Privacy Policy
Last updated: August 3, 2026
1. Information We Collect
We collect the minimum information necessary to provide the Service:
- Account data: Display name and WebAuthn credential (public key) provided during registration.
- Usage data: Tool name, target string, parameters, verdict, and latency for each API check. Target strings may contain command-line arguments but we do not extract or store the content of files read or written by your tools.
- Billing data: Payment method and transaction history are processed and stored by Stripe, our payment processor. We do not store full credit card numbers.
- Device data: A random device identifier stored in your browser's localStorage to distinguish trusted devices.
2. How We Use Information
We use the collected information to:
- Provide, maintain, and improve the Service
- Process payments and manage subscriptions
- Enforce usage limits and prevent abuse
- Send service-related notifications (e.g., usage warnings, billing reminders)
- Respond to support requests
We do not sell your data, use it for advertising, or train machine learning models on your tool call data.
3. Data Storage and Retention
Data is stored in SQLite databases on our servers. Check events are retained for 90 days by default. Account data is retained until you delete your account. Upon account deletion, your data is permanently removed within 30 days.
4. Data Sharing
We share data only as necessary:
- Stripe: For payment processing. Stripe's privacy policy applies to data they handle.
- Legal obligations: If required by law, court order, or government request.
5. Security
We use WebAuthn (passkeys) for authentication — no passwords are stored. API keys are SHA-256 hashed at rest. All traffic is encrypted in transit via TLS. However, no security measure is perfect; you use the Service at your own risk.
6. Your Rights
You may:
- Request a copy of your data by contacting us
- Delete your account and associated data through the console
- Export your check events and audit log in CSV or JSON format
- Opt out of non-essential communications
7. Cookies
We use a single HttpOnly session cookie for authentication. No tracking cookies, no third-party cookies, no analytics scripts. The console stores your display preferences (dark mode, compact view) in localStorage.
8. Children's Privacy
The Service is not intended for individuals under 16. We do not knowingly collect data from children.
9. Changes to This Policy
We will notify you of material changes via the Service dashboard. Continued use after changes constitutes acceptance.
10. Contact
Privacy questions or data requests? Open an issue on our support page or contact your account representative.