Back to home
Safe-say

Privacy Policy

Effective Date: 2026

This Privacy Policy explains how Safe-say collects, uses, stores, and protects your personal data when you use our application security platform. We are committed to protecting your privacy in accordance with the Brazilian General Data Protection Law (LGPD) and the EU/UK General Data Protection Regulation (GDPR).

1. Data We Collect

Account data: your name, email address, organization name, and authentication credentials (managed via our secure identity provider).

Target & scan data: the assets you register (domains, IPs, CIDR ranges, URLs, API specifications), ownership-validation records, scan configuration, findings, and reports generated for you.

Technical data: IP address, browser type, device information, and usage analytics collected when you access the platform.

2. Payment Data

Payments are processed by our payment processor (Stripe). We do not store or process your full card numbers, CVV, or other sensitive payment instrument data on our servers.

Stripe handles card data in compliance with the Payment Card Industry Data Security Standard (PCI DSS). We store only the identifiers returned by Stripe (such as a customer or subscription reference) needed to manage your billing and subscription.

3. How We Use Data

We use your data to: provide and operate the scanning service; verify that you are authorized to test the assets you register; manage your account, subscriptions, and billing; deliver scan results and reports; improve and secure our platform; and comply with legal obligations.

We do not sell your personal data. We process your data only for the purposes described in this Policy.

4. Cookies & Session Data

We use session cookies (including HttpOnly, Secure, SameSite cookies) to keep you authenticated and protect your session. We also use essential cookies required for the functionality of the service.

Cookies used for authentication are cleared when you log out and do not persist beyond your session except where required to maintain your login.

You can control optional analytics cookies through your browser settings; however, disabling essential cookies may prevent the platform from functioning.

5. Scan Log & Data Retention

Scan logs (including terminal output and raw findings) are retained only as long as needed to deliver reports and support your account. Retention periods are defined per data category and aligned with your subscription lifecycle.

When you delete a target or your account, we make reasonable efforts to delete or anonymize associated target and scan data, except where we are legally required to retain records.

We implement appropriate technical and organizational measures, including encryption in transit and at rest, to protect your data against unauthorized access.

6. Your Rights (LGPD / GDPR)

Depending on your jurisdiction (e.g., under the Brazilian LGPD or the EU/UK GDPR), you may have the right to access, correct, delete, or restrict the processing of your personal data, and the right to data portability.

You may withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data-protection authority (e.g., ANPD in Brazil or the relevant GDPR supervisory authority).

To exercise any of these rights, contact our team with your request; we will respond within the period required by law and verify your identity before actioning changes.

7. Third-Party Processors & Contact

We engage processors to deliver the service, including our cloud hosting provider, our payment processor (Stripe), and LLM/AI model providers used to execute scans. Each processor is bound by appropriate data-processing terms.

We may update this Privacy Policy to reflect changes in our practices or legal requirements and will communicate material changes before they take effect.

For privacy inquiries or to exercise your rights, contact the Safe-say team. This Policy is governed by applicable data-protection legislation in the jurisdictions where Safe-say operates.