Privacy Policy
Last updated: 15 August 2026
This Privacy Policy describes how FPSEC (“we”, “us”, “our”) collects, uses, stores, and protects personal data when you visit our website or use AppCheck. We collect as little as possible, and we do not share your data with third parties.
1. Who we are
FPSEC is the data controller responsible for the personal data described in this policy. You can contact us at privacy@fpsec.sh.
2. Data we collect
We only collect data that is necessary to provide the AppCheck service:
- Account data — your name, work email address, company, and billing details.
- Audit inputs — the target URL(s), a read-only test account, and, if you choose to share it, read-only source repository access.
- Audit outputs — scan results, scorecards, fix lists, and the FPSEC certificate we issue.
- Operational logs — request and rate-limit logs used to prevent abuse and debug issues.
3. How we use your data
We use your personal data to:
- run the audit and produce your scorecard and fix list;
- issue and re-issue your FPSEC certificate;
- provide support and send invoices;
- prevent abuse and unauthorized scans.
The legal basis for this processing is the performance of the contract you enter into when you order an audit, and our legitimate interest in protecting our systems from abuse.
4. Third parties
We do not sell, rent, or share your personal data with third parties. We do not use third-party advertising networks, analytics vendors, or data brokers. Your data is accessed only by the FPSEC team members who run your audit. The only exceptions are where disclosure is required by law, or where disclosure is necessary to protect the security of our systems.
5. Cookies and tracking
We do not use third-party tracking cookies, pixels, or similar technologies. Any cookies we set are strictly necessary for the service to function.
6. Data retention
Account data is kept while your account is active and deleted on request. Scan results are kept for 12 months after delivery so you can use your free rescans, then deleted. Certificates are publicly shareable by design and remain available until they expire.
7. Your rights
Depending on where you are based, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict our processing of it. To exercise any of these rights, email privacy@fpsec.sh. We will respond within 30 days.
8. Security
We protect data in transit and at rest using encryption, and we apply least-privilege access controls. Only the team members running your audit have access to the details.
9. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and update the “Last updated” date above.
10. Contact
Questions about this policy? Email privacy@fpsec.sh.