blocks, blog posts, and layout settings. This content is associated with your account and stored in Cloudflare's infrastructure. You can delete it at any time. We do not collect data about readers of your published pages.
Google Analytics connection (paid plans).
Wiley Solo, Plus, and Pro users can optionally connect a Google Analytics 4 (GA4) property to give Wiley an additional, independent source of evidence when generating nudges. This is entirely optional — Wiley's own analytics keep working exactly the same whether or not you connect one, and connecting one never replaces or overrides the analytics Wiley collects on its own.
Connecting uses Google's standard OAuth sign-in and requests only the minimum read-only permission needed (analytics.readonly) — Wiley can never modify your GA4 property, your Google Ads account, or anything else in your Google account. You choose exactly which GA4 property to connect after signing in.
What we import is aggregated: daily totals for visitors, sessions, pageviews, and conversions; a breakdown by traffic channel and device type; and a rolling snapshot of your top pages by pageviews. We never request or receive individual-visitor-level GA4 data — no Client IDs, User IDs, or anything that could identify a specific person.
Because Wiley's own analytics and GA4 measure traffic differently (different session logic, bot filtering, and consent handling), the two will often report different numbers for the same period. That's expected and by design — Wiley treats GA4 as corroborating evidence to compare against its own analytics, not as a replacement or a single "more correct" number.
Your Google OAuth credentials are encrypted at rest and are never exposed to your browser or included in any API response. Imported GA4 data older than 13 months is condensed into a short internal summary and the detailed daily data is deleted, matching how Wiley ages out its own analytics data.
You can disconnect Google Analytics at any time from the Integrations tab in your account settings. Disconnecting immediately revokes Wiley's access on Google's side and deletes your stored credentials. You choose separately whether to also delete the GA4 data already imported: by default it's retained (it's aggregated and contains no personal information, so keeping it costs nothing privacy-wise and preserves the historical context it took time to build), or you can choose to delete it permanently at the same time you disconnect.
Wiley Pro users can also optionally upload a one-time Google Analytics CSV export as a lighter-weight alternative to connecting live. Uploaded data is the same kind of aggregated, page-level traffic data, with no individual visitor information included. It's stored in your account, used only to inform your nudges, and can be deleted at any time from the Data page in your dashboard.
Search rank tracking.
On paid plans, Wiley automatically selects a set of search keywords relevant to your site and checks where your site ranks in Google results for those terms. This runs daily and the results are used to inform your nudges. For example, they can identify pages that could rank higher with a small structural change.
To perform these checks, your site's domain and the selected keywords are sent to DataForSEO, a third-party service that queries Google on our behalf. No visitor data, account information, or personally identifiable information is included in these requests. You can see which keywords Wiley is tracking in your dashboard settings.
PageSpeed testing.
On paid plans, Wiley periodically tests your site's page speed and Core Web Vitals using the Google PageSpeed Insights API. This runs a standard Lighthouse analysis against your public homepage and returns performance metrics (load time, layout stability, interactivity). No visitor data is sent, only your site's public URL. Results are used to generate nudges about performance improvements that may affect search ranking and user experience.
Broken link and content checking.
During Wiley's regular crawls of your public site, we check whether any internal links return error responses (such as 404 Not Found), and we look for date signals on pages to understand how recently content was updated. This is done entirely using your site's publicly available pages. No personal data is involved. Findings are used to flag outdated content and broken links in your nudges.
Connections (paid plans).
Wiley's Connections feature explains what may have caused a change in your traffic, such as a site change, a backlink shift, a Google algorithm update, or a seasonal pattern, instead of just reporting that traffic moved.
Most of this runs on data Wiley already collects: referrer spikes are detected from your own traffic data, and possible Google algorithm updates are inferred from rank movement across the keywords Wiley already tracks for your site. No separate third-party call is made for either. Weekly, we also check your site's backlinks by sending your site's domain to DataForSEO to retrieve a summary of referring domains; no visitor or account data is included in this request.
Third-party services.
Wiley uses the following third-party services:
- Cloudflare: infrastructure, Workers, D1 database, and transactional email delivery
- Stripe: payment processing (we never see or store card details)
- Anthropic (Claude): AI-powered nudge generation and accessibility review. Anonymized, aggregated site data is sent to generate nudges, including traffic metrics, crawl data, context notes you've provided, and imported analytics summaries. For the AI-reviewed accessibility checks (paid plans), screenshots of public page images and visible page text are also sent, routed through Cloudflare's AI Gateway. No personally identifiable visitor information is sent in either case.
- DataForSEO: Google search rank checking and backlink monitoring (paid plans). Your site domain (and, for rank checks, your selected keywords) is sent to retrieve ranking and backlink data. No visitor or account data is included.
- Google PageSpeed Insights: Page performance testing (paid plans). Your site's public URL is sent to retrieve Lighthouse performance metrics. No visitor or account data is included.
- Google Analytics: optional GA4 connection (paid plans, see above). Only requested if you choose to connect it; read-only, aggregated data only.
Contact.
Questions about privacy? [email protected]