Privacy Policy
Last updated: August 10, 2026
⚠ SUMMARY
We collect the minimum data needed to operate the Service: an access token, scan results you upload, and billing data processed by Gumroad. We do not sell your data. We do not use your data for advertising. We do not train AI models on your data. This policy explains what we collect, why, and your rights to control it.
1. Data We Collect
We collect only the data necessary to provide the Service:
- Access tokens: A randomly generated UUID that identifies your account. We do not collect names, emails, or passwords unless you provide them during checkout or support communication. Tokens are generated client-side using the Web Crypto API and stored in your browser's localStorage.
- Scan data: When you push scan results from the CLI, we store the framework name, route inventory, and findings. This may include file paths and line numbers from your source code, but not the source code itself. You are responsible for ensuring you have the right to upload this data.
- Billing data: Processed entirely by Gumroad (our Merchant of Record). We receive your Gumroad subscription ID, but never your full payment card number, CVV, or other raw payment details. Gumroad's privacy policy applies to payment data.
- Usage logs: Server logs include IP address, user agent, timestamp, and requested URL. These are used for rate limiting, abuse prevention, and debugging. Logs are retained for 30 days, then permanently deleted.
- Cookies & local storage: We use browser localStorage (not cookies) to store your access token between sessions. We do not use tracking cookies, analytics cookies, or advertising cookies. Clearing your browser storage logs you out.
2. How We Use Your Data
We use your data exclusively for the following purposes:
- Displaying your scan results in the dashboard
- Generating ABOM PDF reports and badge SVGs
- Verifying your subscription status with Gumroad
- Preventing abuse, rate-limiting automated traffic, and detecting bots
- Providing support when you contact us
- Maintaining the security and integrity of the Service
- Complying with legal obligations
We do NOT: sell, rent, or trade your data; use your data for advertising or marketing; use your data to train machine learning models; share your scan results with third parties; or use your source code paths to identify your internal architecture. Your data is yours and we treat it as confidential.
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area, United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Contract: Processing necessary to perform our contract with you (providing the Service) under Article 6(1)(b) of the GDPR.
- Legitimate interest: Processing for rate limiting, abuse prevention, and security under Article 6(1)(f) of the GDPR.
- Legal obligation: Processing to comply with tax, billing, and other legal requirements under Article 6(1)(c) of the GDPR.
- Consent: Where you provide consent (e.g., contacting support), you may withdraw it at any time.
4. Data Storage & Security
Scan data and token records are stored in a Neon PostgreSQL database hosted in the cloud. All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Access to the database is restricted to authenticated API routes and is isolated to our cloud account. We do not store data on local disks, unencrypted media, or personal devices.
We implement industry-standard security measures including: Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), bot detection, rate limiting, and regular security reviews. However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR.
5. Data Sharing & Sub-Processors
We do not sell, rent, or trade your personal data. We share data only with the following sub-processors, who process data on our behalf under written agreements that meet GDPR Article 28 requirements:
- Gumroad, Inc.: Payment processing (Merchant of Record). Processes your name, email, and payment details. Privacy policy.
- Vercel Inc: Hosting provider. Processes IP addresses and request logs. Privacy policy.
- Neon Database Inc: Database hosting. Stores encrypted scan data and token records. Privacy policy.
- GitLab Inc: Source code hosting (for the open-source CLI). Does not process scan data. Privacy policy.
We may also disclose data to law enforcement or government authorities when required by law, court order, or valid legal process, or when we believe in good faith that disclosure is necessary to protect our rights, safety, or property, or those of third parties. We will disclose only the minimum data necessary to comply.
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (the "right to be forgotten").
- Restriction: Request that we limit processing of your data.
- Portability: Request your data in a structured, machine-readable format (JSON).
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent at any time where processing is based on consent.
- Complain: Lodge a complaint with your local data protection authority.
To exercise these rights, contact ubaid0345@proton.me. We will respond within 30 days. We may request additional information to verify your identity before processing your request. We may decline requests that are frivolous, repetitive, or would infringe on the rights of others.
7. International Data Transfers
Your data may be processed in countries other than your own, including the United States. Where data is transferred from the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or another valid transfer mechanism under applicable data protection law. By using the Service, you acknowledge that your data may be transferred to and processed in such countries.
8. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
- Scan data: Retained for the lifetime of your account. Deleted within 30 days of account deletion.
- Token records: Retained indefinitely for billing reconciliation, fraud prevention, and legal compliance.
- Server logs: Retained for 30 days, then permanently deleted.
- Billing records: Retained for 7 years as required by tax law.
- Support communications: Retained for 2 years after the last interaction.
When data is no longer needed, we delete it permanently or anonymize it so it cannot be linked to you. We are not responsible for data loss caused by: (a) account termination for Terms violations, (b) expiration of retention windows, (c) database failures, or (d) your failure to maintain backups.
9. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you are under 16, do not use the Service. If you believe a child has provided us with personal data, contact us immediately and we will delete it. We do not knowingly process data from children for targeted advertising, behavioral tracking, or any purpose prohibited by COPPA, the GDPR, or other applicable children's privacy laws.
10. Cookies & Tracking
We do not use cookies for tracking, advertising, or analytics. The Service uses browser localStorage to store your access token, which is required to load your dashboard. This is strictly functional storage and does not track your behavior across sites. Clearing your browser storage will log you out and you will need your token URL to regain access. We do not use Google Analytics, Facebook Pixel, or similar tracking technologies.
11. Your Choices & Opt-Outs
You can: (a) decline to provide data by not using the Service; (b) delete your data by contacting support; (c) disable localStorage in your browser (this will prevent the Service from working); (d) opt out of marketing communications (we rarely send marketing emails, but you can unsubscribe via the link in any email); (e) use a VPN or proxy to mask your IP address. You cannot opt out of functional data collection (tokens, scan data) while using the Service, as it is required to provide the Service.
12. Security Vulnerability Disclosure
If you discover a security vulnerability in the Service, please report it responsibly to ubaid0345@proton.me before disclosing it publicly. We will acknowledge receipt within 48 hours and provide a timeline for a fix within 72 hours. We will not take legal action against good-faith security researchers who follow responsible disclosure. We may offer a reward or acknowledgment for significant vulnerability reports at our discretion.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the dashboard at least 30 days before the change takes effect. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. If you do not agree, you must stop using the Service and request deletion of your data.
14. Contact & Data Protection Officer
For privacy questions, data requests, or to exercise your rights, contact us at ubaid0345@proton.me. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For EU users, the supervisory authority is the data protection authority in the EU member state where you reside.