Privacy Policy
Last updated July 22, 2026
This explains what vandel collects, why we collect it, and who else touches it. Scan results describe weaknesses in your application, so we treat them as confidential and keep the data we hold to what the service actually needs.
What we collect
- Account. Your email address and authentication identifiers, handled by our auth provider. We never see or store your password.
- Targets. The hostnames and URLs you submit, plus the ownership-verification token issued for each one.
- Scan data.Requests our scanner and agent made to your application and the responses they got, the findings derived from them, and the report we generate. This can include fragments of your application's content, headers, and configuration, and may incidentally include sensitive values that your application exposed, since exposing them is often the finding itself.
- Billing. Subscription status and the identifiers our payment processor gives us. We never see or store your card number, Stripe handles that directly.
- Operational logs. Ordinary server logs needed to run and debug the service.
Why we use it
To run the scans you ask for, show you results, email you reports, bill you, keep the service working, and enforce the ownership gate that stops vandel being pointed at systems you don't control. We don't sell your data, and we don't use your scan results to advertise to you.
Who else touches it (subprocessors)
We use these providers to operate the service, and your data reaches them only for that purpose:
- Anthropic, which runs the AI agent. On paid scans, content retrieved from your application is sent to Anthropic's API so the agent can reason about it. This is the most significant disclosure here, and it is what makes the agent scan possible.
- Supabase, database and storage for accounts, targets, and reports.
- Clerk, authentication.
- Stripe, payments.
- Resend, sending your report emails.
- Vercel, hosting.
We may also disclose data if legally required, or to protect the rights and safety of users or the public. If vandel is ever acquired or merged, data may transfer as part of that, subject to this policy.
Retention and deletion
We keep scan reports so you can see history over time. You can delete a target and its associated reports from the dashboard, and you can ask us to delete your account and everything tied to it by emailing us. We'll action deletion requests within 30 days, except where we're required to retain billing records for tax or accounting purposes. Ownership grants expire on their own after 30 days.
Security
Data is encrypted in transit. Reports are stored in a database with row-level security enabled and no public access policy, reachable only by our server-side credentials. We follow the same practices we tell customers to follow, because it would be embarrassing not to. No system is perfectly secure, and we can't guarantee absolute security.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. Email us and we'll help. We won't discriminate against you for exercising these rights.
Children
vandel is not directed to children, and we don't knowingly collect personal data from anyone under 13.
Changes
We may update this policy. If a change is material we'll give notice before it takes effect.
Contact
Privacy questions or a deletion request: support@vandel.dev.