Legal

Privacy Policy

Last updated: May 12, 2026

This is the policy of Individual Entrepreneur Mykhailo Polazhynets, the operator of CrabScan. It explains, in plain English, what data we collect, how we use it, and the rights you have. We try to be honest and specific — if anything is unclear, please email us at support@crabscan.ai.

The short version

  • We store your email (only if you sign in), the domains you scan, and the resulting reports.
  • We send your scan data to Anthropic so an AI can summarize it. We send your email through Resend to deliver magic links and audit reports. Payments are processed by our payment provider acting as Merchant of Record (identified at checkout). We use Cloudflare Turnstile to block bots.
  • Anonymous scans expire in 7 days. Free-tier scans expire in 30 days. Paid scans and audits stay until you delete them.
  • We never sell your data, run no ad-tech, and use no third-party analytics.
  • You can request a copy of your data, correction, or deletion at any time.

1. What we collect

Information you give us directly:

  • Email address. We use it as your account identity and to send you magic-link sign-ins, audit reports, and (rarely) service notifications.
  • Domain names you submit for scanning. Treated as scan input, stored alongside the resulting report.
  • Payment information(when applicable). Handled entirely by our payment processor — we don't store card numbers. We receive only the subscription status, customer ID, and last-4 digits for invoicing.

Information generated by your use of the Service:

  • Scan results. The structured output of scanners (open ports, HTTP headers, TLS metadata) for each domain you submit, plus the AI-generated summary.
  • Audit reports. Same as scans, plus a longer AI analysis. You access them via a permanent shareable link.
  • Account metadata. Your tier, when you signed up, your scan and audit history.

Information collected automatically:

  • IP address.Used to enforce rate limits and detect abuse. We log it in transient request logs but don't store it against your scan results.
  • Session cookie (named sec_session). HttpOnly, SameSite=Lax, encrypted JWT. Used solely to keep you signed in. No analytics or tracking cookies.
  • localStorage (browser-only, never sent to our servers): a small list of scan IDs you ran while anonymous, so we can offer to claim them after you sign in. Cleared by us on dismiss or claim, expires after 7 days.

2. How we use it

  • To run the scans you ask us to run.
  • To deliver reports — both in the app and by email (for paid Deep Audits).
  • To enforce tier limits and prevent abuse.
  • To process payments and manage subscriptions, via our payment processor.
  • To investigate and respond to security incidents (e.g. someone attempting to exploit our rate limiter).
  • To improve the Service — e.g. analyzing aggregated, anonymized scan data to refine our scoring rubric. Never on a per-customer basis.

We do not use your data to train AI models. The AI we use (Anthropic Claude) is configured to not retain or train on inputs we send.

4. Who we share it with

We share your data only with these sub-processors, and only what they need to do their job:

  • Anthropic, PBC (USA) — receives the structured scanner output for AI analysis. Does not retain or train on inputs.
  • Resend, Inc. (USA) — delivers magic-link sign-in emails and audit-ready notifications. Receives your email address and the email body.
  • Cloudflare, Inc. (USA) — provides Turnstile (bot protection). Receives your IP address and a browser fingerprint for the duration of solving the challenge.
  • Hetzner Online GmbH (Germany) — runs our servers and stores our database. Receives all customer data needed to operate the service.
  • Our payment provider— acts as Merchant of Record and processes all payments. Receives your email, billing address, and payment details directly from you. We never store card numbers. The provider's identity, terms of service, and privacy policy are displayed in the checkout window and on the receipt you receive after purchase.

We do not sell your data, share it with advertisers, or expose it to data brokers.

5. How long we keep it

  • Anonymous scans: 7 days from creation, then permanently deleted.
  • Free-tier scans: 30 days from creation, then permanently deleted (unless you upgrade — then they become permanent).
  • Pro / Agency scans: kept until you delete them or close your account.
  • Deep Audits: kept indefinitely — you paid for the report and may need it for compliance reasons. You can request deletion at any time.
  • Account email: kept while your account is open.
  • Magic-link tokens: 15-minute expiry, single-use, stored only as a SHA-256 hash. Cleartext is never persisted.
  • Request logs: 7 days, then deleted. Used for debugging and abuse investigation.
  • Backups:rolled monthly. A scan you delete may persist in a backup for up to 30 days, after which it's overwritten.

6. Your rights

You can exercise these rights by emailing support@crabscan.ai. We'll respond within 30 days.

  • Access: request a copy of the personal data we hold about you.
  • Rectification: ask us to correct inaccurate data.
  • Erasure ("right to be forgotten"): ask us to delete your account and all associated data, subject to legal retention obligations (e.g. tax records).
  • Portability: receive your data in a machine-readable format (JSON).
  • Objection / restriction: object to specific uses of your data or ask us to restrict processing while we resolve a dispute.
  • Withdraw consent: for anything we processed based on your consent.
  • Lodge a complaint with your local data-protection authority. For EU users, you can find yours at edpb.europa.eu.

7. International data transfers

Some of our sub-processors (Anthropic, Resend, Cloudflare) are based in the United States. When your data is transferred there, the transfer is governed by Standard Contractual Clauses or an equivalent mechanism approved under EU/UK data-protection law.

8. Security

We protect your data with appropriate technical and organizational measures:

  • TLS encryption for all traffic.
  • Database encryption at rest.
  • Magic-link tokens stored only as SHA-256 hashes.
  • HttpOnly session cookies signed with a strong secret.
  • Rate limits, signup velocity caps, disposable-email blocklist, and global AI spend cap to limit abuse.
  • Backups encrypted and access-controlled.

No system is perfectly secure. If we ever discover a breach affecting your data, we'll notify you within 72 hours of becoming aware, per GDPR.

9. Children

The Service is not directed to anyone under 16. If we learn that we've collected data from a child, we'll delete it.

10. AI disclosure

We use AI to summarize scan findings and generate audit reports. The AI's output is deterministic enough for production use but can occasionally make mistakes (factual or technical). Always verify critical fixes against authoritative documentation. The AI's analysis is not a substitute for professional security review.

We do not use the AI to make automated decisions that have a legal or similarly significant effect on you (e.g. denying you service). Tier and limit decisions are deterministic and based on your account status only.

11. Changes to this policy

When we update this policy, we'll change the "last updated" date at the top. For material changes — anything that meaningfully affects your privacy — we'll email account holders at least 14 days before the change takes effect.

12. Contact us

For privacy questions, requests under any of the rights above, or to exercise your data-protection rights:

  • Email: support@crabscan.ai
  • Individual Entrepreneur Mykhailo Polazhynets
    Tax ID: 3391114511
    Torun, 358, Mizhhirya district, 90015, Zakarpattia region, Ukraine

See also: our Terms of Service and Refund Policy.