Privacy Policy
Last updated: 8/8/2026
1. Who we are
Horus Secure Analyst ("we", "us") operates a security scanning platform. This policy explains what personal data we collect, how we use it, and your rights under data-protection laws including the GDPR and CCPA.
2. Data we collect
- Account data: email address, hashed password, display name.
- Indemnity acceptance: full name, timestamp, IP, and user agent at the time of signing.
- Usage data: scans you run, target URLs, findings, support messages.
- Technical data: IP address, browser, device type, log data.
- Cookies: essential session cookies and optional analytics cookies (only if you accept).
3. How we use data
- To operate the Service, run scans, and deliver reports.
- To authenticate you and secure your account.
- To prevent abuse, enforce our Terms, and comply with legal obligations.
- To improve the product (aggregated, de-identified analytics).
- To send essential service emails (you may opt out of marketing at any time).
4. Legal basis (GDPR)
We process personal data on the basis of (a) performance of a contract (operating the Service); (b) legitimate interests (security, abuse prevention, improvement); (c) consent (optional cookies, marketing); and (d) legal obligation.
5. Sharing
We do not sell personal data. We share data only with: hosting and database providers (processors under contract), authentication providers, email-delivery providers, analytics providers (only if you accept), and law enforcement when legally required.
6. International transfers
Data may be processed in countries outside your own. Where required, we use Standard Contractual Clauses or equivalent safeguards.
7. Retention
We retain account data while your account is active and for a reasonable period afterwards to comply with legal obligations. Scan history is retained per your subscription tier. You can request deletion at any time.
8. Your rights
Depending on your jurisdiction, you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing. EU/UK users may lodge a complaint with their supervisory authority. To exercise rights, contact us via the support page.
9. Cookies
We use essential cookies required for sign-in and session management. We use optional analytics cookies only if you click "Accept" on the cookie banner. You can clear cookies from your browser at any time.
10. Security
We use TLS, encryption at rest, scoped database access (row-level security), and least- privilege controls. No system is 100% secure; you use the Service at your own risk.
11. Children
The Service is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us so we can delete it.
12. Changes
We may update this policy. Material changes will be communicated via the Service or by email. The "Last updated" date above reflects the latest revision.
13. Contact
For privacy questions or to exercise your rights, contact us via the support page in the app or the contact form on our website.