Privacy Policy

Last updated:August 4, 2026

1. Introduction

Sentinel Security Scanner ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our security scanning service.

2. Information We Collect

We collect the following types of information:

2.1 Account Information

  • Email address (for authentication and communications)
  • Name and organization details (optional)
  • Authentication tokens and session data

2.2 Scan Data

  • Target domains and infrastructure details you authorize us to scan
  • Scan results and vulnerability reports
  • Security telemetry and metrics
  • Remediation recommendations generated by our AI systems

2.3 Technical Data

  • IP address and browser type
  • Device information and operating system
  • Usage patterns and interaction data
  • Log files and diagnostic information

3. How We Use Your Information

We use the collected information for the following purposes:

  • Providing and improving our security scanning services
  • Generating vulnerability reports and remediation recommendations
  • Authenticating users and securing accounts
  • Processing payments and managing subscriptions
  • Sending service-related communications and updates
  • Analyzing usage patterns to enhance our service
  • Complying with legal obligations

4. Data Storage and Security

We implement industry-standard security measures to protect your information:

  • Encryption at rest using AES-256 for sensitive data
  • Encryption in transit using TLS 1.3
  • Secure authentication with NextAuth.js
  • Regular security audits and penetration testing
  • Access controls and principle of least privilege

Scan results and telemetry data are stored in Google Cloud Firestore, while account and billing information is stored in PostgreSQL hosted on Neon. Both services maintain high security standards and compliance certifications.

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share your information only in the following circumstances:

  • With your explicit consent
  • With service providers who perform services on our behalf (e.g., payment processing, cloud infrastructure)
  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • In connection with a business transfer or merger

6. AI and Machine Learning

Our service uses Google Cloud Gemini AI to generate vulnerability analysis and remediation recommendations. When using AI features:

  • Scan data is sent to Google Cloud's AI services for analysis
  • Google processes this data under their privacy policy and data processing agreements
  • We do not use your data to train Google's AI models
  • AI-generated content is based solely on your scan results and security best practices

7. GDPR Compliance

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

To exercise these rights, please contact us using the information provided below.

8. Data Retention

We retain your information for as long as necessary to provide our services and comply with legal obligations:

  • Account information: Retained while your account is active
  • Scan results: Retained according to your subscription plan (typically 30-90 days for free plans, longer for paid plans)
  • Payment records: Retained for 7 years as required by tax regulations
  • Logs and diagnostics: Retained for 90 days for security and troubleshooting purposes

9. Third-Party Services

Our service integrates with the following third-party providers:

  • Google Cloud (Gemini AI, Firestore): AI analysis and data storage
  • Neon (PostgreSQL): Relational database for account data
  • Upstash (Redis): Message queuing and rate limiting
  • Stripe: Payment processing
  • Vercel: Application hosting and edge computing
  • Render: Background worker hosting

10. Children's Privacy

Our service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected such information, we will take steps to delete it immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the service after such changes constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Contact Support

© 2026 Sentinel. All rights reserved.