RoastMyOpsec

Legal

Privacy Policy

Last updated: July 27, 2026

1. What we collect

  • URLs / hostnames you submit for scanning and the scan type you choose (website or app).
  • Scan results, scores, and timestamps needed to show your report and leaderboard entries.
  • Basic request metadata (approximate IP, user agent) for rate-limiting and abuse prevention.
  • Payment metadata from our processor if you unlock a full report (we do not store full card numbers).
  • Optional GitHub OAuth tokens/scopes only if you connect a repo for deepen scans.

2. How we use data

We use this data to run defensive audits, display reports, operate the leaderboard, prevent abuse, process unlocks, and improve the product. We do not sell personal data.

3. What a scan touches

Scans fetch publicly reachable responses for the URL you provide (headers, HTML, linked same-origin scripts, selected well-known paths, and public DNS records). We do not intentionally access private networks. Optional GitHub deepen reads repository contents you authorize.

4. Public leaderboard

Published free scans may show a sanitized hostname and score publicly. Avoid submitting sensitive internal hostnames if you do not want them listed.

5. Retention

Demo infrastructure may keep scan records ephemerally (including in-memory stores that reset). As the product matures we may retain reports longer to support unlock links; we will update this Policy accordingly.

6. Processors

We may use hosting (e.g. Vercel), payments (e.g. Stripe), and analytics/error tools under their respective privacy terms.

7. Your choices

Do not submit personal data in URLs you do not control. To request deletion of a report identifier you control, contact us via the site. See also our Terms of Use.