Introduction
Orbitwise OÜ runs BoringSec. This page tells you what we do with your data — in plain English on the left, in the binding legal text below.
Orbitwise OÜ("Company", "we", "us", or "our") operates the BoringSecplatform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We are committed to protecting your privacy and handling your data transparently and responsibly. By accessing or using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
If you do not agree, please do not access or use the Service.
Information We Collect
Three buckets: what you give us (account, payments, the URL you scan), what your browser tells us automatically (logs, cookies), and the public scan data we generate from those URLs.
2.1 Information You Provide
We collect information you voluntarily provide when using our Service:
- Account Information: Name, email, and authentication data (email or third-party providers like Google or GitHub).
- Profile Information: Optional profile details you choose to provide.
- Payment Information: Billing address and payment method details (processed securely by Stripe).
- Scan Data: Domain names and URLs you submit for security scanning.
- Connected Scan Data: Repository identifiers, selected source evidence, archive manifests, and an expiring authenticated-scan profile when you explicitly configure those features.
- Communications: Messages you send for support or feedback.
2.2 Information Collected Automatically
When you access our Service, we automatically collect:
- Device Information: Browser type, operating system, device identifiers.
- Usage Data: Pages visited, features used, time spent on the Service.
- Log Data: IP address, access times, referring URLs, error logs.
- Cookies and Similar Technologies: See Section 6.
2.3 Anonymous Purchase Data
When you purchase a single report without registering, we create a minimal account record with your email so we can deliver the report and validate access. You can request deletion at any time via support@boringsec.com.
Data we store for anonymous purchases:
- Email address (for delivery)
- Stripe customer/payment IDs (for refund processing)
- Purchase metadata (which report, package type, timestamp)
We do not store payment card details — those are handled exclusively by Stripe.
2.4 Scan Result Data
When you perform security scans, we collect and store the scan results, which may include HTTP headers, SSL/TLS certificate details, DNS records, and other publicly available technical information about the scanned domains. This data is necessary to provide the Service and generate security reports.
2.5 Public Business Contact and Security Outreach Data
For narrowly targeted business security outreach, we may process a public business or security contact address, the official source URL where it was published, the assessed domain, a recipient-safe summary of fresh public scan evidence, and delivery, suppression, reply, and conversion metadata. We do not purchase contacts or use guessed personal addresses for the autonomous path. The eligibility, cadence, audit, and opt-out controls are described in our Security Outreach Policy.
How We Use Your Information
We use data to run the product, communicate about the service, prevent abuse, and conduct narrowly scoped marketing or business security outreach under the applicable consent or legitimate-interest rules.
We use the information we collect for the following purposes:
- Provide the Service: Process scans, generate reports, deliver security analysis.
- Account Management: Create and manage your account, authenticate users, process payments.
- Communication: Send service notifications, security alerts, respond to inquiries.
- Improvement: Analyze usage patterns to improve the Service.
- Security: Detect, prevent, and address technical issues, fraud, and abuse.
- Legal Compliance: Comply with applicable laws, regulations, and legal processes.
- Marketing and Business Security Outreach: Send promotional communications with consent where required, or narrowly targeted business security notices under legitimate interests where permitted. Automated outreach remains subject to the published evidence, recipient, jurisdiction, cadence, suppression, and audit controls.
Data Retention
Each data class has an explicit window or retention rule. The matrix distinguishes report history, credentials, source connections, analytics, audit logs, support, and billing instead of hiding them behind “as long as necessary.”
The normal production retention rules are:
| Data class | Default window | Deletion or minimization | Exceptions |
|---|---|---|---|
| Anonymous URL scan report and request network metadata | Public report access expires after 30 days. | Request metadata is minimized when public access expires, and the anonymous scan is deleted shortly afterward under the retention schedule. | A scan retained for an active Care relationship or a required outreach/disclosure audit trail is protected from that automatic deletion path. |
| Signed-in domains, scans, findings, monitoring history, and paid reports | Retained while needed to provide the account, purchase, report history, or monitoring relationship. No shorter fixed automatic window is promised. | The owner can delete a domain/account or request erasure. Related product data is deleted or anonymized unless a legal or security obligation requires limited retention. | Billing, fraud, incident, and legally required records may be retained separately for the applicable obligation. |
| Optional authenticated-scan credentials | The owner selects 7, 30, or 90 days. The profile expires automatically. | Credentials remain encrypted and server-side, are used only for the authorized scan, and can be revoked or deleted earlier. | Reports store scan status and minimized evidence, not credential values. |
| Connected repository content and repository access credentials | Source is fetched for the authorized scan. Findings and scan metadata remain with the report history. | Repository credentials stay server-side and can be revoked. Full source content is not intentionally copied into public reports. Evidence is minimized and secrets are masked. | Provider-side logs and repository retention remain governed by the connected provider and customer repository. |
| Repository archive and redacted static-analysis findings | The raw archive is deleted after processing. The minimized manifest and findings expire after 30 days. | The owner can delete the scan sooner. Raw source is kept private during processing and is never returned through public report surfaces. Secret-bearing evidence is redacted before result storage. | Minimal audit metadata may be retained for abuse prevention and does not contain source content. |
| Raw product analytics sessions | 90 days. | Raw analytics sessions older than the window are deleted automatically. | Aggregated, non-identifying operational metrics may remain after raw sessions are removed. |
| Audit-log IP addresses and user agents | Direct network and routine client detail are minimized after 90 days. | Network identifiers are reduced and routine client details are removed when they are no longer needed. | Security-relevant audit events may retain limited user-agent context for abuse, access, and incident review. |
| Closed support and inbound-reply conversations | 24 months after the last message. | Closed conversations older than the window are deleted automatically. | Open conversations and records under a legal/security hold are not part of the normal closed-conversation cleanup. |
| Billing and transaction records | For the tax, accounting, dispute, and fraud-prevention period required by applicable law and payment operations. | BoringSec stores provider identifiers and purchase state, not full payment-card data. | Stripe independently processes payment data under its own retention and legal obligations. |
You may request deletion of your data by contacting us. We will delete or anonymize your data within a reasonable timeframe, except where retention is required by law.
Data Security
Public control statements describe the implemented server, release, scan, billing, and retention safeguards and their operational scope.
Our current public control statements include:
- Server-side authorization and ownership boundaries: Server-managed sessions, role checks, ownership checks, and focused authorization tests are used on protected access and mutation paths. This control covers the protected paths listed in its scope and is maintained through focused authorization tests.
- Server-side secret protection: Sensitive values remain server-side, and release checks help prevent accidental exposure in public application assets. The public packet protects secret names, values, internal paths, and deployment credentials.
- Authorized and bounded scanning: Public scans are limited to the submitted public surface. Deeper or source-based checks require verified ownership or an explicit connection. Coverage is target-dependent. An unavailable or incomplete scanner is reported as such and is not converted into a clean result.
- Protected billing state: Pricing and billing status are validated server-side. Payment-card details are processed by the payment provider. Stripe independently processes payment details; BoringSec validates trusted pricing and billing state server-side.
- Data minimization and retention: The Privacy Policy explains data categories, retention windows, and deletion rights. Narrow billing, fraud, incident, legal, or security obligations can require limited retention beyond the normal product path.
- Privacy-safe service status: The public status view reports the current privacy-safe application health signal. The snapshot covers application health at the time of the request; scanner applicability remains target-dependent.
The dated control summary and its evidence boundaries are published in the BoringSec Trust Center.
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
Your Privacy Rights (GDPR Articles 15–22)
You can ask for a copy of your data, correct it, delete it, or take it elsewhere. We respond within 30 days. Email privacy@boringsec.com to start any request.
Under GDPR and similar privacy laws, you have the following rights regarding your personal data:
Request a copy of all personal data we hold — scan results, account info, usage data.
Request →Correct inaccurate or incomplete personal data we have on file.
Request →"Right to be Forgotten" — deletion of your account and data within 30 days, except where law requires retention.
Request →Receive your data in a machine-readable format (JSON / CSV) for transfer to another service.
Request →Object to processing based on legitimate interests. Opt out of marketing emails any time.
Request →Withdraw consent for optional processing (marketing cookies). Doesn't affect prior processing.
Request →We respond within 30 days as required by GDPR. For complex requests, we may extend up to 60 additional days, and will inform you within the initial 30-day period.
For all requests, contact us at privacy@boringsec.com. We may verify your identity before processing your request.
International Data Transfers
Some providers operate across countries. The exact processing context depends on the core service or optional feature you use, and the provider inventory links to current privacy references.
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
9.1 Provider processing locations
Some service providers may process data in more than one country. The processing path depends on the feature you use:
- Google measurement:If you consent to marketing cookies, conversion tracking follows Google's current service and privacy terms.
- Stripe:Payment processing follows Stripe's current service and privacy terms.
- Optional Authentication and Repository Features: Google and GitHub may process data on global infrastructure when you choose those features.
- Optional External AI: External model processing occurs only when a supported AI feature is explicitly requested and available. Any external provider and the applicable data boundary are disclosed before use.
9.2 Safeguard boundary
The applicable contractual and transfer safeguards depend on the selected provider, feature, data, and customer context. Our privacy team reviews those details for the stated context through the request path below.
- Consent: For optional services like marketing cookies, we obtain your explicit consent first.
- Data Minimization: We only transfer data necessary for the specific service.
- Provider Review: Provider purpose, activation, data boundary, and current public privacy reference are listed in the Trust Center.
9.3 DPA and privacy review request
Privacy and DPA review requests are handled case by case through the privacy contact below.
Send the request to privacy@boringsec.comwith the subject "DPA and privacy review request" and include:
- Your legal entity and business contact.
- The BoringSec feature and intended use.
- Expected data categories and data-subject groups.
- Relevant jurisdictions and requested review deadline.
We will confirm the materials, processing details, and expected review timing available for the stated context.
European Users (GDPR)
If you are in the EEA, UK, or Switzerland, you get full GDPR rights — and you can complain to your local data protection authority if anything looks wrong.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply.
Legal Basis for Processing: We process your personal data based on:
- Contract: Processing necessary for performance of our contract with you (providing the Service).
- Legitimate Interests: Improving the Service, preventing fraud.
- Consent: Marketing communications and optional cookies.
- Legal Obligation: Compliance with legal requirements.
You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
California Residents (CCPA)
California residents have the same right to know, delete, and not be discriminated against — and we don't sell personal info under CCPA either.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Disclosure of categories and specific pieces of personal information we have collected.
- Right to Delete: Request deletion of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights.
We do not sell personal information as defined under the CCPA.
Children's Privacy
Service is not for users under 18. If we ever discover we collected data from a child, we delete it.
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us at privacy@boringsec.com. If we learn that we have collected personal information from a child, we will take steps to delete that information.
Changes to This Privacy Policy
We update this page when needed and bump the date. For material changes we email account holders.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification. Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
Contact Us
privacy@boringsec.com for privacy questions or DSARs. support@boringsec.com for everything else.
If you have any questions about this Privacy Policy or our data practices, please contact us: