Privacy Policy

Last updated: September 3, 2026

BlackBrains ("we", "us", or "our") operates the automated security-scanning platform at blackbrains.tech. This policy explains what personal data we collect, why, how long we keep it, and what rights you have.

1. Who we are and what this covers

You register a website you own, we run automated security tools against it, and we return a report describing the weaknesses found. This policy covers the website, the API, the browser extension and the mobile app.

2.1 Account data — you give us this

Full name — to address you in the product and in emails. Email address — login identifier, security codes, scan notifications, receipts. Password — authentication. Stored only as a PBKDF2-HMAC-SHA256 hash (100,000 iterations, unique 16-byte salt). We never store or transmit your password in readable form and cannot recover it.

2.2 Scan data — created when you use the service

• Target website addresses you register • Scan configuration (which checks, how deep, excluded paths) • Scan results: vulnerabilities found, severity, affected URLs, and technical evidence (request/response fragments captured by the tools) • Timing and status of each scan

2.3 Credentials for authenticated scanning — optional

If you ask us to scan an area of your site that requires login, you may store a username and password for your own site. These are encrypted at rest and are decrypted only for the duration of a scan. They are never shown back to you and never included in reports. Do not enter credentials for any system you do not control.

2.4 Technical and security data — collected automatically

• IP address, endpoint accessed, HTTP method, and the outcome of the action • Timestamps and the role you acted under We keep this as a security audit log to detect abuse and investigate incidents. It is retained for 90 days and then automatically deleted.

2.5 Browser extension

The extension submits the details of the page you choose to scan (URL, page structure, form and script metadata) plus a device fingerprint and your IP address, which we use solely to enforce free-tier rate limits and prevent abuse. The extension does not read pages you have not asked it to scan.

2.6 Payment data

Payments are processed by Stripe. Card numbers never reach our servers — we receive only the subscription status and a transaction reference. Stripe processes this as an independent controller under its own privacy policy.

2.7 What we do not collect

We do not use advertising trackers, we do not sell personal data, and we do not profile you for marketing. We do not collect special-category data (health, biometrics, political opinions, and so on) and ask that you do not submit any.

3. Why we process it, and our legal basis

Creating and running your account — performance of a contract. Running scans and producing reports — performance of a contract. Sending security codes and service emails — performance of a contract. Taking payment and issuing receipts — performance of a contract / legal obligation. Security audit logging and abuse prevention — legitimate interests (keeping the platform and its users safe). Responding to your support or contact messages — legitimate interests. We do not rely on consent for any of the above, so there is no consent to withdraw — but you can close your account at any time (see "Your rights").

4. Automated analysis (AI)

Scan findings may be sent to a third-party AI provider to be de-duplicated, prioritised and explained in plain language for your report. What is sent: the technical findings produced by the scanning tools, plus the target address. What is not sent: your name, email address, password, payment details, or any credentials you stored for authenticated scanning. The provider currently used is configurable; at the time of writing it is OpenAI. Providers are used as processors under contract and are not permitted to use your data to train their models. If you do not want AI processing, contact us and we will disable it for your account — you will still receive the full technical report. There is no automated decision-making that produces legal or similarly significant effects about you.

5. Who we share it with

We share personal data only with the providers needed to run the service: Stripe — payment processing. Data shared: email, subscription and transaction data. AI provider (see "Automated analysis") — report enrichment. Data shared: scan findings, target address. Hostinger (SMTP) — sending our emails. Data shared: email address, message content. Vercel — hosting the web frontend. Data shared: technical request data. Atlassian (Jira) — only if you connect Jira. Data shared: scan findings you choose to export as tickets. We also disclose data where we are legally required to, or to establish or defend legal claims. We do not sell personal data, and we do not share it for anyone else's marketing.

6. Where your data is held, and for how long

Scan data and account data are held on our own servers. Some providers listed above process data outside your country; where that involves a transfer out of the UK/EEA it is covered by the provider's Standard Contractual Clauses or an adequacy decision. Account details — until you delete your account. Scans, findings and reports — until you delete them, or until account deletion. Stored scan credentials — until you remove them, or until account deletion. Raw tool output files on the scanner — deleted immediately after results are saved. Security audit logs — 90 days, then deleted automatically. Guided-setup chat sessions — 24 hours. Login sessions — access tokens expire after 30 minutes; refresh tokens after 30 days. Billing records — as required by tax and accounting law.

7. Your rights

Under UK/EU GDPR you have the right to access, correct, delete, restrict, object to, and port your personal data, and to complain to a supervisory authority. Deleting your account. You can erase your account yourself from the "Delete account" section of your profile page. This is immediate and irreversible. It permanently removes your account, scans, findings, reports, targets, stored credentials, plan and credit records, Jira connections and chat sessions. We keep the security audit log entries, but we anonymise them first: your user ID is removed and your IP address is replaced with an irreversible pseudonym, so the remaining records cannot be linked back to you. This lets us keep an accurate security history without keeping your data. For any other request, email info@blackbrains.tech. We respond within one month.

8. How we protect your data

• Passwords hashed with PBKDF2-HMAC-SHA256, 100,000 iterations, unique salt per user • Stored scan credentials encrypted at rest; scanner-side credential bundles encrypted with authenticated encryption (ChaCha20-Poly1305) • All traffic over HTTPS/TLS • Two-factor email verification on login • Role-based access control; internal services authenticate to each other with separate secrets • Scanner runs in an isolated container per job, and its working files are wiped after each job • Security audit logging with automatic 90-day expiry No system is perfectly secure, but this is the standard we hold ourselves to.

9. Children

The service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

10. Cookies

We use only what is necessary to run the service: a session/authentication token, and a cookie remembering your language choice. We do not use advertising or analytics cookies that track you across sites.

11. Changes

If we make a material change we will notify registered users by email at least 14 days before it takes effect. The "last updated" date above always reflects the current version.

12. Contact

Email: info@blackbrains.tech If you are in the UK or EEA and are unhappy with our response, you may complain to your national data protection authority.

Questions about this policy? Contact us at info@blackbrains.tech.