Privacy Policy
What we collect
We collect only what is needed to run the scanner, accounts, and payments:
- Email address - newsletter signup, account login (Google/GitHub OAuth), or when you attach an email to a scan. Stored in Cloudflare D1.
- Account profile from social login - when you sign in with Google or GitHub we receive your email, display name, avatar URL, and provider user id (OAuth). We do not post on your behalf or access private repos.
- URL / hostname you submit for scanning - stored with the scan result so you can reopen history and share links. Results are private by default; a public
/r/:idpermalink is created only if you explicitly publish a scan you own. - Scan findings - score, grade, and check details (JSON) kept so the dashboard and share pages work.
- Session cookie-
cyber_sess(HttpOnly, Secure on HTTPS, SameSite=Lax) identifies your logged-in session. Lifetime ~30 days. - Hashed network metadata - we store a salted hash of your IP and a hash of the user-agent for abuse prevention and session binding. We do not store raw IP addresses in scan rows.
- Support chat messages - if you use the on-site assistant, message text is stored in D1 for quality review and abuse control.
- Payment records - order id, amount, tier, and status from Stripe webhooks. Card numbers never touch our servers (Stripe only).
- Cloudflare Web Analytics - privacy-oriented page metrics at the edge.
What we do not collect
- Third-party advertising pixels or advertising identifiers
- Card numbers, CVV, or full payment credentials (Stripe handles checkout)
- Passwords for Google/GitHub (OAuth only)
- Exploit payloads or authenticated access to your systems - scans are passive HTTP/TLS checks
Cookies
We set a first-party session cookie when you sign in. We do not use third-party ad cookies. You can clear cookies in your browser; that signs you out. Full detail: Cookie Policy.
Legal basis (GDPR Art. 6)
- Consent (Art. 6(1)(a)) - newsletter subscription (double opt-in where used).
- Contract (Art. 6(1)(b)) - delivering scans, dashboard, paid plans, and ordered reviews.
- Legitimate interest (Art. 6(1)(f)) - abuse prevention (rate limits, hashed IP), security of the service, and product analytics.
How long we keep your data
- Scan findings (score, grade, check details) - retained 90 days from the scan date, then automatically deleted. Reopening a report before 90 days does not reset the clock.
- Account profile + scan history index (which URLs you scanned, when): until you delete the account or request erasure.
- Newsletter email: until you unsubscribe or request deletion.
- Order/payment records: up to 7 years where Slovak/EU accounting and tax law requires it, independent of account deletion.
- Chat logs: retained for support quality; request deletion anytime.
Your rights under GDPR
You may access, correct, delete, restrict, port, or object to processing of your data, and withdraw consent where consent is the basis. Email hello@koscak.ai with subject "GDPR request". We respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority (in Slovakia: the Office for Personal Data Protection of the Slovak Republic, dataprotection.gov.sk).
International data transfers
Our processors may transfer or process data outside the EU/EEA (for example Cloudflare and Stripe operate global infrastructure, including in the United States). Where this occurs, transfers are made under the EU Standard Contractual Clauses, an adequacy decision, or another valid transfer mechanism recognized under GDPR Chapter V, as implemented by each processor.
Third-party processors
- Cloudflare - hosting, CDN, Pages Functions, D1, analytics.
- Stripe - payment processing and subscription billing, acting as an independent data processor/controller for payment data per its own privacy policy and Data Processing Agreement. We never see or store full card numbers.
- Google / GitHub - optional OAuth identity providers.
- Mailchannels (or equivalent) - transactional email where enabled.
- AI inference provider (z.ai / GLM) - optional support-chat replies. Message content is sent only to generate an answer; we scrub vendor names from output. Do not paste secrets into chat.
Data Protection Officer / privacy contact
[DPO PLACEHOLDER - name/role and contact if a Data Protection Officer is appointed; if not legally required at your scale, this section can state "no DPO is currently appointed; privacy inquiries go to the contact below."]
Data deletion
Email hello@koscak.ai with subject "delete". We process within 72 hours and confirm by reply (order records required by law may be retained in minimized form).
Unsubscribe
Every marketing email includes a one-click unsubscribe link (/api/unsubscribe?token=…). No confirmation maze.
Contact
Data controller: koscak.ai
Contact: hello@koscak.ai