Privacy
Short version: we keep your email so you can sign in, and a summary of each scan so you can see what changed. Not your site's content.
What we store about you
- Your email address. Needed to sign in, to reset your password, and to tell you when a deploy breaks something. Nothing else about you — no name, no company, no profile.
- A verifier for your password, never the password itself. We could not tell you your own password if you asked.
- Sessions — as verifiers too, so a copy of our database does not let anyone sign in as you.
What we store about your site
The scan runs in memory. What reaches the database is a summary: which problems were found, where, and a masked sample as proof. Your pages, your bundles, your keys and your data are not stored — keeping them would make us a target worth attacking, which is the opposite of what you hired us for.
What leaves our servers
Findings are triaged by a language model. What goes to it is the kind of problem, where it is, and the facts — never your content. Emails go to the service that delivers them. That is the whole list.
Deleting your account
One button in your account. Your email and sessions are gone for good. Reports you already ran stay reachable by their links but stop being yours, and the anonymous statistics we keep — which kinds of problems appear in apps built with which builder — contain nothing that points back to you.
Sites you scan
Anything beyond what a visitor sees requires proof that you control the site. If you got here because you saw our traffic in someone else's logs, the scanner page explains it and tells you how to stop it.