Legal
Privacy Policy
Effective September 10, 2026
This Privacy Policy explains how HackInspect collects, uses, discloses, and retains information when you use our websites, application-security checks, reports, and related services.
1. Scope
This Policy applies to information processed by HackInspect through the Service. It does not cover third-party websites or services, such as GitHub, an application you choose to test, an AI coding assistant where you paste a generated prompt, or a payment provider. Those services have their own privacy practices.
2. Information we collect
Account and contact information
We collect information such as your email address, password hash, account settings, and communications with us.
Project and testing information
We collect project names, live application URLs, repository URLs and identifiers, proof that you control or are authorized to test a target, test-account names and credentials, and the scope and settings you provide. Test-account usernames and passwords are encrypted in our database.
Repository and application information
When you connect a repository, we may retrieve selected source files, paths, line references, commit identifiers, repository metadata, and analysis results. When we check an application, we may process pages, requests, responses, access behavior, test-session information, and evidence needed to support or verify a finding.
Reports and generated content
We store investigation status, events, findings, supporting evidence, suggested fixes, regression information, exported reports, and generated prompts.
Technical and usage information
We may collect IP address, browser and device information, timestamps, pages viewed, feature usage, error records, security logs, and cookie or session information. If paid plans are offered, a payment provider may process billing details and provide us with transaction and subscription records.
We receive information directly from you, automatically from your use of the Service, from the application you authorize us to check, and from connected providers such as GitHub.
3. How we use information
We use information to:
- create and secure accounts;
- verify authorization and perform requested or scheduled checks;
- connect repositories, analyze application behavior, create reports, and verify fixes;
- generate explanations, recommendations, and AI-ready prompts;
- email account notices, reports, findings, service messages, and support responses;
- operate, debug, protect, measure, and improve the Service;
- prevent fraud, abuse, unauthorized testing, and security incidents;
- administer plans, payments, and usage limits; and
- comply with law and enforce our agreements.
4. Artificial intelligence
HackInspect uses AI systems to help analyze information, explain findings, suggest next steps, or generate prompts. Depending on the feature, relevant portions of repository content, application evidence, and report information may be processed by AI service providers acting on our behalf.
AI systems can make mistakes. Generated output should not be treated as a security certification or professional advice. Review findings and proposed fixes with qualified developers and, where appropriate, a security professional or security team before making or deploying changes.
We will describe material changes to our use of AI or Customer Content in this Policy or an in-product notice. Do not submit information to an AI-enabled feature unless you are authorized to have it processed for that purpose.
5. How we disclose information
We may disclose information to:
- infrastructure, hosting, database, monitoring, email, customer-support, analytics, payment, and security providers that help operate the Service;
- repository and identity providers, such as GitHub, when you connect or use them;
- AI service providers when an AI-enabled feature requires processing;
- professional advisers, auditors, insurers, and financing or transaction partners under appropriate duties of confidentiality;
- government authorities, law enforcement—including the United States Federal Bureau of Investigation where appropriate—or other parties when reasonably necessary to comply with law, protect rights and safety, investigate suspected illegal or harmful use, preserve evidence, or enforce agreements; and
- a successor involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
We do not currently sell personal information or share it for cross-context behavioral advertising. If that practice changes, we will update this Policy and provide legally required choices before the change applies.
6. Retention and deletion
We retain information while your account is active and as reasonably necessary to provide the Service, maintain security and business records, resolve disputes, enforce agreements, and comply with law. Retention depends on the type of information, the sensitivity of the data, why it was collected, and legal or operational requirements.
You can delete a project and its associated credentials, investigations, events, and findings through the Service when no investigation is actively running. You can also close your account using the account controls. Deleted information may remain temporarily in backups and security records until those systems are overwritten or the information is no longer reasonably needed.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information. For example, saved test-account usernames, passwords, and regression records are encrypted. No security measure or transmission method is completely secure, and we cannot guarantee that information will never be accessed, lost, altered, or disclosed.
You can reduce risk by using a separate test environment, artificial data, short-lived test credentials, minimum repository permissions, and prompt removal of projects and credentials you no longer need.
9. Your choices and privacy rights
You may update your account information, export project data, delete projects, remove test credentials, disconnect provider access through the provider, or close your account using the available controls.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; to opt out of certain sales, sharing, targeted advertising, or profiling; and to appeal a denied request. We may need to verify your identity and authority before completing a request. You will not be discriminated against for exercising a privacy right.
HackInspect does not currently sell personal information or use it for cross-context behavioral advertising, so there is no sale or advertising-sharing opt-out required for our current practices.
10. Location and international use
The Service is operated from the United States. Information may be processed in the United States and other countries where our providers operate. Those countries may have different data-protection laws. Where required, we use an approved legal mechanism for international transfers.
11. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children through the Service. If you believe a child has provided information, contact us so we can review and delete it where appropriate.
12. Changes and contact
We may update this Policy as the Service and our practices change. We will post the revised version, update the effective date, and provide additional notice when required by law.
Privacy requests and questions may be sent through the contact method provided in the Service. Operator identity, mailing address, and a dedicated privacy email should be added here before commercial launch.