Privacy Policy

Last updated June 2026

Our approach

Hullchecks is operated by Cysmiq Retriever AI Private Limited (India) and is built privacy-first. The hosted inspection processes only what it needs, for as short a time as possible: a live-URL hullcheck reads only your public surface, and an uploaded zip is inspected in an offline sandbox and deleted right after the report is written.

What we process

  • Scan inputs — a URL you submit, or code you upload, processed transiently to run the scan and then deleted shortly after it completes. We do not retain your source code.
  • Findings — stored with secrets redacted to a masked locator (for example, "AWS key at config.js:12"), never the secret value.
  • Abuse prevention — a salted hash of your IP for rate limiting, never the raw address.
  • Account data — if you create an account, your email and plan.

How we use it

To run scans, show your results, prevent abuse, operate paid features, and improve the Service. We do not sell your data or use your code to train models.

Sub-processors

We use reputable infrastructure providers for hosting, database, storage, and payments. Scanners run in an isolated, offline sandbox. A current list of sub-processors is available on request.

Your rights

Depending on where you live (including under the GDPR and India's Digital Personal Data Protection Act), you may access, correct, export, or delete your data. Email privacy@hullchecks.com and we will respond within a reasonable time.

Privacy Policy · Hullchecks