Privacy Policy
Last updated: August 29, 2026 Identity and Contact SaaS Factory LLC operates PrivaScan, a service that scans public website surfaces and locally extracted mobile-app technical facts, produces privacy reports and draft privacy policies, and offers optional monitoring features. Privacy contact: privacy@privascan.net Mailing address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States Scope This Privacy Policy describes how SaaS Factory LLC handles personal information when a person visits privascan.net, creates or uses a PrivaScan account, submits a public URL for scanning, uses browser-local app analysis, opens or saves a report, requests a policy draft, enables optional monitoring, uses billing features, interacts with a consent tool, or communicates with us. Privacy rights and obligations can vary according to a person's location, the service involved, and the law that applies. Our New Mexico location does not make New Mexico law the only law that may apply. This notice describes the practices supported by our reviewed product and operational evidence; it is not a representation that one statute governs every interaction. Information and Sources Depending on the features used, PrivaScan may handle: • Account and contact information, such as an email address, name, authentication records, account settings, and persistent session data. • Purchase and billing information. When configured and used, the reviewed billing flow directs payment-card entry to Stripe's hosted checkout. PrivaScan receives related plan, transaction, billing-contact, entitlement, and payment-status records. • Submitted material, including website URLs, questionnaire answers, company and contact details, product descriptions, privacy-practice details, existing policy text, and policy-drafting instructions. • Public website evidence, including page content and metadata, response headers, cookie names and attributes, script and request hosts, detected service names, form-field labels, consent behavior, and scan diagnostics. • App-scan facts extracted in the user's browser. The reviewed flow keeps the selected APK or IPA binary in the browser while sending extracted technical facts to PrivaScan. Depending on the platform, those facts can include file name, size, and cryptographic hash; app identifier, name, and version; permissions and purpose strings; packages, SDKs, libraries, or frameworks; tracker matches and supporting evidence; endpoint domains and URL samples; and component, signing, entitlement, privacy-manifest, security-configuration, diagnostic, and warning data. • App and report records, including platform, app identifier, a resolved policy URL when available, report and coverage data, content hash and version, cache source, holder-access token, and access-expiry data. • Report-delivery contact information, report revisions, monitoring snapshots, detected differences, drift events, and operational notices tied to requested features. • Browser and consent data. The first-party pp_consent cookie remembers a browser-local consent choice for up to 365 days. In the reviewed implementation, the bundled banner records the choice in pp_consent and emits configured callbacks and local browser events. Hosted logging occurs only through the separately configured integration described below. • Hosted consent-log data only when a site operator separately configures an integration and enables hosted consent logging for that site and origin. A received event can include the site identifier, consent action and preferences, country code, a truncated browser user-agent, and a pseudonymous visitor identifier derived from request network and browser data plus the site identifier. The identifier is pseudonymous, not anonymous, and an event received from a configured site is not independently authenticated proof of a person's identity or intent. • Technical request data used to deliver and protect the service, including IP address, request headers, route, browser information, timestamps, diagnostics, and rate-limit information. • Public-site analytics activity. The reviewed public scan detected Plausible Analytics on the public marketing surface, but its transmission list was empty, so this policy does not assert an exact field list for that scan. Reviewed product code limits analytics initialization to selected public marketing paths and applies additional guards to report, app-report, dashboard, admin, and account paths. • Correspondence content and related sender, recipient, and message information when a person communicates with PrivaScan. Information can come from a user, the user's browser, a submitted public website, public app-store listings and published policy pages, authentication and billing providers, service operations, monitoring activity, and communications with PrivaScan. Extracted app facts and holder-access reports can remain sensitive even when the original app binary stays in the browser. Purposes SaaS Factory LLC uses information to: • Provide accounts and requested features. • Scan submitted public URLs and extracted app facts. • Create, serve, maintain, and troubleshoot reports and policy drafts. • Locate a prior content-hash cache result where that product flow supports it. • Resolve public app-store disclosures and published policy links. • Operate optional monitoring, compare public-site changes, and send feature-related alerts. • Process purchases and maintain billing and entitlement status. • Send requested, transactional, support, privacy, and operational communications. • Receive, track, evaluate, and close privacy requests. • Record hosted consent events when a site operator has separately configured and enabled that integration. • Apply rate limits, prevent fraud or abuse, diagnose failures, and protect service reliability. • Review evidence and diagnostics to improve scan and drafting quality. • Respond to lawful requests, enforce applicable terms, and retain records when a verified legal, tax, accounting, security, or contractual requirement applies. Providers and Disclosures Provider involvement depends on the feature used and deployment configuration: • Supabase provides authentication, database, and storage functions for account, report, policy, consent, organization, billing-status, monitoring, retention, and privacy-request records. • Railway provides application hosting and supporting infrastructure. • Stripe provides checkout, payment processing, purchase or subscription status, and billing-portal functions when billing is configured and invoked. • Anthropic processes reviewed questionnaire answers, scan evidence, existing policy text, and drafting instructions when an AI-backed policy-parsing or supported policy-generation feature is invoked. • Plausible Analytics provides analytics for selected public marketing pages. The reviewed scan detected Plausible but did not establish specific transmitted fields, so this policy makes no claim about an exact transmission payload. • Resend delivers transactional or service email when its configuration is enabled and an email feature is used. • Google Fonts supplies typefaces used by the website; a visitor's browser connects to Google font hosts and sends ordinary network-request information. • Google Play and Apple App Store public lookup services receive an Android package identifier or iOS bundle identifier when app scanning resolves public listing metadata, privacy labels, or a published privacy-policy link. PrivaScan may also retrieve the publicly linked policy page from its publisher. • Google Workspace / Gmail processes and stores business correspondence sent to or from PrivaScan mailboxes. • Upstash provides distributed rate limiting only when its Redis configuration is enabled. The reviewed implementation uses a requester-IP-and-route-prefix key and Upstash analytics; otherwise the application uses an in-process limiter. • OpenAI Codex can be used by authorized PrivaScan personnel in a separate, controlled internal quality, debugging, and draft-review workflow. Codex is not the customer-invoked production policy generator, and its output is not published automatically. PrivaScan may also disclose information when required by law, to protect rights or safety, or in connection with a business transaction, subject to applicable requirements. Provider account settings, processing regions, contractual terms, retention periods, and model-training treatment were not established by the reviewed evidence and can differ by provider and configuration. Public Report Links Website and app reports use holder-access links. Anyone who has an active link can open the report and can share the link. Search-engine instructions are not access control. The reviewed production implementation expires public holder access for website and app reports 365 days after report creation, applies no-store and noindex protections, and supports earlier revocation for certain website reports by an authorized account holder or administrator. Access expiry prevents later public retrieval through that link; it does not itself delete the stored report record. Destructive full-report deletion has not been tested against live production data, so PrivaScan does not promise that every report can be immediately or automatically deleted. Users should not submit confidential URLs or place confidential information in a URL. A user should not select an app binary whose derived technical facts the user is not authorized to process. Retention, Deletion, and Monitoring Retention periods differ by category. Account, report, policy, publication, monitoring, billing, correspondence, security, consent, and operational records can have different needs and triggers. Legal holds, security investigations, disputes, and verified legal, tax, accounting, or contractual duties can require longer retention. Information may be deleted earlier when it is no longer needed. SaaS Factory LLC has selected 365 days as its default retention target unless a verified compliance obligation requires a different period. This target is not a promise that every category is deleted exactly 365 days after collection. The reviewed production release includes category-level retention metadata and purge operations, a 365-day public-report access horizon, a 365-day horizon for superseded hosted consent-log events, and lifecycle handling for website and app reports. A current consent decision may be retained longer as consent evidence while it remains current. The separate browser-local pp_consent cookie can last for up to 365 days. Provider-controlled records, logs, and backups can follow separate settings or obligations. Optional monitoring requires an explicit opt-in and performs recurring weekly scans of publicly accessible pages. The reviewed implementation stores monitoring snapshots and detected differences, sends change alerts to the account or paid-checkout email, and provides a signed stop-monitoring path with durable opt-out protection so later policy generation does not silently re-enable monitoring. Full report deletion can remove monitoring baselines and difference history. Because destructive deletion has not been exercised against live production data, this policy does not promise an immediate or universally available deletion outcome. Privacy Requests Depending on location and applicable law, a person may be able to request access, correction, deletion, or a portable copy of certain personal information; object to or restrict certain processing; withdraw consent where consent is the basis; or appeal a decision. Exceptions may apply. This policy does not determine which law or right applies to a particular person. Send a request to privacy@privascan.net and describe the account, report, or interaction involved and the action requested. The mailbox is monitored, and an external-origin delivery test verified that messages addressed to it can reach the monitored mailbox path. We may need to verify identity and authority before acting, especially because possession of a holder-access report link does not establish report ownership. SaaS Factory LLC targets a response within 30 calendar days as a voluntary company service target, not as a statement that every request has a 30-day statutory deadline. The reviewed production workflow supports minimized intake, administrative tracking, versioned state changes, closure evidence, and retention handling. We will use the period required by applicable law when it differs from the company target. Sale, Advertising, and Training SaaS Factory LLC does not sell personal information. SaaS Factory LLC does not use personal information for advertising. SaaS Factory LLC does not use customer questionnaire answers or customer policy content to train models. These owner-confirmed statements do not establish the retention, training, contractual, or account-setting practices of Anthropic, OpenAI, or another external provider. Verified Safeguards The reviewed deployed code contains authentication and access controls, database row-level permissions, input validation, request rate limiting, scanner safeguards intended to block private and reserved network destinations, security-related browser headers, and signed payment webhooks. The reviewed analytics guard narrows measurement to selected public marketing paths. Report access code includes expiry, revocation where supported, no-store, and noindex protections. These observations support a conservative description of the reviewed deployment only. They do not guarantee security, encryption of every stored field, a particular hosting region or transfer mechanism, a review frequency, or immunity from unauthorized access. No method of transmission or storage is completely secure. Report a suspected security issue to support@privascan.net. Children and Sensitive Data PrivaScan is a business service and is not designed for children. We do not claim that a verified age-screening control is present. If a parent or guardian believes that a child provided personal information to PrivaScan, that person can contact us so we can review the circumstances and respond as appropriate. Questionnaires, correspondence, scanned public pages, app technical facts, reports, and policy content can contain confidential, sensitive, or regulated information. Users should submit only material they are authorized to process and should avoid confidential material that is unnecessary for the requested feature. This policy does not assert that PrivaScan has identified every sensitive-data category or special rule that could apply. Changes SaaS Factory LLC may update this Privacy Policy as practices, providers, product behavior, and legal obligations change. A revised policy will show an updated date. We will provide additional notice when required by applicable law or appropriate to the significance of a change. Contact SaaS Factory LLC PrivaScan 1209 Mountain Road Pl NE, Ste R Albuquerque, NM 87110 United States Email: privacy@privascan.net