Legal
Privacy policy (Datenschutzerklärung)
Privacy policy (Datenschutzerklärung)
Last updated: 5 August 2026. This policy describes the production implementation currently contained in this repository. It must be checked again whenever a hosting provider, database, email provider, analytics feature, or scanner data flow changes.
1. Controller
Tribus Solutions UG (haftungsbeschränkt) Donaustraße 44, 12043 Berlin Germany
Email: hello@howsafeismyapp.com
No data protection officer has been appointed. The controller currently assumes that the appointment requirements in Article 37 GDPR and section 38 BDSG are not met. This assessment must be revisited if the organisation or its processing activities change.
2. What this policy covers
This policy covers howsafeismyapp.com, the passive scan, saved and shared reports, the optional email report, the paid full report, payment processing, and anonymous server-side usage statistics. It does not govern the website you ask us to scan or the independent processing carried out by Stripe.
3. Website delivery and security logs
The production application and private report renderer are intended to run on Google Cloud Run, operated by Google Cloud EMEA Limited and affiliated Google companies, in region europe-west4 (Netherlands). Google and its infrastructure providers necessarily process connection data such as IP address, requested URL, timestamp, user agent, referrer, and technical error/security information to deliver and protect the service.
Purpose: website delivery, availability, troubleshooting, abuse prevention, and information security. Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the service.
Provider security logs are retained according to the configured Google Cloud plan and settings. We aim to keep application-access logs no longer than 30 days, unless a security incident requires longer retention.
Google's Cloud Data Processing Addendum applies to customer personal data and describes subprocessors, processing locations, and international-transfer safeguards. Current provider information is available at: https://cloud.google.com/terms/data-processing-addendum, https://cloud.google.com/terms/subprocessors, and https://cloud.google.com/run/docs/locations.
4. Anonymous usage statistics
4.1 Server-side request log
For ordinary page requests our application records the requested path and, if provided by the browser, the referrer. Campaign links may instead record the allowlisted utm_source, utm_medium, and utm_campaign labels after length limiting and character filtering. We deliberately do not store the IP address or user agent in this analytics table, do not set an analytics cookie, and do not create a cross-site identifier. Referrers can nevertheless contain personal data if another site puts such data into its URL.
Purpose and legal basis: aggregate product usage and abuse detection under Article 6(1)(f) GDPR. Retention: normally up to 90 days, then deletion or aggregation. You may object as described in section 13.
4.2 Cookieless web analytics (Plausible)
We use Plausible Analytics, operated by Plausible Insights OÜ, Estonia, to count page views and referrers. The measurement script and the event endpoint are served from our own domain (/stats/js and /stats/event); your browser does not connect to Plausible directly. Our server forwards the event to Plausible together with your IP address and user agent so that Plausible can count unique visits. Plausible states that it processes this data within the European Union, derives a rotating, non-reversible hash for visit counting, and does not store the IP address.
Plausible does not set cookies and does not read information from your device beyond what your browser transmits with the request, so no consent under section 25 TDDDG is required for it. Purpose and legal basis: reach measurement and product decisions under Article 6(1)(f) GDPR — our legitimate interest in understanding aggregate usage without tracking individuals. You may object as described in section 13.
4.3 Administrator sign-in (Clerk)
Our internal administration area is protected by Clerk, Inc., United States. Clerk processes the email address and session data of our own staff members who sign in; it is not used for visitors to the public website. Legal basis: Article 6(1)(f) GDPR (securing our systems). Transfers are covered by Clerk's data processing agreement and EU Standard Contractual Clauses.
5. Passive website scan
When you submit a URL, the scanner makes read-only requests to publicly available pages and assets. It does not attempt a login, guess credentials, or intentionally copy database records. During processing it may receive IP addresses, public page content, HTTP headers, script URLs, host names, and public legal/contact information from the target site.
We store a scan digest containing the submitted host, selected market profile, finding categories, severity/status information, third-party destinations, and the creation date. We do not intentionally store page bodies, database row contents, or secret values. Suspected secrets are redacted in findings.
Purpose and legal basis: performing the scan requested by you (Article 6(1)(b) GDPR where a contract or pre-contractual request exists) and operating and improving a secure service (Article 6(1)(f) GDPR). Our legitimate interests are providing the requested result, preventing duplicate work, quality assurance, and defending against misuse.
Retention: unlisted scan digests and share links are removed after 12 months during scheduled application maintenance. Data required for a contract, complaint, security incident, or legal claim may be retained until that purpose ends and applicable limitation periods expire.
6. Share links and public directory
Each result receives a cryptographically random share identifier. Anyone who obtains the link can view the result; share links should therefore be treated as confidential. A report is added to the public checked-app directory only after an explicit opt-in. Directory entries remain visible until the operator withdraws the opt-in or asks us to remove them.
Please do not submit private intranet URLs, URLs containing credentials or personal data in query strings, or a third party's site without authority.
7. Database provider
Production share reports, requested-report leads, payment audit records, and anonymous usage records are stored in Neon Postgres, with the database project intended to be located in Frankfurt, Germany. Neon may use subprocessors and provides a Data Processing Agreement and cross-border transfer safeguards. Provider information: https://neon.com/security, https://neon.com/pdf/DPA.pdf, and https://neon.com/subprocessors.
8. Email reports
If you request a report by email, we store your email address, the target host, and the time. The report email is sent only to fulfil your request under Article 6(1)(b) GDPR. The current form does not subscribe you to marketing.
Email is delivered by Plus Five Five, Inc. (Resend). Resend receives the recipient address, message content, delivery metadata, and technical logs. Resend states that account data and email metadata are stored in the United States even when an EU sending region is selected. Transfers are covered by Resend's DPA, EU Standard Contractual Clauses, and, where applicable, the EU-US Data Privacy Framework. See https://resend.com/legal/dpa and https://resend.com/legal/privacy-policy.
Transactional report-request records are normally retained for 90 days after delivery, unless they become part of a purchase or support case. If a marketing subscription is introduced later, it will use a separate consent and legally appropriate confirmation process. Any such consent can be withdrawn at any time by emailing hello@howsafeismyapp.com.
9. Stripe payments
Paid reports use Stripe Payments Europe, Limited, Ireland, and its affiliates. Stripe collects payment method, billing, fraud-prevention, device, and transaction data on its own checkout page. We receive a session/payment status, amount, target host metadata, and transaction identifiers; we do not receive full card details.
Legal basis for our processing: Article 6(1)(b) GDPR (contract performance) and Article 6(1)(c) GDPR (tax/accounting obligations). Stripe acts under its own legal roles described in its privacy documentation. International transfers may rely on the EU-US Data Privacy Framework and Standard Contractual Clauses. See https://stripe.com/legal/privacy-center and https://stripe.com/legal/data-privacy-framework.
Payment and accounting records are retained for the applicable statutory period, generally eight years for accounting vouchers under section 147 AO and section 257 HGB; longer retention can apply where another legal duty or an ongoing dispute requires it.
10. Cookies and browser storage
The current application does not set analytics or advertising cookies and does not use client-side analytics. It self-hosts its fonts. A consent banner is not used because the current first-party page does not perform non-essential access to your device within the meaning of section 25 TDDDG. Stripe's separate checkout page is governed by Stripe's notices.
11. Recipients and transfers
Depending on the feature used, recipients are Google Cloud (hosting/rendering), Neon (database), Plausible (cookieless analytics), Resend (email), Stripe (payment), Clerk (administrator sign-in), professional advisers, and authorities where legally required. We do not sell personal data. Provider locations and subprocessors can change; current provider lists and transfer terms linked above control.
12. No solely automated legal decision
The scanner automatically classifies technical signals. It does not make a decision producing legal or similarly significant effects about a person within Article 22 GDPR. Findings are technical indicators and may contain false positives or omissions.
13. Your rights
Subject to the statutory conditions, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21). You may withdraw consent prospectively at any time (Article 7(3)). Contact hello@howsafeismyapp.com.
You may lodge a complaint with the data protection supervisory authority for your habitual residence, place of work, or the alleged infringement. The authority responsible for the controller should be inserted after the legal address is final: Landesdatenschutzbehörde Berlin.
14. Changes
We update this policy when the service or law changes. The date at the top is the applicable version. Material changes will be highlighted where reasonably possible.