Przejdź do treści
P
boringsec/prawne/privacy policy

Privacy Policy

How we collect, use, store, and protect your data — and the rights you have over it.

obowiązuje od December 29, 202414 sekcjiRead Terms of Service
01

Introduction

prostym językiem

Orbitwise Ltd runs BoringSec. This page tells you what we do with your data — in plain English on the left, in the binding legal text below.

02

Information We Collect

prostym językiem

Three buckets: what you give us (account, payments, the URL you scan), what your browser tells us automatically (logs, cookies), and the public scan data we generate from those URLs.

03

How We Use Your Information

prostym językiem

We use your data to run the product, talk to you about your account, prevent abuse, and (only with your consent) send promotional emails. Nothing else.

04

How We Share Your Information

prostym językiem

We never sell your data. We share narrowly with infrastructure providers (hosting, payments, auth) — listed by name in the table below — and with law enforcement only when legally required.

05

Data Retention

prostym językiem

We keep data only as long as needed. Account data while your account exists; usage logs ≤ 12 months; payment records as long as tax law requires. Email us to delete sooner.

06

Cookies and Tracking Technologies

prostym językiem

Three cookie categories: essential (always on, required for the product), analytics (need your consent), preferences (remember your settings).

07

Data Security

prostym językiem

TLS in transit, encryption at rest, audit logs, secure auth. Standard practice — but no system is 100% breach-proof.

08

Your Privacy Rights (GDPR Articles 15–22)

prostym językiem

You can ask for a copy of your data, correct it, delete it, or take it elsewhere. We respond within 30 days. Email privacy@boringsec.com to start any request.

09

International Data Transfers

prostym językiem

Some of our infrastructure (Vercel, Stripe, Google/GitHub OAuth) runs partly in the US. We use Standard Contractual Clauses and minimize transferred data.

10

European Users (GDPR)

prostym językiem

If you are in the EEA, UK, or Switzerland, you get full GDPR rights — and you can complain to your local data protection authority if anything looks wrong.

11

California Residents (CCPA)

prostym językiem

California residents have the same right to know, delete, and not be discriminated against — and we don't sell personal info under CCPA either.

12

Children's Privacy

prostym językiem

Service is not for users under 18. If we ever discover we collected data from a child, we delete it.

13

Changes to This Privacy Policy

prostym językiem

We update this page when needed and bump the date. For material changes we email account holders.

14

Contact Us

prostym językiem

privacy@boringsec.com for privacy questions or DSARs. support@boringsec.com for everything else.