[ Legal ]
Privacy Policy
Last updated: 30 July 2026
This policy covers AuditMerlin (“we”, “us”), a website security audit service at app.auditmerlin.com. It explains the data we hold about visitors to this website and about people who run audits, unlock reports, or create an account.
1. What we collect
- Account data: your email address. Login works with one-time magic links, so we never store a password.
- Scan data: the URL you submit and the audit results we compute for it (response headers, TLS metadata, and the presence of publicly reachable files).
- Cloudflare API token, only if you choose to connect Cloudflare on a paid plan. It is encrypted at rest, used only to apply or undo the fixes you request, and you can disconnect it at any time.
- Billing details for paid plans, processed by Stripe. We never see or store your full card number.
- Server logs (request metadata such as IP address, timestamp, and user agent), kept for security and troubleshooting.
Legal basis: performance of our contract with you.
2. What scanning a site involves
An audit makes ordinary public requests to the site you submit: standard GET requests and a TLS handshake, the same things a browser does. We never attempt to exploit, fuzz, brute-force, or log in to the target site, and we do not collect personal data from the pages we fetch.
3. Cookies
The app at app.auditmerlin.com uses a small number of strictly necessary, httpOnly cookies to keep you logged in. The login page uses Cloudflare Turnstile for bot protection, which may set its own functional cookie. We do not use advertising or cross-site tracking cookies. This marketing website sets no cookies of its own.
4. Email
Transactional email (magic sign-in links, report unlocks, billing receipts) is sent through Amazon Web Services SES. We do not send marketing email without your consent.
5. Who we share data with (sub-processors)
- Hetzner (EU hosting and database)
- Cloudflare (CDN, proxy, security, and Turnstile bot protection)
- Amazon Web Services SES (transactional email)
- Stripe (payment processing for paid plans)
We never sell your data.
6. Retention and your rights
We keep your data while your account is active. You may request access, correction, export, or erasure of your account and its data, and you can lodge a complaint with your data protection authority. Deleting your account removes your sites, scan history, and any stored Cloudflare token. Invoicing records may be retained where required by tax law.
7. Contact
Email [email protected]. We respond within 30 days.