LeaklyBot
What it is
Leakly is a conversion audit tool. Someone — usually the site’s own team — entered your domain and asked for an analysis. LeaklyBot opened the pages in a headless Chromium, on a desktop and a mobile viewport, and produced a report about what might be costing conversions.
It is not a continuous crawler and it does not index anything. It runs once, on request, and then stops. If nobody asks for an audit of your site, it never visits.
How to identify it
Every request carries this User-Agent:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 LeaklyBot/1.0 (+https://leakly.ai/bot) |
It begins with a standard Chrome token because the pages are loaded in a real Chromium and many sites serve broken markup to anything that does not look like a browser. The distinguishing part is LeaklyBot/1.0, and it is never omitted.
How it behaves
| Pages per audit | At most 5, chosen for relevance to the conversion being analyzed |
| Concurrency | 3 pages at a time, each loaded on two viewports |
| Duration | Around 20 seconds for a typical site, then it is gone |
| robots.txt | Read before anything else, and honoured. Disallowed paths are never fetched |
| Forms and logins | Never submitted. Nothing is typed, purchased or created |
| Cookie banners | Accepted so the page below can be measured, after the first screenshot is taken |
The load is comparable to a handful of ordinary visitors arriving at once, because that is essentially what it is: a real browser fetching your pages the way anyone else’s would.
What we keep
Screenshots of the pages visited, a structured extract of their public content, and the measurements taken while loading. All of it comes from pages served publicly to any visitor.
Captures are deleted automatically after 3 days. We do not sell this data, and we do not use it to train models. See the privacy policy for the full detail.
How to block it
Add this to your robots.txt. LeaklyBot reads it on every run and a named rule takes precedence over the wildcard group:
User-agent: LeaklyBot |
To allow audits but keep specific areas out of them, disallow only those paths. To block at the edge instead, filter on the LeaklyBot/1.0 token in the User-Agent header.
If you would rather we exclude your domain entirely, email hello@leakly.ai and we will add it to a server-side blocklist so no visitor can run an audit against it.