Privacy Policy

A plain-language summary of what we collect when you use EngineeringScore, and what we do with it.

Who we are

EngineeringScore is a website-audit tool operated by We Do Dev Work, a software agency based in Bangkok, Thailand.

What we collect

  • The website URL you ask us to scan, and the technical results of that scan.
  • The answers you give to the follow-up questions about your team and setup.
  • The contact details you choose to share (name, email, and optionally your company) to receive your full report.
  • If you buy the fix plan, a record that the purchase happened against your report, the amount, and the time you consented to immediate delivery. Payment is handled by Stripe: your card details go to Stripe and never reach us.

How we use it

We use this information to generate your Engineering Score and roadmap, and to follow up about helping you act on the results. We do not sell your data or share it with third parties for their own marketing.

Where it's stored

Assessment data is stored in our database (hosted on Supabase). We keep it only as long as needed to provide and improve the service.

What becomes public if you publish a report

A scan is private until someone presses Publish. Nothing is published automatically and we never publish a report ourselves.

If you do publish, the report gets an address of the form engineeringscore.com/r/<token> and that page is public. Search engines can index it, it can be linked to from anywhere, and it carries the scanned domain, the score, the category grades and the roadmap. Anyone who has the link, or who finds the page in a search, can read it. Treat publishing as making the report public, because that is what it is.

One category is held back on the public page. The Exposure category covers credentials accidentally shipped in a site's own JavaScript, and naming which credential and which file on a public page would hand it to whoever reads the page next. On a published report those findings appear as counts and severities with no detail, and the page says so. The score is calculated from the full findings either way, so it is not inflated by what is withheld. Whoever ran the scan sees the detail in their own copy.

You can unpublish a report you published, from the same toolbar you published it with. That takes the page down but does not stop it being published again later.

If someone published a report about your domain

Anyone can scan any public URL here without proving they own it. That is deliberate, and it means someone can publish a report about a domain that is not theirs. If that domain is yours and you would rather the page did not exist, you can have it removed: request removal here.

We ask you to prove you control the domain first, either by opening a link we send to a fixed role address on it or by publishing a DNS TXT record in its zone. We do not accept a typed email address as proof, because an address the requester chooses proves nothing and would make every published report removable by any stranger.

Once proven, every published report for that domain and its subdomains stops resolving, so search engines drop the pages rather than merely stop displaying them, and any future attempt to publish a report for the domain is refused. Scanning still works: anyone can still scan the site and see their own results privately. It is publication that stops, not scanning.

Analytics

We use Google Analytics 4 to count page views, so we can tell which pages are worth writing more of. It only runs if you accept it, and it is off until you do. Nothing about the scanner changes either way.

If you accept, your browser loads a script from googletagmanager.com and sends Google, for each page you view here, the address of the page, the page title, the page you came from, your approximate location derived from your IP address, and basic details about your browser, device and screen. Google receives that data and processes it on our behalf under its own terms. We do not send it your name, your email, or the URL you asked us to scan.

Accepting also sets first-party cookies on this domain, named _ga and _ga_<id>, which give your browser a random identifier so a repeat visit is not counted as a new person. They are set by our own domain, not by a third party, and they last up to two years unless you clear them.

One cookie is not covered by this choice: when you run a scan we set a strictly necessary cookie called es_assessment, which is what lets you refresh the page without losing your report. It carries no analytics and is not used to track you across sites. Without it the product does not work, so it is not something we can offer to switch off.

If your browser sends a Do Not Track signal we take that as an answer and never ask, and analytics stays off.

You can change your mind here at any time. Turning analytics off takes effect immediately, without a reload, and clears the _ga cookies. To be straight about the limit of that: page views already sent to Google are held by Google under its retention settings, and switching off here does not reach back and delete them.

Your choices

You can ask us to access or delete the data associated with your assessment at any time by emailing info@wedodevwork.com.

Ready to see where you stand?

Scan your site and get your Engineering Score with a prioritized roadmap in under a minute, no signup required.

Scan your site