Skip to content
P
boringsec/legal/privacy policy

Privacy Policy

How we collect, use, store, and protect your data — and the rights you have over it.

effective December 29, 202414 sectionsRead Terms of Service
01

Introduction

in plain english

Orbitwise Ltd runs BoringSec. This page tells you what we do with your data — in plain English on the left, in the binding legal text below.

02

Information We Collect

in plain english

Three buckets: what you give us (account, payments, the URL you scan), what your browser tells us automatically (logs, cookies), and the public scan data we generate from those URLs.

03

How We Use Your Information

in plain english

We use your data to run the product, talk to you about your account, prevent abuse, and (only with your consent) send promotional emails. Nothing else.

04

How We Share Your Information

in plain english

We never sell your data. We share narrowly with infrastructure providers (hosting, payments, auth) — listed by name in the table below — and with law enforcement only when legally required.

05

Data Retention

in plain english

We keep data only as long as needed. Account data while your account exists; usage logs ≤ 12 months; payment records as long as tax law requires. Email us to delete sooner.

06

Cookies and Tracking Technologies

in plain english

Three cookie categories: essential (always on, required for the product), analytics (need your consent), preferences (remember your settings).

07

Data Security

in plain english

TLS in transit, encryption at rest, audit logs, secure auth. Standard practice — but no system is 100% breach-proof.

08

Your Privacy Rights (GDPR Articles 15–22)

in plain english

You can ask for a copy of your data, correct it, delete it, or take it elsewhere. We respond within 30 days. Email privacy@boringsec.com to start any request.

09

International Data Transfers

in plain english

Some of our infrastructure (Vercel, Stripe, Google/GitHub OAuth) runs partly in the US. We use Standard Contractual Clauses and minimize transferred data.

10

European Users (GDPR)

in plain english

If you are in the EEA, UK, or Switzerland, you get full GDPR rights — and you can complain to your local data protection authority if anything looks wrong.

11

California Residents (CCPA)

in plain english

California residents have the same right to know, delete, and not be discriminated against — and we don't sell personal info under CCPA either.

12

Children's Privacy

in plain english

Service is not for users under 18. If we ever discover we collected data from a child, we delete it.

13

Changes to This Privacy Policy

in plain english

We update this page when needed and bump the date. For material changes we email account holders.

14

Contact Us

in plain english

privacy@boringsec.com for privacy questions or DSARs. support@boringsec.com for everything else.