Skip to main content

Privacy Policy

Effective as of August 2026 — GDPR compliant (EU 2016/679)

1. Data controller

Kortilabs is the data controller for this service.
Contact: [email protected]

2. No persistence of scan results — technical confirmation

SecureCheck does not store the URL you submit nor the results of the scan. Technically:

  • The /api/scan endpoint computes the scan result entirely in memory, for the duration of a single HTTP request, and returns it directly in the response.
  • The submitted URL and the scan report are never written to disk and never inserted into a database — this service uses no database.
  • The only server-side state kept is an in-memory rate-limit counter per IP address (request count and reset time), used solely to enforce the 10 scans/minute limit; it contains no scan content and is discarded once its rolling window expires.
  • Once the HTTP response is sent, nothing related to the request is retained beyond the request/response cycle.

This applies to the free public scan. Paid offers involve additional, limited processing described in section 3 below — in particular, the Fix-it-for-me offer results in the scanned URL being transmitted to our notification provider (see "Order notification" below).

3. Data collected and purposes

ProcessingDataLegal basisRetention
Security scanURL submitted by the user, HTTP responses fetched from that URLArt. 6.1.b (performance of the requested service)None — processed in memory only, never stored
Rate limitingIP address, request count (in-memory, non-persistent)Art. 6.1.f (legitimate interest — abuse prevention, availability)Rolling 60-second window
Payment (Badge, Fix-it-for-me, API offers)Name, email, payment details — collected and processed directly by LemonSqueezy (Kortilabs never receives your card details)Art. 6.1.b (performance of the ordered offer)Per LemonSqueezy's own retention policy, as our payment processor and Merchant of Record
License validation (Badge, API offers)License key, cached validation result (in-memory, no scan content)Art. 6.1.b (performance of the ordered offer)Up to 5 minutes per key (cache), bounded in size
Order notification (Fix-it-for-me offer only)Buyer name and email, order amount, and — if you filled in the "scanned URL" field at checkout — the URL you asked us to fix. This data is emailed once, via Brevo, to Kortilabs' own inbox to trigger the manual remediation; it is not stored in any database.Art. 6.1.b (performance of the ordered offer)Kept in the recipient mailbox per Kortilabs' normal email retention; not persisted elsewhere
Audience measurement (if consented)Cookies (_ga, _ga_*, _gid) via Google Analytics/GTMArt. 6.1.a (consent — Google Consent Mode v2, denied by default)13 months max

About the scanned URL and Fix-it-for-me: the URL you submit for a Fix-it-for-me order can, by design, indirectly identify you or your business (e.g. your own website's address). It is only transmitted to Brevo (our transactional email provider) as part of the order notification described above, solely so our team knows which site to fix — never for marketing, profiling, or any other purpose, and never for the free public scan.

4. Hosting and sub-processors

The application is hosted in the European Union.

Sub-processorRoleRegion
Contabo GmbHApplication hosting (VPS)Germany (EU)
LemonSqueezyPayment processing and Merchant of Record for the Badge, Fix-it-for-me, and API offersEU/US (Standard Contractual Clauses)
BrevoTransactional email — sends Kortilabs a one-time internal notification when a Fix-it-for-me order is placed (may include the scanned URL, see section 3)France / EU
Google (Google Analytics / GTM)Audience measurement — only after consentEU/US (Standard Contractual Clauses)

5. Cookies

This site deposits no strictly necessary cookie beyond the consent-choice cookie itself (tarteaucitron). Audience measurement cookies are deposited only after your explicit consent, collected via the cookie banner (Google Consent Mode v2 — denied by default). You can change your choice at any time via "Manage cookies" in the footer.

6. Your rights

Under the GDPR, you have the right to access, rectify, delete, restrict, and port your personal data, as well as the right to object. Since no scan URL or result is ever stored, these rights mainly apply to cookie consent. Requests can be sent to [email protected]. You also have the right to lodge a complaint with the CNIL (France) or your local supervisory authority.