Legal instrument · Privacy Policy
Privacy
Policy
Rather than describe what we collect, here is the whole inventory — every item, where it lives, and how long it stays.
- Effective
- 28 September 2026
- Applies to
- securescanr.com
api.securescanr.com - Data requests
- hello@securescanr.com
Everything we hold
Twelve items. Four of them are never written down at all — those get a tick, not a bar.
In shortWe never keep the URL you scanned or the report. Only the domain's letter grade is kept, for 30 days, so its badge works.
Scanned URLs & Results
When you scan a URL, our backend sends a request to that URL to retrieve its HTTP headers, TLS certificate, DNS records and other publicly available security signals. Scanned URLs and the resulting report are not stored anywhere — they exist only for the duration of the scan request and are discarded once the response reaches your browser.
One small thing is kept: the scanned domain name with its letter grade and score, so that a security badge embedded for that domain can display it. It is kept for 30 days from the domain's last scan and then deleted. It is not linked to you, your IP address or your account, and it is never listed or published anywhere on SecureScanr — it is only readable one domain at a time, through that domain's badge.
The one deliberate exception is shareable report links, created only when you explicitly click "Share": that result is stored for 7 days and then expires automatically. Anyone holding the link can view it during that window.
Your own scan history — the list on the scan page — is saved only in your browser's local storage. It never reaches our servers and is not visible to us.
In shortYour IP picks your payment provider, stops abuse and meters the free tier. We never store the address — only a one-way monthly hash of it.
How We Use Your IP Address
Your IP address is used for three functional purposes. It is never sold, never shared with advertisers, and never stored by us as an address:
- Payment routing — to send you to Razorpay (India) or LemonSqueezy (international) automatically, we ask the geolocation service ip-api.com which country your address is in. The answer is used for that request only and is not retained by us.
- Rate limiting — a short in-memory counter (5 requests per 60 seconds per IP) protects the scanner from abuse. It lives in server memory, resets continuously, and is never written to our database.
- Free-scan limit and visitor count — free scans are limited per visitor per month, and we count how many different people use the scanner. For both, your IP is turned into a keyed one-way hash (HMAC-SHA256 under a server secret, combined with the current month), and only that hash is stored, next to your scan count for the month. It cannot be turned back into your IP address, and because the month is part of it, the same visitor cannot be followed from one month to the next. Paid plans are counted by API key instead.
Our infrastructure providers — Cloudflare and Railway — see your IP as a normal part of routing your request, and may keep their own standard access logs under their own privacy policies. We do not access or export those logs.
In shortScan PDFs are never saved. Agency PDFs are, because you asked us to schedule them.
PDF Reports
Scan-report PDFs are generated on-demand server-side and returned directly to your browser as a file download. No scan PDF is saved, cached, or stored server-side — once the response stream closes, it exists only on your device.
Compliance-report PDFs work the same way, except that if you ask for one to be emailed rather than downloaded, the address you give is used once to send it via Resend and is not added to any marketing list.
Agency scan PDFs are the exception in the inventory above. Because they are generated on a schedule and offered for later download from your agency dashboard, they are kept on a persistent volume for as long as your agency account stays active.
In shortPaid keys need an email and a counter. Agency emails are encrypted before they are stored.
API Keys & Paid Accounts
If you subscribe to Pro or Agency, we store your API key, email address, plan and monthly scan usage so the key keeps working and your quota resets correctly. This is not shared, sold, or used for marketing.
Agency customer emails are encrypted at rest with symmetric (Fernet) encryption before being written to storage — a step not applied to Pro emails, because an Agency record also carries a list of monitored domains and a scan history tied to that address. You can request deletion of your account data at any time by emailing hello@securescanr.com.
In shortCloudflare serves the pages, Railway runs the API and database, Resend sends the mail.
Infrastructure & Processors
The frontend and backend run on separate infrastructure, each with a narrow job:
- Cloudflare Pages serves the static frontend. No application data is stored there.
- Railway runs the Flask API and its SQLite database on a persistent volume — this is where API keys, quota counters, agency records and 7-day shared reports live.
- Resend sends account, receipt and agency-report email on our behalf.
- Razorpay (India) and LemonSqueezy (international) process payments directly — we never see or store your card details.
Google Fonts is loaded from Google's CDN for typography, so your browser makes a request to Google's servers when loading any SecureScanr page.
In shortWe set no tracking cookies — but a Google Ads tag runs here and may set its own.
Cookies & Advertising
SecureScanr sets no cookies of its own to track you across the site. It would be easy to stop there, and inaccurate: this site runs Google Ads conversion tracking (gtag.js) on every page — including this one — to measure ad performance. Google may set cookies as part of that tag and may use the data under its own privacy policy.
If you would rather not be measured that way, your browser's tracking-protection settings or any extension that blocks Google's tag will stop it. Doing so has no effect whatsoever on your ability to use the scanner.
In shortAsk and we will delete what we hold.
Contact & Data Requests
Questions about this policy, or want your account data deleted? Email hello@securescanr.com — I read every message.
Nothing in the table should surprise you. That is the point.