Effective [EFFECTIVE DATE PLACEHOLDER]
Privacy Policy
This Policy explains how [LEGAL ENTITY PLACEHOLDER] processes information through OutClean. Contact the controller at [CONTACT EMAIL PLACEHOLDER] or [LEGAL ADDRESS PLACEHOLDER].
This is a strong GDPR- and CCPA-oriented operational template, not certified legal advice. Qualified counsel must review it and complete the placeholders before launch.
1 / Data collected
- Domain and proof: submitted domain, one-way hashed ownership nonce, proof method, verification state, timestamps, and a one-way hash of the server-issued owner session.
- Scan records: target domain, bounded response-derived security signals, private finding detail, score, issue count, status, error code, and timestamps.
- Public listing: domain, effective score, color band, issue count, and successful scan date.
- Notification data: optional email address, subscription status, associated domain, and timestamps.
- Security data: one-way keyed hash of the requesting IP address for abuse prevention. We do not store the raw IP in application tables or logs.
- Basic request data: hosting infrastructure may process IP address, user agent, request path, and operational logs under its standard service configuration.
2 / Purpose and basis
- Verify control and perform the requested passive scan: performance of your request and legitimate interests in consent-only operation.
- Publish and maintain the scorecard: your explicit domain authorization, performance of the service, and legitimate interests in operating the scoreboard.
- Send score-change notices: consent, which you may withdraw at any time.
- Rate limiting, SSRF prevention, fraud investigation, and service security: legitimate interests and legal obligations.
- Respond to rights requests and disputes: legal obligations and legitimate interests.
Where consent is the basis, withdrawal does not affect earlier lawful processing.
3 / What is public
Only the verified domain, score, band, issue count, and scan date are public. Ownership nonces, owner session hashes, email addresses, IP hashes, and individual findings are private. Full vulnerability detail is never placed in public pages, badges, share text, or open-graph images.
4 / Processors
- Vercel, Inc. — application hosting, edge delivery, scheduled requests, and infrastructure logs.
- Supabase, Inc. — PostgreSQL database and managed data infrastructure.
- Resend, Inc. — delivery of owner-requested score-change notifications and associated delivery metadata.
- Scan provider: the OutClean scanner runs within the Vercel-hosted application; no external vulnerability-scanning provider receives target data.
Opening “Share on X” sends you to X Corp.; X receives data only when you choose that link and processes it under its own policy. Build Guard and Noumenon likewise receive data when you follow their links.
5 / Retention
- Pending ownership proofs: 30 days after creation; the proof itself expires after 24 hours.
- Verified domain listing and score history: while published, then 90 days after removal for disputes and integrity, unless law requires longer.
- Private completed scan detail: 12 months; aggregate score history: 24 months.
- Failed scan records and keyed IP hashes: 30 days.
- Email subscription: until unsubscribe or verified deletion request, then suppression evidence for up to 3 years where needed to honor opt-out.
- Security and legal records: only as long as reasonably necessary for the relevant claim or obligation.
Database backups may retain deleted data for a limited rolling period before secure overwrite.
6 / GDPR rights
Depending on location, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to your supervisory authority. Email [CONTACT EMAIL PLACEHOLDER]. We may verify identity or domain control before acting. We generally respond within one month, subject to lawful extensions.
If processing is based on legitimate interests, contact us for the balancing assessment. The service does not make legal or similarly significant decisions solely by automated means.
7 / US privacy rights
Residents of California and other covered US states may request to know, access, correct, delete, or obtain a portable copy of personal information and may appeal a denied request by contacting [CONTACT EMAIL PLACEHOLDER]. We do not sell personal information or share it for cross-context behavioral advertising, and we do not discriminate for exercising privacy rights. An authorized agent may submit a request with proof of authority.
Categories collected are identifiers, internet/network activity, and user-provided professional contact information. Sources are you, the verified domain’s public response, public DNS, and service infrastructure. Purposes and recipients are described above.
8 / Transfers
Processors may handle data outside your country. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, or another lawful mechanism. Contact us for relevant safeguard information.
9 / Security
Controls include row-level security on every application table, server-only privileged credentials, one-way nonce/session/IP hashing, strict target validation, DNS re-resolution before connections, private-network blocking, response caps, redirect and time limits, least-public data, structured non-PII logs, and rate limits by requester and domain. No system is perfectly secure.
10 / Cookies and signals
OutClean uses a strictly necessary HttpOnly owner-session cookie to associate your browser with proof and re-scan rights. It is not advertising or cross-site tracking. We do not respond to browser “Do Not Track” signals because we do not perform behavioral advertising. Where Global Privacy Control applies to sale or sharing, our default is already not to sell or share.
11 / Children
The service is not directed to children under 16, and we do not knowingly collect their personal information. Contact us for deletion if you believe a child submitted information.
12 / Changes and contact
We will post material updates here and change the effective date. If a change materially affects consent-based processing, we will seek new consent where required.
Privacy requests: [CONTACT EMAIL PLACEHOLDER]. Supervisory authority and statutory rights remain available regardless of this contact route.