Privacy Policy
Last updated: 8 July 2026
This Privacy Policy explains what data HatTest (“we”, “us”) collects when you use hattest.ai (the “Service”) and how we handle it.
1. What we collect
- Scan inputs and results — the URLs you submit and the findings and evidence derived from scanning them.
- Email address — if you contact us or purchase a report.
- Payment information — handled by Stripe. We do not receive or store your full card number.
- Technical data — IP address, request metadata, bot-protection (Turnstile) tokens, and basic logs, used for security, abuse prevention, and rate limiting.
2. How we use it
- To run scans and deliver your results — the scoreboard and informational findings, and, when you unlock them, the paid negative findings.
- To verify domain ownership and process payment.
- To prevent abuse and keep the Service available.
- To respond to your support requests and comply with the law.
We do not sell your personal data, and we do not use advertising or cross-site tracking.
3. Service providers
We rely on a small number of processors, each governed by its own privacy terms:
- Cloudflare — hosting, bot protection (Turnstile), encrypted storage, and email routing.
- Stripe — payment processing.
- SendGrid (Twilio) — transactional and contact-form email.
4. Retention
Raw scan evidence is automatically deleted 30 days after a scan, always — regardless of any setting. The minimized finding record (severity, title, control mapping, and a redacted teaser — no raw evidence) is retained so your scan history and continuous monitoring stay available, until you delete it. You are in control: delete any individual scan or your entire account at any time from your dashboard, and we honor it immediately — or set new scans to delete on the 30-day schedule instead. We keep a minimal record of paid scans (the property, date, and amount — no findings or evidence) for billing and to price repeat scans correctly. Emails you send us are kept only as long as needed to handle your request.
5. Security
Scan evidence is encrypted at rest (envelope encryption), and we minimize what we store. No method of transmission or storage is perfectly secure, but we design the Service to hold as little sensitive data as possible, to expire the raw evidence quickly, and to keep the minimized record no longer than it is useful to you.
6. Cookies and tracking
We do not use advertising trackers or cross-site tracking. For aggregate traffic measurement we use Cloudflare Web Analytics, which is privacy-first: it sets no cookies, uses no client-side state, and does not fingerprint or track you across sites. Cloudflare Turnstile and Stripe may set their own functional cookies or load their own scripts when you use the scan or payment features.
7. Your rights
You can request access to, or deletion of, personal data we hold about you by emailing support@hattest.ai. You can also delete your scans and your account yourself, at any time, from your dashboard: raw evidence clears within 30 days automatically, and deleting a scan or your account removes the retained finding record immediately.
California residents: under the CCPA/CPRA you have the right to know, access, and delete the personal information we hold about you, and not to be discriminated against for exercising those rights. We do not sell or share your personal information. To make a request, email support@hattest.ai.
8. Children
The Service is not directed to children under 16, and you should not use it if you are under 16.
9. International processing
The Service runs on Cloudflare’s global network and our processors operate internationally. By using the Service you consent to your data being processed in the locations where we and our processors operate.
10. Changes and contact
We may update this Policy from time to time. For any privacy question, contact support@hattest.ai.