Privacy Policy
Last updated: 2026-07-20
At Scanaris we take your privacy seriously (we are a security scanner, after all). This policy explains what data we process and why.
1. Who we are
Scanaris ("we") is a service that scans websites and returns a security report. Data controller: [legal entity], [address]. Contact: privacy@scanaris.com.
2. What data we process
Account: your email (and the sign-in provider if you use Google). Usage: the URLs you scan, scan results, and your onboarding answers (profile, interests, how you found us).
We do not ask for more personal data than is needed to provide the service.
3. How we use it
To run scans and show you reports, manage your account, improve the product and, if you subscribe to a plan, handle billing. Legal basis (GDPR): performance of the contract and our legitimate interest in improving the service.
4. Providers we use
Supabase (database, authentication and storage). Anthropic (AI generation of "fix prompts" from the finding context). Stripe/Paddle (payment processing, once you activate a plan). These providers process data on our behalf under their own data-protection agreements.
5. Cookies
We use strictly necessary cookies only: the session cookie (to keep you signed in) and the language cookie (to remember your preference). We do not use advertising cookies.
6. Scanning websites
When you scan a site, we perform READ-ONLY checks against already-public information (headers, cookies, certificates, accessible files). We never modify, delete or inject anything. You must only scan sites you own or are authorized to test (see Terms).
7. Retention and your rights
We keep your data while your account is active and as long as the law requires. You can access, rectify or delete your data, and exercise your other GDPR rights, by writing to privacy@scanaris.com.