Privacy

Your report is designed to disappear.

Web SafeScore minimizes scan data by default. Finished reports are delivered once to the active browser and are not stored in the project database.

Last updated September 6, 2026

Scan data

The submitted URL, scan progress, and findings are held temporarily in Upstash Redis so the scan can run and the active browser can receive progress. Request state expires in about 15 minutes. A completed report expires in about 5 minutes if it is not retrieved; report, progress, and request keys are deleted together when it is retrieved.

The durable Workflow receives only a random scan ID. It may retain operational execution metadata according to the infrastructure provider’s service behavior, but the workflow input and completion marker do not contain the target URL, report, or findings.

One-time reports

The report is kept only in the page’s in-memory state after delivery. Web SafeScore does not use localStorage or a public report database. Refreshing, closing, or leaving the report page discards the browser copy, and report links are not shareable.

Abuse prevention

We transform network identifiers into shortened cryptographic hashes before using them for temporary distributed rate limits. We do not need to keep response bodies or findings for abuse prevention.

Help requests

If you voluntarily submit the “Get help fixing this” form, we store the name, email, optional company and message, website address, consent, timestamp, and optional opaque scan reference in Neon. The scan report and findings are not copied into that record.

Contact information is used to respond to the inquiry and retained only as reasonably needed for that purpose and related business records.

Service providers

  • Vercel hosts the application, Workflow runtime, AI Gateway connection, and basic production analytics.
  • Upstash provides short-lived scan state and rate limiting.
  • Neon stores voluntarily submitted help requests.
  • An AI model may rewrite a bounded, sanitized subset of already-determined findings for clarity; input size, output tokens, retries, and duration are capped. It cannot alter scores or create new findings, and deterministic copy is used if AI is off, paused, malformed, or unavailable.

Choices

You can use the informational pages without starting a scan. You can view a scan without submitting a help request. Browser and network controls may also limit basic analytics.