Effective 8 August 2026

Privacy

Lockvane is a security tool, so the least surprising thing it can do is hold as little about you as possible. A public scan needs no account and no name. An account needs an email address. Everything beyond that exists because you connected something and asked us to look at it.

01

A public scan asks nothing of you

You can analyse a URL without an account, and we do not ask who you are. To run the scan and stop it being abused we handle three things:

  • the address you submitted,
  • what that address publicly serves: pages, JavaScript and CSS files, and response headers, which is the same material any visitor receives, and
  • your IP address, used to rate limit scans and discarded once it is no longer needed for that.

We do not publish scan results and we do not sell them. A public scan is shown to whoever ran it. What we do when a scan reveals something serious about someone else’s application is set out in the disclosure policy.

02

What an account holds

An account exists so we can attach findings to you and keep them away from everyone else.

Email address
From the address you sign up with, or from Google if you chose Continue with Google. Used to sign you in and to send you findings.
Password
Only if you set one. It is handled by our authentication provider and stored as a hash. Lockvane never sees it.
Connected assets
Which Supabase projects, GitHub repositories, and domains you asked us to watch, and the access tokens that let us read them.
Findings and evidence
What each scan found, and the request and response that prove it. This is the product, and it is the most sensitive thing we hold.
Billing
Whether you are on a paid plan and how many deep-scan credits remain. Payment details are held by the payment provider, not by us.
03

What we never take

  • Card numbers. Payment pages are hosted by the payment provider and card details never reach a Lockvane server.
  • Write access you did not ask for. Connections are read-only by default. We ask for permission to change something only at the moment you tell us to apply a fix, and we do not store a write key.
  • Your code, when you sign in with GitHub. Signing in with GitHub gives us your email address. Reading a repository is a separate authorization that you grant separately and can revoke on its own.
  • Tracking across other websites. We do not run advertising trackers or sell audience data.
04

Who else touches it

Lockvane runs on other people’s infrastructure. These are the services involved and what each one sees. The ones marked optional are only reached if you choose them.

Cloudflare
Serves the website and the API. IP address and request metadata, in transit.
Supabase
Database, authentication, and server functions. Account email, connected asset identifiers, findings and their evidence.
Resend
Transactional email. Account email and the contents of the message being sent.
Stripe
Card payments. Billing details you enter with Stripe. Card numbers never reach Lockvane.
MonCashoptional
Mobile payments in Haiti. The payment reference and amount.
Googleoptional
Sign-in, only if you choose Continue with Google. Your email address and basic profile. Lockvane requests nothing else.
GitHuboptional
Repository scanning, only if you connect a repository. Repository contents Lockvane reads to scan them.

We add to this list before a new service starts handling your data, not after. If you want to be told when it changes, say so at privacy@lockvane.com and we will write to you.

05

How long we keep it

Findings and their evidence stay for as long as your account does, because the value of a finding is the comparison with the last scan: that is how Lockvane can tell you something regressed rather than just that it exists.

When you disconnect an asset we stop scanning it immediately. When you delete your account we delete the account, its connected assets, and its findings. Deleting an account cannot be undone, and it will not delete anything a payment provider is required to keep for its own accounting.

06

What you can ask for

  • A copy of what we hold about you.
  • A correction, if something is wrong.
  • Deletion of your account and everything attached to it.
  • That we stop sending you email that is not required to operate your account, which you can also do from any message we send.

Write to privacy@lockvane.com. We will answer within 30 days, and we will not ask you why.

07

Children

Lockvane is a tool for people running software in production. It is not intended for anyone under 16, and we do not knowingly hold information about anyone under 16. If you believe we do, tell us at privacy@lockvane.com and we will remove it.

08

Changes to this policy

When we change what we collect or who we share it with, we change this page and move the effective date at the top. If the change is material and you have an account, we will email you before it takes effect rather than rely on you noticing.

Questions about any of it: privacy@lockvane.com.