Skip to main content
← Back to home

Privacy Policy

Last updated: March 14, 2026

1. Data We Collect

We collect the minimum data necessary to provide the Service:

  • Account users: Email address (for authentication and notifications).
  • Guest users: A SHA-256 hash of your IP address (used only for rate limiting; we do not store raw IP addresses for guests).
  • All users: Target URLs submitted for scanning, scan results, and scan metadata (timestamps, scan type, status).

2. How We Use Your Data

  • To authenticate your account and send login codes.
  • To perform scans on the URLs you submit and generate reports.
  • To send you scan completion notifications (account users only).
  • To enforce rate limits and prevent abuse.
  • To improve the Service (aggregated, anonymized usage patterns only).

3. Cookies

We use a single session cookie (appvet_session) to maintain your authenticated session. This cookie is HTTP-only, secure, and same-site. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

4. Third-Party Services

We use the following third-party services to operate AppVet:

  • Cloudflare: Hosting infrastructure (Workers, D1 database, R2 storage, Containers). Data is processed and stored on Cloudflare's global network.
  • Resend: Transactional email delivery (login codes, scan notifications). We share your email address with Resend solely for email delivery.

We do not sell, rent, or share your data with any other third parties.

5. Data Retention

  • Scan results: Retained for 30 days, then automatically deleted.
  • Account data: Retained for as long as your account is active.
  • Guest data: IP hashes and guest scan records are retained for 30 days.
  • Auth codes: Expire after 10 minutes and are marked as used.

6. Your Rights

Depending on your jurisdiction, you may have rights under GDPR, CCPA, or similar data protection regulations, including:

  • The right to access the personal data we hold about you.
  • The right to request deletion of your personal data.
  • The right to request correction of inaccurate data.
  • The right to data portability.
  • The right to withdraw consent for data processing.

To exercise any of these rights, contact us at support@appvet.dev. We will respond within 30 days.

7. Security

We implement appropriate technical measures to protect your data, including encryption in transit (TLS), encrypted storage, secure session management, and access controls. However, no system is 100% secure, and we cannot guarantee absolute security.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by the "Last updated" date at the top. Continued use of the Service after changes constitutes acceptance.

9. Contact

Questions about this Privacy Policy? Contact us at support@appvet.dev.