1. Scope and controller
This Policy applies to the SafeForProd website and Services. SafeForProd is responsible for the personal information it determines how and why to process.
For information contained in a customer-controlled application, repository, test account, or dataset, SafeForProd’s role may depend on the engagement. A signed agreement may include additional data-processing terms.
Privacy questions and requests may be sent to hello@safeforprod.com.
2. Information you provide
Depending on the Service, you may provide:
- App URLs, domains, project descriptions, framework or platform information, and scan preferences.
- Your email address, contact details, communications, support requests, and report-delivery information.
- Your ownership-or-authorization attestation and information used to verify domain control or testing permission.
- Account, billing, transaction, and engagement information for paid Services.
- Source code through a ZIP or selected read-only repository connection, configuration files, test accounts, documentation, and project context when you request deeper analysis.
- Any feedback, remediation updates, or retest materials you choose to submit.
Please do not provide production credentials or personal data that are unnecessary for the agreed scope.
3. Information collected automatically
When you use the website or Services, we may collect:
- IP address, approximate network or regional information, browser and device type, operating system, user agent, referring page, requested pages, timestamps, and diagnostic events.
- Signed session or security identifiers, rate-limit decisions, bot-verification outcomes, failed submission information, and evidence of suspected abuse.
- Account activity, feature usage, report access, job status, errors, queue events, and service-performance logs.
We use this information to operate the Services, prevent abuse, enforce scan limits, troubleshoot, and maintain security.
4. Scan and target information
To perform a scan, SafeForProd may process the submitted URL and the information available within the selected scope, including public HTML, scripts, styles, source maps, manifests, response headers, cookies set during the visit, browser storage, network metadata, public routes, stack indicators, and security configuration.
Authorized source scans and human reviews may also process submitted source code, repository metadata, configuration, approved endpoint responses, test-account behavior, and relevant data flows.
A target may unexpectedly expose credentials, personal information, or other sensitive material. SafeForProd minimizes collection, redacts secret values in reports and operational logs where reasonably possible, limits access, and stops retrieval when configured sensitive-data conditions are reached.
The person submitting the target is responsible for having authority to request the scan. See the Terms of Service.
5. How we use information
We use information to:
- Accept, queue, perform, document, and deliver requested scans and reports.
- Create and administer accounts, repository connections, source uploads, paid engagements, and retests.
- Verify authorization, domain control, human submissions, and compliance with scan limits.
- Detect fraud, bots, unauthorized scanning, SSRF attempts, malicious payloads, and threats to SafeForProd or third parties.
- Communicate about reports, support, engagement scope, service changes, and security matters.
- Debug, measure, improve, and develop the Services using minimized or de-identified information where practical.
- Comply with law, enforce agreements, establish or defend legal claims, and respond to valid legal requests.
6. Legal bases where required
Where data-protection law requires a legal basis, SafeForProd processes information as necessary to provide requested Services or perform a contract; for legitimate interests such as service security, fraud prevention, product improvement, and protecting legal rights; to comply with legal obligations; and with consent where consent is appropriate.
Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect earlier lawful processing and may prevent us from providing a requested feature.
7. How information is shared
We may share information only as reasonably necessary with:
- Hosting, infrastructure, email, bot-protection, monitoring, payment, repository, storage, and professional service providers acting under appropriate obligations.
- Integrations or recipients you select, such as a connected repository provider or the email address designated for a report.
- Authorities, regulators, courts, or other parties when required by law or reasonably necessary to protect rights, safety, systems, targets, or the public.
- A successor or potential successor in a merger, financing, reorganization, acquisition, or sale, subject to appropriate confidentiality and legal requirements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
8. Cloudflare Turnstile
SafeForProd may use Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. Turnstile may process browser and network signals such as IP address, TLS fingerprint, user-agent header, site key, origin, browser characteristics, and challenge outcomes.
Cloudflare processes some signals on SafeForProd’s behalf to protect the form and may process signals for its own bot-detection improvement purposes, as described in the Cloudflare Turnstile Privacy Addendum.
9. Google Fonts
The website currently loads font files through the Google Fonts Web API. Your browser sends Google the IP address needed to return the file, the requested URL, HTTP headers including user agent, and referrer information. Google states that Google Fonts does not set or log cookies and does not use this information for profiling or targeted advertising. See Google Fonts privacy information.
10. Cookies and local storage
SafeForProd does not use advertising cookies. The Services may use strictly necessary cookies or browser storage for security, session continuity, preferences, rate limiting, account access, and bot protection.
Turnstile or infrastructure providers may use necessary technologies according to their documentation. Blocking necessary storage may prevent a scan form or account feature from working.
11. Retention
Unless a different period is shown when information is collected or agreed in writing, SafeForProd uses these default retention targets:
- Raw free-scan captures and generated reports: up to 30 days after report delivery.
- Uploaded source code and repository snapshots: deleted within 30 days after report delivery or the end of the engagement.
- Security, authorization, abuse-prevention, and operational logs: up to 12 months.
- Account, payment, contract, support, and legal records: for the relationship and as required for legitimate business, tax, accounting, dispute, or legal obligations.
We may retain de-identified aggregate information that no longer identifies a person or target. Backups may persist for a limited additional cycle and remain protected from ordinary use. We may retain information longer when required by law, necessary for a legal claim, or requested by the customer in writing.
12. Source code and AI systems
Submitted source code, repository snapshots, credentials, and raw scan evidence are treated as confidential engagement material and are not used to train general-purpose AI models.
If an automated model assists with explanation, deduplication, or triage, SafeForProd will minimize and redact inputs where practical and apply the provider and data-handling controls documented for the relevant Service. Deterministic evidence—not a model alone—drives findings.
13. Security
SafeForProd uses administrative, technical, and organizational safeguards designed for the sensitivity of the information, including access controls, encryption where appropriate, isolation, request limits, evidence redaction, and minimal retention. No system is completely secure, and we cannot guarantee that unauthorized access or loss will never occur.
14. International processing
SafeForProd and its providers may process information in countries other than the country where you live. Where required, we use contractual, organizational, or other safeguards recognized by applicable data-protection law.
15. Your privacy rights
Depending on where you live, you may have rights to confirm processing; access, correct, delete, anonymize, or port information; restrict or object to processing; withdraw consent; receive information about sharing; and complain to a data-protection authority.
Send a request to hello@safeforprod.com. We may need to verify your identity and authority. Rights may be limited where information must be retained for security, legal, contractual, or third-party reasons.
16. Children
The Services are intended for people who can legally enter into a service agreement and are not directed to children. Do not submit a child’s personal information unless it is necessary, lawful, and expressly included in an authorized engagement.
17. Third-party sites
The website may link to third-party sites, and scans necessarily interact with customer-selected targets. SafeForProd does not control the independent privacy practices of those parties. Review their policies before providing information to them.
18. Changes and contact
We may update this Policy as the website, Services, providers, or legal requirements change. The revised version will be posted here with a new effective date, and material changes may be communicated through the website, account, or email where appropriate.
Questions, requests, or concerns may be sent to hello@safeforprod.com.