Back to Presail

Privacy Policy

Last updated: August 24, 2026

1. Data We Collect

Account data: your email address, name, and authentication credentials (stored as hashed passwords by our auth provider).

Profile data: notification preferences, phone number (if you opt into SMS alerts), and onboarding selections you provide.

App data: the URLs, names, and types of applications you submit for scanning, and the scan results we generate.

Usage data: pages visited, features used, and device/browser information collected through standard analytics.

2. How We Use Your Data

We use your data to: (a) provide security scans and reports for the applications you submit; (b) send you security alerts and daily briefs when enabled; (c) operate and maintain the service; (d) communicate with you about your account; and (e) detect, prevent, and address fraud or abuse.

3. Legal Bases (GDPR)

For users in the EEA, UK, and Switzerland, we process your data on the following bases: (a) contract — to provide the service you signed up for; (b) legitimate interest — to secure and improve the service; (c) consent — for optional marketing communications and analytics, which you can withdraw at any time.

4. Data Sharing

We do not sell your data. We share it only with: (a) our payment processor (Stripe) to handle subscription billing; (b) our auth provider to manage login; (c) email delivery services to send alerts and briefs; and (d) authorities where required by law. All processors are bound by data protection agreements.

5. Data Security

We protect your data with encryption in transit (TLS) and at rest. Access to your data is restricted by row-level security — other users cannot see or modify your apps, scans, or alerts. Only your account and authorized admins can access your data. Scan results are scoped to the account that created them.

6. Data Retention

We retain your data for as long as your account is active. When you delete your account, we remove your applications, scan history, and alerts within 30 days. We may retain limited data for legal obligations or fraud prevention.

7. Your Rights

Depending on your region, you may have the right to: (a) access your data; (b) correct inaccurate data; (c) delete your data; (d) export your data; (e) object to processing; (f) withdraw consent; and (g) lodge a complaint with a supervisory authority. To exercise these rights, use the delete-account option in your settings or contact us.

8. Cookies and Consent

We use essential cookies to maintain your session and authenticate you. We may use optional analytics cookies to understand usage. On your first visit, we show a consent banner asking whether you accept non-essential tracking; your choice (accept or reject) is stored locally with a timestamp and persists across visits. You can change this choice at any time by clearing your local storage or contacting us. We do not sell cookie data to third parties.

9. Children's Privacy

The service is not directed to children under 16. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

10. International Transfers

Your data may be processed in countries other than your own. We use standard contractual clauses and equivalent safeguards to protect international transfers.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be notified through the service or by email. Continued use after changes constitutes acceptance.

12. Vulnerability Reporting

Security researchers may report vulnerabilities responsibly to security@presail.app or via the details published at /.well-known/security.txt.

13. Contact

For privacy questions or data requests, contact us through the support channel in your dashboard or at security@presail.app.

We use analytics to improve Presail. You can accept or reject non-essential tracking. Privacy policy.