Authorized testing platform
PrivacyPublic record / V1.0

Privacy policy

We collect the minimum information needed to run a security testing platform, and we do not sell it, share it for advertising, or use your scan data to train models.

Effective
31 August 2026
Owner
Elenxo
01

What we collect

  • Account details: name, email, password hash, two-factor settings.
  • Target configuration: URLs, APK files, repository access, server credentials (encrypted at rest).
  • Agent activity: plans, tool calls, observations, findings, evidence artifacts.
  • Usage records: credits consumed, token counts, cost per call.
  • Service logs: IP addresses, browser data, security telemetry.
02

How we use it

To provide the service you asked for: running agents against your targets, generating findings, streaming live sessions, and billing accurately. To keep the platform secure: fraud prevention, rate limiting, abuse detection. To comply with legal obligations.

We do not sell personal information. We do not use scan evidence or target data for advertising. We do not train models on your code or findings.

03

Where data lives

Scan artifacts (screenshots, HTTP exchanges, decompiled sources) are stored encrypted and purged on a 90-day retention cycle, or earlier if you delete the target. Account and billing records may be retained longer for security, accounting, and dispute resolution.

04

Who processes data

Infrastructure providers (cloud hosting, storage, databases), payment processors, and email delivery services handle data under contracts that restrict use to providing the service. We disclose information when required by law or to protect users and systems.

05

Your choices

Depending on your jurisdiction, you may request access, correction, deletion, or export of your personal information. Some records (billing, security logs) must be retained for legal reasons.

Contact us to start a privacy request.