Last updated: 2026-10-03
Privacy Policy
What personal data we collect, why, who we share it with, how long we keep it and your rights.
1. Who is responsible
Fadi Kanaani, Al-hor, Kafr Qara, Israel, Israel is the controller of personal data processed through DevScan AI (https://devscanai.com). Contact us about privacy at [email protected].
For data that our customers put into the Service about other people (for example team members they invite, or personal data that appears on the websites they scan), we process it on the customer's behalf as a processor, under the customer's instructions.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account | Name, email address, password (stored only as a one-way hash), timezone, two-factor settings (secret stored encrypted) | You |
| Workspace & team | Workspace name, members, roles, invitations | You and your workspace owner |
| Websites & test settings | URLs of projects, scan settings, ownership verification records, API check definitions, user-flow steps; any credentials or headers you provide for tests (stored encrypted) | You |
| Scan results | Pages tested, issues found with evidence, performance metrics, screenshots and reports of the websites you test (these can contain personal data that is visible on those websites) | Generated by the Service |
| Integrations | GitHub account name, selected repository and an encrypted access token; webhook URLs; API keys (stored only as a hash) | You |
| Billing | Plan, subscription status, billing period, Paddle customer and subscription IDs, invoices. Card details are handled only by Paddle | You, Paddle |
| Security & usage logs | IP address, browser user agent, login times, failed logins and sensitive actions (audit log), session records | Your device |
| Support & communications | Messages you send us, enterprise inquiries, email delivery status | You, our email provider |
| Free instant scans (no account) | The website address you enter, a summary of the results and a one-way hash of your IP address (used only for rate limiting) | You |
| Ask DevScan assistant | The questions you type and, when you ask about a scan or issue, that scan's redacted results. Chat history is not stored by us after the answer is returned | You |
| Product analytics | Coarse events such as "scan started" with internal IDs and plan — never scanned content, page URLs, findings, emails or credentials | The Service |
We do not sell personal data, do not use it for advertising and do not knowingly collect special-category data.
3. Why we use it (and legal bases)
- To provide the Service you signed up for — running scans, monitoring, reports, AI prompts, alerts, team features and integrations (performance of a contract).
- To keep accounts and the platform secure — login protection, rate limiting, fraud and abuse prevention, audit logs, preventing unauthorized scanning (legitimate interests; legal obligations).
- To bill you and meet tax and accounting duties, through Paddle (contract; legal obligation).
- To send service emails — verification, password resets, security notices, alerts and billing messages (contract; legitimate interests). You can turn alert emails off in Settings; essential security and account emails cannot be turned off.
- To send a weekly summary of your own websites' results (legitimate interests). Every weekly email has a one-click unsubscribe link, and you can turn it off in Settings → Notifications.
- To improve the Service using aggregated, privacy-conscious analytics (legitimate interests).
- Marketing emails only with your consent, which you can withdraw at any time via the unsubscribe link.
4. Who we share data with
We share personal data only with service providers that help us run the Service, under contracts that limit them to processing it for us. The current list (Paddle, our email provider, hosting providers and, where enabled, AI, error-tracking and analytics providers) is on our Subprocessors page.
AI providers receive only a compact, redacted summary of scan findings when AI features are used — passwords, tokens, cookies and API keys are removed first — and not your account details. When you use the Ask DevScan assistant with AI answers enabled, your question is sent to the AI provider together with that redacted context. Under its commercial terms our AI provider does not use this data to train its models.
We may also disclose data if required by law or to protect rights, safety and security, and to a successor if our business is sold or merged (you will be informed).
5. International transfers
Our servers are located in Germany (European Union). Some providers may process data in other countries, including the United States. Where data leaves the EEA/UK we use appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.
6. How long we keep data
| Data | Retention |
|---|---|
| Detailed scan results, evidence, screenshots and reports | According to your plan's history period: Free 7 days, Starter 90 days, Pro 1 year, Team 2 years, Enterprise 3 years. A lightweight score history (dates and scores) is kept while the project exists |
| Projects and account data | Until you delete them or your account |
| Login sessions | Until they expire or you sign out, then deleted within 30 days |
| Email verification and password-reset tokens | Deleted 30 days after they expire |
| Security / audit logs (IP address, user agent, actions) | 12 months |
| Uptime monitoring checks | 90 days |
| Free instant scan results (no account) | 7 days |
| Billing and invoice records | As long as required by tax and accounting law (typically up to 7–10 years), kept by Paddle and us |
| Backups | Kept by our database provider for disaster recovery for at most 30 days, then overwritten |
When you delete your account, we delete your personal workspace, its projects and stored files immediately and remove remaining personal data from active systems, except what we must keep by law (for example billing records) or for security (a record that the account was deleted).
7. How we protect data
Encryption in transit (HTTPS) and of sensitive fields at rest, password hashing (Argon2id), optional two-factor login (required for administrators), strict access control between workspaces, rate limits, network isolation of scanning infrastructure and regular dependency audits. No system is perfectly secure; if a breach affects you we will inform you and the authorities as required by law.
8. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or US state laws such as the CCPA/CPRA), you may have the right to access, correct, export (portability), delete or restrict the processing of your data, to object to processing based on legitimate interests, and to withdraw consent at any time.
Many of these you can do yourself: edit your profile and export your data or delete your account in Settings. For anything else, email [email protected]. We answer within one month and may need to verify your identity. You also have the right to complain to your local data protection authority.
We do not sell or "share" personal information for cross-context behavioural advertising, and we do not make decisions with legal or similarly significant effects about you based solely on automated processing.
9. Cookies
We use only essential cookies and a little local storage for preferences. Details are in our Cookie Policy.
10. Children
The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect children's data; contact us if you believe we have.
11. Changes
We will post changes on this page and update the date above. For significant changes we will also notify you by email or in the Service.
12. Contact
Fadi Kanaani — Al-hor, Kafr Qara, Israel, Israel — [email protected]