What we collect
- Account details: name, email, password hash, two-factor settings.
- Target configuration: URLs, APK files, repository access, server credentials (encrypted at rest).
- Agent activity: plans, tool calls, observations, findings, evidence artifacts.
- Usage records: credits consumed, token counts, cost per call.
- Service logs: IP addresses, browser data, security telemetry.
How we use it
To provide the service you asked for: running agents against your targets, generating findings, streaming live sessions, and billing accurately. To keep the platform secure: fraud prevention, rate limiting, abuse detection. To comply with legal obligations.
We do not sell personal information. We do not use scan evidence or target data for advertising. We do not train models on your code or findings.
Where data lives
Scan artifacts (screenshots, HTTP exchanges, decompiled sources) are stored encrypted and purged on a 90-day retention cycle, or earlier if you delete the target. Account and billing records may be retained longer for security, accounting, and dispute resolution.
Who processes data
Infrastructure providers (cloud hosting, storage, databases), payment processors, and email delivery services handle data under contracts that restrict use to providing the service. We disclose information when required by law or to protect users and systems.
Your choices
Depending on your jurisdiction, you may request access, correction, deletion, or export of your personal information. Some records (billing, security logs) must be retained for legal reasons.
Contact us to start a privacy request.

