Privacy Policy

Last updated: May 25, 2026

Exposd (“we”, “our”, “us”) operates the Exposd website and security scanning service. This policy explains what information we collect when you use our service, how we use it, and what rights you have over it.

1. Information We Collect

1.1 URLs You Submit

When you submit a URL for scanning, we record that URL and its root domain. We store this alongside your scan results to generate a permanent, shareable report page. We do not require you to create an account or provide any personal information to run a scan.

1.2 Scan Results

We store the output of each scan — the letter grade, score, and findings — in our database indefinitely. These reports are publicly accessible via their unique report URL (e.g.,frontguard.app/report/[id]). Do not submit URLs that you consider confidential or that reveal private infrastructure.

1.3 IP Addresses

We log your IP address solely to enforce our rate limit of 5 scans per IP per hour. IP addresses are not stored permanently and are not linked to scan reports in our database.

1.4 Email Addresses

If you join our waitlist, we collect your email address and optionally associate it with the scan report you were viewing at the time. We use this only to send product updates and launch notifications. We never sell or share your email with third parties for marketing purposes.

1.5 Usage Data

Our hosting provider (Vercel) may collect standard server logs including browser type, referring page, and general geographic region. We do not run any first-party analytics or tracking scripts. We do not use cookies except those strictly necessary for the service to function.

2. How We Use Your Information

  • To perform the security scan you requested and generate your report
  • To serve your report page to anyone you share the link with
  • To enforce rate limits and prevent abuse of the service
  • To send you product updates if you joined the waitlist
  • To understand aggregate usage patterns and improve the scanner

We do not use your submitted URLs, domains, or scan findings to train machine learning models, build advertising profiles, or sell insights to third parties.

3. Data Storage and Security

Scan reports are stored in a Supabase Postgres database hosted on infrastructure in the United States. We implement standard security measures including encrypted connections (TLS), access controls, and row-level policies. However, no system is perfectly secure. Do not submit credentials, internal IP addresses, or sensitive URLs you would not want stored.

The scanner makes outbound HTTP requests to the URL you provide on your behalf. We sanitize findings before storage — we do not store raw HTML or JavaScript bundle content from the scanned site.

4. Data Retention

Scan reports are stored indefinitely to support permanent shareable links. If you would like a specific report deleted, contact us at the email below with the report URL and we will remove it within 14 days.

Waitlist email addresses are retained until you unsubscribe. Every marketing email we send includes a one-click unsubscribe link. Unsubscribing removes you from future emails but does not delete your email from our database; contact us directly to request full deletion.

5. Sharing with Third Parties

We share data only with the infrastructure providers necessary to operate the service:

  • Vercel — hosts the application and handles HTTP requests. Vercel's infrastructure processes all web traffic.
  • Supabase — stores scan reports and waitlist entries. Supabase infrastructure is located in the United States.

We do not sell, rent, or otherwise disclose your data to advertisers, data brokers, or other third parties. We may disclose data if required by law or to protect against fraud or abuse.

6. Public Nature of Scan Reports

Each scan report is assigned a unique, unguessable UUID and is publicly accessible at its URL. Anyone with the link can view the report. We do not index report pages in search engines (they carry a noindex meta tag), but we cannot prevent someone you share the link with from further sharing it.

Only scan domains you own or have explicit authorization to test. Do not submit URLs containing sensitive query parameters or authentication tokens.

7. Children's Privacy

Exposd is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has submitted information to our service, contact us and we will delete it promptly.

8. Your Rights

Depending on your location, you may have rights including access to, correction of, or deletion of your personal data. To exercise any of these rights, email us at the address below. We will respond within 30 days. We do not discriminate against users who exercise their privacy rights.

If you are in the European Economic Area or United Kingdom, you have additional rights under GDPR/UK GDPR including the right to data portability and the right to lodge a complaint with your local supervisory authority.

9. Changes to This Policy

We may update this policy as the service evolves. If we make material changes, we will update the “Last updated” date at the top of this page. Continued use of the service after changes constitutes acceptance of the revised policy.

10. Contact

For privacy questions, deletion requests, or any concern about how we handle your data:

psbkkp777@gmail.com