Legal
Privacy Policy
Last updated: July 27, 2026
1. What we collect
- URLs / hostnames you submit for scanning and the scan type you choose (website or app).
- Scan results, scores, and timestamps needed to show your report and leaderboard entries.
- Basic request metadata (approximate IP, user agent) for rate-limiting and abuse prevention.
- Payment metadata from our processor if you unlock a full report (we do not store full card numbers).
- Optional GitHub OAuth tokens/scopes only if you connect a repo for deepen scans.
2. How we use data
We use this data to run defensive audits, display reports, operate the leaderboard, prevent abuse, process unlocks, and improve the product. We do not sell personal data.
3. What a scan touches
Scans fetch publicly reachable responses for the URL you provide (headers, HTML, linked same-origin scripts, selected well-known paths, and public DNS records). We do not intentionally access private networks. Optional GitHub deepen reads repository contents you authorize.
4. Public leaderboard
Published free scans may show a sanitized hostname and score publicly. Avoid submitting sensitive internal hostnames if you do not want them listed.
5. Retention
Demo infrastructure may keep scan records ephemerally (including in-memory stores that reset). As the product matures we may retain reports longer to support unlock links; we will update this Policy accordingly.
6. Processors
We may use hosting (e.g. Vercel), payments (e.g. Stripe), and analytics/error tools under their respective privacy terms.
7. Your choices
Do not submit personal data in URLs you do not control. To request deletion of a report identifier you control, contact us via the site. See also our Terms of Use.