Skip to content

Last updated: 2026-10-03

Privacy Policy

What personal data we collect, why, who we share it with, how long we keep it and your rights.

1. Who is responsible

Fadi Kanaani, Al-hor, Kafr Qara, Israel, Israel is the controller of personal data processed through DevScan AI (https://devscanai.com). Contact us about privacy at [email protected].

For data that our customers put into the Service about other people (for example team members they invite, or personal data that appears on the websites they scan), we process it on the customer's behalf as a processor, under the customer's instructions.

2. Data we collect

CategoryExamplesSource
AccountName, email address, password (stored only as a one-way hash), timezone, two-factor settings (secret stored encrypted)You
Workspace & teamWorkspace name, members, roles, invitationsYou and your workspace owner
Websites & test settingsURLs of projects, scan settings, ownership verification records, API check definitions, user-flow steps; any credentials or headers you provide for tests (stored encrypted)You
Scan resultsPages tested, issues found with evidence, performance metrics, screenshots and reports of the websites you test (these can contain personal data that is visible on those websites)Generated by the Service
IntegrationsGitHub account name, selected repository and an encrypted access token; webhook URLs; API keys (stored only as a hash)You
BillingPlan, subscription status, billing period, Paddle customer and subscription IDs, invoices. Card details are handled only by PaddleYou, Paddle
Security & usage logsIP address, browser user agent, login times, failed logins and sensitive actions (audit log), session recordsYour device
Support & communicationsMessages you send us, enterprise inquiries, email delivery statusYou, our email provider
Free instant scans (no account)The website address you enter, a summary of the results and a one-way hash of your IP address (used only for rate limiting)You
Ask DevScan assistantThe questions you type and, when you ask about a scan or issue, that scan's redacted results. Chat history is not stored by us after the answer is returnedYou
Product analyticsCoarse events such as "scan started" with internal IDs and plan — never scanned content, page URLs, findings, emails or credentialsThe Service

We do not sell personal data, do not use it for advertising and do not knowingly collect special-category data.

3. Why we use it (and legal bases)

  • To provide the Service you signed up for — running scans, monitoring, reports, AI prompts, alerts, team features and integrations (performance of a contract).
  • To keep accounts and the platform secure — login protection, rate limiting, fraud and abuse prevention, audit logs, preventing unauthorized scanning (legitimate interests; legal obligations).
  • To bill you and meet tax and accounting duties, through Paddle (contract; legal obligation).
  • To send service emails — verification, password resets, security notices, alerts and billing messages (contract; legitimate interests). You can turn alert emails off in Settings; essential security and account emails cannot be turned off.
  • To send a weekly summary of your own websites' results (legitimate interests). Every weekly email has a one-click unsubscribe link, and you can turn it off in Settings → Notifications.
  • To improve the Service using aggregated, privacy-conscious analytics (legitimate interests).
  • Marketing emails only with your consent, which you can withdraw at any time via the unsubscribe link.

4. Who we share data with

We share personal data only with service providers that help us run the Service, under contracts that limit them to processing it for us. The current list (Paddle, our email provider, hosting providers and, where enabled, AI, error-tracking and analytics providers) is on our Subprocessors page.

AI providers receive only a compact, redacted summary of scan findings when AI features are used — passwords, tokens, cookies and API keys are removed first — and not your account details. When you use the Ask DevScan assistant with AI answers enabled, your question is sent to the AI provider together with that redacted context. Under its commercial terms our AI provider does not use this data to train its models.

We may also disclose data if required by law or to protect rights, safety and security, and to a successor if our business is sold or merged (you will be informed).

5. International transfers

Our servers are located in Germany (European Union). Some providers may process data in other countries, including the United States. Where data leaves the EEA/UK we use appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions.

6. How long we keep data

DataRetention
Detailed scan results, evidence, screenshots and reportsAccording to your plan's history period: Free 7 days, Starter 90 days, Pro 1 year, Team 2 years, Enterprise 3 years. A lightweight score history (dates and scores) is kept while the project exists
Projects and account dataUntil you delete them or your account
Login sessionsUntil they expire or you sign out, then deleted within 30 days
Email verification and password-reset tokensDeleted 30 days after they expire
Security / audit logs (IP address, user agent, actions)12 months
Uptime monitoring checks90 days
Free instant scan results (no account)7 days
Billing and invoice recordsAs long as required by tax and accounting law (typically up to 7–10 years), kept by Paddle and us
BackupsKept by our database provider for disaster recovery for at most 30 days, then overwritten

When you delete your account, we delete your personal workspace, its projects and stored files immediately and remove remaining personal data from active systems, except what we must keep by law (for example billing records) or for security (a record that the account was deleted).

7. How we protect data

Encryption in transit (HTTPS) and of sensitive fields at rest, password hashing (Argon2id), optional two-factor login (required for administrators), strict access control between workspaces, rate limits, network isolation of scanning infrastructure and regular dependency audits. No system is perfectly secure; if a breach affects you we will inform you and the authorities as required by law.

8. Your rights

Depending on where you live (for example under the GDPR, UK GDPR or US state laws such as the CCPA/CPRA), you may have the right to access, correct, export (portability), delete or restrict the processing of your data, to object to processing based on legitimate interests, and to withdraw consent at any time.

Many of these you can do yourself: edit your profile and export your data or delete your account in Settings. For anything else, email [email protected]. We answer within one month and may need to verify your identity. You also have the right to complain to your local data protection authority.

We do not sell or "share" personal information for cross-context behavioural advertising, and we do not make decisions with legal or similarly significant effects about you based solely on automated processing.

9. Cookies

We use only essential cookies and a little local storage for preferences. Details are in our Cookie Policy.

10. Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect children's data; contact us if you believe we have.

11. Changes

We will post changes on this page and update the date above. For significant changes we will also notify you by email or in the Service.

12. Contact

Fadi Kanaani — Al-hor, Kafr Qara, Israel, Israel — [email protected]