← vulnscan.pro

Privacy Policy

Last updated: March 8, 2026

1. Data We Collect

Account: Email, name (optional), hashed password. Scans: Target domain, results, findings, PDF reports. Payments: Processed by Lemon Squeezy — we never store card numbers. Usage: IP address (rate limiting only), timestamps.

2. How We Use Data

Account data for authentication and scan delivery. Scan results solely for report generation. We do not use scan data for training AI models, analytics, or any purpose beyond your report.

3. Data Storage

EU-based servers (Hetzner, Germany). Reports encrypted at rest (AES-256). Auto-deleted after 90 days.

4. Third-Party Services

Lemon Squeezy: EU payment processing. Resend: Transactional emails. OpenRouter/Anthropic: AI analysis (no PII transmitted). No data sold to advertisers.

5. Your Rights (GDPR)

Access, rectify, delete, export your data, or withdraw consent at any time. Contact support@vulnscan.pro.

6. Cookies

Essential session cookies only. No tracking, no analytics, no third-party cookies.

7. Data Breach

Notification within 72 hours as required by GDPR.

8. Contact

Data Controller: VulnScan Pro. Email: support@vulnscan.pro