Privacy Policy
Last updated: placeholder — not yet finalized.
1. Information we collect
- Account info from Google sign-in: name, email address, profile image.
- The domains you add as projects, and their ownership-verification status.
- Scan results: findings, evidence snippets (which may include short, sometimes redacted excerpts of your own public-facing code or config), severity, and remediation text.
- Billing status and plan tier (Stripe handles your actual payment details — we never see full card numbers).
2. Domains we scan — and don't
We only scan domains you've added and proven ownership of via a verification meta tag, re-checked at the start of every scan. We do not scan, store data about, or otherwise process any domain you haven't explicitly added and verified.
3. How we use your data
We use your data to run scans, generate and store findings and fixes, unlock full reports once a scan is paid for, and manage your subscription. Once a report is unlocked, its findings are sent to a third-party AI model (via OpenRouter, currently a DeepSeek model) to generate a plain-language explanation and remediation steps — this only happens after unlock, never on a free scan, and the model is instructed to perform remediation only, not to generate attack techniques.
4. Third parties we share data with
- Google — authentication (Sign in with Google).
- Stripe — subscription billing and payment processing.
- OpenRouter / DeepSeek — generating remediation text for unlocked findings.
- Our database and hosting providers — storing account, project, and scan data.
We do not sell your data.
5. Retention
We retain account, project, and scan data for as long as your account is active. If you delete your account, we will delete or de-identify this data within a reasonable period, except where we need to keep it for billing records, fraud prevention, or legal compliance. (Placeholder — exact retention windows are pending legal review.)
6. Your rights
You can request a copy of your data or ask us to delete your account and associated data at any time by contacting us below. (Placeholder — this section will be expanded to reflect applicable regional privacy law, e.g. GDPR/CCPA, before Production.)
7. No liability disclaimer
Placeholder — pending real legal review. This policy is provided for informational purposes only during development and does not constitute a legally binding privacy commitment. It will be replaced with reviewed, jurisdiction-appropriate language before Production.
8. Contact
Questions about this policy, or to request data deletion: hello@unbreachable.dev.