Privacy policy
Last updated: September 11, 2026
This English version is the canonical one and prevails in case of conflict.
Scanfull was designed to need little: no sign-up, no password, and we ask only for what’s necessary to run the scan and deliver the report. This policy explains, in plain language, what data we collect, why, who we share it with, and how you exercise your rights. Any questions: help@scanfull.dev.
1.Who controls your data
The party responsible for processing the data (controller) is Smart Data Invest LLC, a company incorporated in the state of Delaware, United States, with an office in Orlando, Florida, which operates Scanfull (scanfull.dev). In this text, "Scanfull", "we", and "our" refer to it.
For any privacy matter, including to exercise your rights, the contact is help@scanfull.dev. That same address serves as the data protection officer (DPO) channel where the law requires one.
2.What data we collect and why
We collect data at three moments: when you run a scan, when you buy a plan, and when you contact us.
- When you run a scan (free or paid): the URL you pasted, what your site responded to our browser (headers, pages, public files), the findings and evidence for each flaw, the resulting score, and your IP address. Purpose: run the audit, generate the report, enable the retest, and limit abuse (the IP serves rate-limiting per origin). Secrets found on your site, such as API keys, are masked before anything is stored: we keep a partial version and a hash, never the full value.
- When you buy a plan (via Stripe): email, name, and, if you choose to provide it, phone; the purchase record (plan, amount, date, payment identifier). Purpose: send the report access link and the panel magic link, invoice and charge, handle refund requests, and comply with tax and accounting obligations. We do not receive or store your card number: that stays with Stripe.
- When you contact us: the content of the email you send to help@scanfull.dev and the address it came from. Purpose: respond and keep a support history.
- When you use the site: technical logs generated by the infrastructure (request date and time, IP, browser, page accessed), used to operate the service, diagnose errors, and protect against attacks.
To run the checks, the browser may also request common public paths and endpoints on your site and consult public sources about your domain, such as Certificate Transparency logs used to discover subdomains. This stays on the public surface and is read-only.
We don’t ask for or want: passwords, card data, ID documents, or any sensitive data. If you put a secret inside a URL sent for a scan, it may get logged; that’s why we ask you never to do this.
We may also generate aggregated, anonymized data (for example, "x% of sites built with a given tool expose such a flaw") to improve the service and publish statistics. This data does not identify you or your site.
3.What we rely on to process the data
Where the law requires a legal basis for each processing (as in the EU, UK, and Brazil), we use the following:
- Performance of a contract: running the scan you asked for, delivering the report, enabling the retest, sending the access links, and processing payment.
- Legitimate interest: limiting abuse and protecting the infrastructure (IP and technical logs), diagnosing errors, preventing fraud, keeping a support history, and producing anonymized statistics. In those cases, we assess whether our interest does not disproportionately harm your rights.
- Legal obligation: keeping payment records for the period tax and accounting law requires, and responding to orders from authorities.
- Consent: only for marketing or WhatsApp communications, which you must explicitly authorize and can withdraw at any time.
4.The access session (+ User and + Admin plans)
To audit your site’s logged-in area, you provide a temporary session from your own browser (the cookie or token created after login), never the password. This session gets its own handling:
- It travels only within the scan job, to the browser that runs the audit.
- It is ephemeral: used while the scan runs and discarded afterward. It is not stored in a database, a log, a backup, or anywhere else.
- Personal data the browser may see inside the logged-in area (for example, usernames from your system) only enters the report to the extent needed to prove a flaw, as evidence, and always masked where possible.
We recommend using a test account or ending the session (logging out) after the scan, which invalidates the provided cookie.
5.Recurring monitoring
If you turn on recurring monitoring for a paid report, we re-run the automated audit on that report’s site on the schedule you chose (daily or weekly) and email you when a new significant finding appears. This adds the following:
- We store your monitoring choice (whether it’s on and how often) on the report and, when a run finds something new, an alert record — so we don’t email you twice for the same event.
- Alerts are sent to the email from your purchase, as a transactional message for a service you enabled. They may include the site’s address, a summary of what’s new, and a link to the updated report.
- Each monitoring run collects the same scan data described in "What data we collect and why", for the same purposes, on a recurring basis.
You can turn monitoring off at any time from the "my reports" panel, which stops future runs and alerts, and you can ask us to delete the alert history at help@scanfull.dev. Monitoring adds no new recipients: the same processors listed in "Who we share with" run it.
6.Who we share with
We don’t sell your data or rent it out. We share it with those who need it for the service to work (our processors or subprocessors) and, on the marketing site, with the ad platforms we use to measure and target our campaigns. All act under a contract that requires them to protect the data:
- Stripe — payment processing and checkout. It’s who receives your card data.
- Purelymail — sending and receiving the help@scanfull.dev emails (access links, support).
- Vercel — hosting the site and running the application.
- Neon — the database (Postgres) where scans, findings, and purchase records live.
- Upstash — the scan processing queue.
- OpenAI — the AI of the optional help assistant (+ User/+ Admin levels), which guides you to grant access to your logged-in area. It receives your messages and any screenshot you send, only to reply. The screenshot is sent to OpenAI and kept for a few days (to improve support) — don’t put a password or sensitive data in the screenshot; if it appears, blur it. The report’s fixes do NOT use third-party AI: they are generated by our own catalog, on our server.
- Google (Google Analytics) — receives, via the analytics cookies described in the "Cookies" section, site usage data (pages accessed, traffic source) to generate audience statistics. Acts as our subprocessor.
- Meta (Facebook/Instagram) and LinkedIn — only on the site’s marketing pages, receive, via the pixels described in the "Cookies" section, the signal that you visited a page or took an action, to measure our ads’ effectiveness and enable remarketing. That signal does not include your scan content, which is never shared with ad platforms.
Beyond those, we may share data when the law requires it (a court order, a request from a competent authority), to protect the rights, safety, or property of Scanfull and third parties, or in a corporate reorganization, merger, or sale, in which case the acquirer assumes the obligations of this policy.
Responsible disclosure: if we find a flaw affecting a third party, we say it exists, never where it is or how to exploit it. The technical detail only goes to whoever proves they own the domain.
7.International transfers
Smart Data Invest LLC is in the United States, and our infrastructure and processors process the data there. If you are in another country, your data will be transferred to the United States.
When your country’s law requires safeguards for that transfer, we use the ones the law provides: for data from the EU, the UK, and Brazil, the standard contractual clauses approved by the competent authorities (or an equivalent instrument) with our processors, plus technical measures such as encryption in transit and at rest. You can ask for more information about these safeguards at help@scanfull.dev.
8.How long we keep it
We keep each piece of data only as long as needed for the purpose it was collected for:
- Scans, findings, and reports: while the report needs to be reachable by the link and to enable retest and comparison between scans of the same site. You can request deletion at any time.
- Purchase data (email, name, phone, payment record): for the period tax and accounting law requires for financial records, and while needed to handle refunds and disputes.
- IP address and technical logs: for a short period, only enough for abuse control and error diagnosis.
- Access session: not kept. It is discarded as soon as the scan finishes.
- Monitoring settings and alert history: while monitoring is on, plus a short period afterward; you can turn it off and request deletion at any time.
- Support emails: for as long as needed for the support and a reasonable history of the relationship.
After those periods, the data is deleted or anonymized, unless the law requires keeping it longer.
9.How we protect the data
We apply to our own service what we require of the sites we audit: encrypted traffic (HTTPS), strict security headers, restricted database access, and secrets found masked before any storage — a rule verified by an automated test and by a constraint in the database itself. Access to paid content is via a link with a unique, long, hard-to-guess code.
No system is fully secure. If we discover an incident affecting your data, we will notify you and the competent authorities as the law requires. On your side, keep the access links safe: whoever has the link sees the report.
10.Cookies
We use the minimum necessary. The site stores a functional cookie called "theme", which keeps your light or dark theme preference for up to a year — it does not identify you.
To understand how the site is used and improve it, we use Microsoft Clarity, an analytics tool that stores two cookies (_clck and _clsk) and records, in aggregate, clicks, scrolling, and navigation (heatmaps and session recording). We set Clarity to the maximum masking level: page text and what you type are hidden in your browser before anything is sent. Clarity is a Microsoft service, acting as our subprocessor.
We also use Google Analytics 4 to measure site traffic: where visitors come from (search, social, ads), which pages they visit, and what converts. It stores its own cookies (like _ga and _ga_<id>) that assign your browser a random identifier — we don’t use this data to identify you personally. Google acts as our subprocessor; the data may be used to improve the measurement of our Google ads.
On the site’s marketing pages, we use two advertising pixels to measure our ads’ effectiveness and enable remarketing: the Meta Pixel (Facebook/Instagram), which stores the _fbp cookie, and the LinkedIn Insight Tag, which stores LinkedIn’s own cookies (like li_sugr and UserMatchHistory). They tell Meta and LinkedIn that you visited a page of ours or took an action, so we can measure conversions and show ads to similar audiences. These are third-party cookies and may involve cross-site tracking by those platforms. They never receive the content of your scans, findings, or reports.
These analytics and advertising cookies load only on the site’s public pages — never on the report pages or the access panel, so the link with your access token isn’t shared with third parties.
You can refuse the analytics and advertising cookies by blocking cookies in your browser (or the domains clarity.ms, google-analytics.com, googletagmanager.com, facebook.com, and licdn.com), enabling the "Do Not Track"/GPC signal, or using Meta’s and LinkedIn’s ad preferences — in any case without losing access to the service. Report access works via the code in the link itself, not via a cookie. Where the law requires prior consent for these cookies, this section will be updated and consent will be requested before enabling them.
11.Minors
Scanfull is a service for people 18 and over and is not directed at children or teenagers. We do not knowingly collect data from minors. If you believe a minor gave us data, email help@scanfull.dev and we will delete whatever is identified.
12.Your rights (all countries)
Regardless of where you live, you can ask us to:
- Know what data we have about you and receive a copy.
- Correct incomplete or wrong data.
- Delete your data, except what the law obliges us to keep (such as payment records).
- Receive your data in a structured, commonly used format (portability).
- Object to processing based on legitimate interest, or ask that it be restricted.
- Withdraw a consent you gave, without affecting what was done before.
- Know whom we share your data with and what safeguards we use in the international transfer.
To exercise any right, email help@scanfull.dev, preferably from the email used for the purchase, so we can confirm the request is yours. We respond within 30 days, or the shorter period your country’s law requires; if we need more time, we let you know. We don’t charge for this, except for manifestly repetitive requests, where the law permits. You may also complain to your country’s data protection authority.
The sections below detail additional rights under specific laws.
13.European Union and United Kingdom (GDPR and UK GDPR)
If you are in the European Economic Area or the United Kingdom, the processing of your data follows the General Data Protection Regulation (GDPR) and the UK GDPR. The legal bases we use are in the "What we rely on to process the data" section: performance of a contract, legitimate interest, legal obligation, and consent (the latter only for marketing).
Beyond the general rights above, you have the right of access, rectification, erasure ("right to be forgotten"), portability, objection, and restriction of processing, and not to be subject to solely automated decisions with legal or similar effects — Scanfull does not make that kind of decision about you. When we process data based on legitimate interest, you can object at any time, and we will stop, unless we demonstrate compelling legitimate grounds that override.
Transfers: your data is transferred to the United States, covered by standard contractual clauses adopted by the European Commission (and the UK’s equivalent instrument) with our processors, plus complementary technical measures. You can request a copy of the safeguards at help@scanfull.dev.
You have the right to lodge a complaint with the data protection authority of your country of residence, of work, or of the place of the alleged infringement; in the UK, the Information Commissioner’s Office (ICO). Smart Data Invest LLC is not established in the EU or the UK; if a local representative is designated, the contact will be published on this page.
14.California (CCPA/CPRA)
If you live in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), grants additional rights. In the last 12 months we collected the following categories of personal data: identifiers (name, email, optional phone, IP address); commercial information (purchase records); internet activity information (submitted URL, technical site-access logs); and, when you provide an access session, the content the browser observes in the logged-in area, only during the scan. The sources are you, your site, and Stripe (purchase data). The purposes and recipients are in the previous sections.
We do not sell personal data for money. However, the advertising pixels described in the "Cookies" section (Meta Pixel and LinkedIn Insight Tag), on the site’s marketing pages, may constitute "sharing" for cross-context behavioral advertising under the CPRA. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit. You can opt out of that sharing at any time: by blocking cookies in your browser (or the domains facebook.com and licdn.com), enabling a recognized opt-out signal (Global Privacy Control / "Do Not Track"), or emailing help@scanfull.dev, which we will treat as a request to opt out of sharing.
Your rights: to know what data we collect, use, and disclose, and to whom; to request deletion; to request correction of inaccurate data; to opt out of having data sold or shared (for sharing via pixels, use the options in the paragraph above); and not to be discriminated against for exercising these rights — we don’t deny service, charge a different price, or offer a different quality because of a request.
To exercise the rights, email help@scanfull.dev. We verify identity by matching the request email against the purchase or scan record; we may ask for more information if needed. You may designate an authorized agent to request on your behalf, with written proof of the authorization. We respond within 45 days, extendable by another 45 when the law permits, with notice.
15.Brazil (LGPD)
If you live in Brazil, the processing of your data follows the General Personal Data Protection Law (Law No. 13.709/2018). Smart Data Invest LLC is the controller. The data protection officer (DPO) can be reached at help@scanfull.dev.
The legal bases we use are those in the "What we rely on to process the data" section, which correspond, under the LGPD, to performance of a contract (art. 7, V), legitimate interest (art. 7, IX), compliance with a legal obligation (art. 7, II), and consent (art. 7, I), the latter only for marketing.
Beyond the general rights, you may request, under art. 18 of the LGPD: confirmation that processing exists; access; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data; portability; information about sharing; information about the possibility of not consenting and the consequences; and withdrawal of consent. We respond within 15 days for full access requests, per the law, and as soon as possible for the others.
International transfer: your data is processed in the United States, based on the grounds of art. 33 of the LGPD, in particular standard contractual clauses with our processors and the performance of the contract you entered into with us. You may petition the National Data Protection Authority (ANPD).
16.Other countries
If you live in another country, you have, at a minimum, the rights listed in the "Your rights (all countries)" section, plus those your local law grants and that cannot be waived by contract. We’ll handle any request with the same care and through the same channel: help@scanfull.dev. If your country’s law provides a specific deadline, authority, or procedure, we’ll follow what it determines.
17.Communications and marketing
By default, we only send transactional emails: the report access link, the panel magic link, payment confirmations, and support replies. These emails are part of the service and don’t depend on consent.
Marketing communications, by email or WhatsApp, only happen if you expressly authorize them, in a separate option that comes unchecked. You can withdraw that authorization at any time, via the unsubscribe link in the email itself or by emailing help@scanfull.dev.
18.Changes to this policy
We may update this policy to reflect changes in the service, the law, or our processors. The date at the top indicates the version in force. Material changes will be announced on the site and, when we have your email from a purchase, by email. If a change requires your consent, we will ask before applying it.
19.Contact and officer (DPO)
For any privacy matter, requests to exercise rights, or contact with the data protection officer: help@scanfull.dev. Smart Data Invest LLC · 7345 W Sand Lake Rd, STE 210, Orlando, FL 32819, USA.
Last updated: September 11, 2026