We store your email, your scan history, and the domains you monitor. We don't sell data, we don't run advertising trackers, and we don't share anything with third parties except the infrastructure needed to run the service. Email us and we'll delete your account and everything in it.
sitesecure.online is operated by TekyTec IT Solutions. For anything in this policy, contact privacy@tekytec.com.
Your email address, optionally your website, and which plan you were interested in. Used once, to tell you when that plan launches.
When you create a share link, a trimmed snapshot of that scan becomes readable by anyone holding the URL. The snapshot deliberately excludes AI analysis, detected technology versions and CVE matches — a public link should not hand an attacker a shopping list.
Share links expire automatically (30 days by default). Anyone with the link can view it until then, so only share it with people you intend to.
| Who | What they see | Why |
|---|---|---|
| Our hosting provider | Data stored on the server | Running the service |
| Google (if you use Google Sign-In) | That you signed in | Authentication |
| Google Fonts | Your IP, when fonts load | Typography |
| Razorpay (if you pay) | Payment details | Processing payment — we never see or store your card |
| Our AI provider (when enabled) | Anonymised scan findings | Generating the written analysis |
The AI provider receives check names, statuses and category scores. It does not receive your email, your account ID, or any raw content from the scanned site.
You can ask us to show you what we hold, correct it, delete it, or send you a copy. Email privacy@tekytec.com and we'll action it within 30 days. We don't require a reason and we won't try to talk you out of it.
If you're in the EU or UK, our lawful basis is contract performance for account and scan data, and legitimate interest for security logging and abuse prevention.
Passwords are scrypt-hashed. Traffic is HTTPS-only with HSTS. The application enforces a strict Content-Security-Policy, blocks requests to private network ranges, and rate-limits both scanning and authentication. We publish a security.txt so researchers can report issues to us directly.
No system is perfect. If we ever suffer a breach affecting your data, we'll tell you what happened and what to do about it — without waiting to be asked.
This is a tool for website operators. It isn't directed at children and we don't knowingly collect data from anyone under 16.
If we change this policy materially, we'll email account holders rather than quietly updating the date at the top.