Skip to content
✕PreflightX Back to PreflightX ↗

PREFLIGHTX / LEGAL

Privacy Policy

How we handle account information, scan data and your privacy rights.

Effective Date: September 24, 2026
Last Updated: September 27, 2026

PrivacyTermsRefundsAcceptable UseCookies
On this page
  1. 1. Information we collect
  2. 2. Why we use information
  3. 3. Legal bases in the EEA
  4. 4. Scan Data and Security Analysis
  5. 5. Personal Data in Scan Targets
  6. 6. Sharing and service providers
  7. 7. International transfers
  8. 8. Retention and deletion
  9. 9. Your privacy rights
  10. 10. Security
  11. 11. Children
  12. 12. Changes and contact

Questions about this policy?
hello@preflightx.io

ContentHub s.r.o. ("Company", "PreflightX", "we", "us", or "our") operates https://preflightx.io (the "Service"). We are the controller of personal information used to manage your account and respond to your support requests. Our role in relation to personal data in scan targets depends on the circumstances of the processing and applicable law. Our company and contact details appear below.

1. Information we collect

Account information

We process your email address, authentication and account identifiers, subscription or plan status, and account creation and activity timestamps. Supabase supports our account authentication and database services.

Scan information

We process submitted URLs or domains and the publicly accessible resources needed for scanning. Scan data can include findings, severities, security scores and grades, scan timestamps, technical metadata, saved scan history for registered users, and scan-to-scan verification metadata. Public resources and findings can incidentally contain personal information or exposed sensitive information.

Anonymous scans are processed to return results and are not added to a registered user's scan history. Reports may still be held in service storage as needed to provide the results and protect the Service. An anonymous scan does not mean that no technical data is processed.

Only submit apps, websites or systems you own or are explicitly authorized to test. Avoid submitting personal information, credentials or secrets in URLs or support messages unless necessary to resolve your request.

Payments and support

Stripe processes card and billing information for purchases. We receive the purchase or subscription status, transaction references, the amount and currency paid, a link to Stripe's receipt and limited billing details needed to provide and support your paid access. PreflightX does not receive or store full card numbers.

If you contact us or request updates about Pro, we process your email address and the information you provide, including relevant account or scan references, to respond to your request.

Technical information and aggregate usage

We process IP addresses and request timestamps for rate limiting and abuse prevention. Our application and hosting infrastructure may also process browser or device information and access, error and security logs where those are available. Referrer information may be received when supplied by your browser; it is not required for scanning.

We use first-party aggregate counters for events such as page views, scan activity and interactions with plan features. These counters do not store submitted URLs, IP addresses or session tokens. Essential session state helps avoid counting the same event repeatedly. We do not currently use optional third-party analytics cookies. See our Cookie Policy.

When enabled, we also use PostHog for limited, cookieless product analytics to understand how the Service is used, from a visit through scanning, account creation, verification and interest in Pro, and to improve it. We send only named product events, such as that a scan started or completed, with limited non-content details where relevant: plan category, scan grade, aggregate finding counts by severity, verification status and which area of the page a Pro button was in. We also send a page view when our main page loads and a page leave when you leave it, so we can measure visits, bounce rate and time on page. These carry only the page's address without any query string or fragment (for example, https://preflightx.io/), the domain name of the site that linked to it, if any (not the full linking address), and, on leaving, time on the page and how far it was scrolled. We do not intentionally send PostHog email addresses, account or authentication identifiers, submitted URLs or domains, query strings or fragments of page addresses, scan identifiers, finding content, technical evidence, remediation instructions, AI repair prompts or secrets. Automatic click tracking, form capture and session recording are disabled.

This analytics configuration does not store an analytics identifier in cookies, local storage or session storage. As part of delivering each request, PostHog receives your IP address and browser user-agent, and combines them with a salt that PostHog rotates daily to derive a visitor identifier on its servers, so visits are not linked across days. Cookieless does not mean that no personal data is processed. Our integration does not load analytics when your browser sends a Global Privacy Control or Do Not Track signal. This analytics is subject to the legal bases and rights described below.

2. Why we use information

We use information to:

  • provide the Service, authenticate users and manage accounts;
  • perform scans, deliver reports, save registered users' history and compare scans or verify remediation;
  • provide Free and Pro functionality and administer subscriptions when paid billing is enabled;
  • prevent abuse, fraud and unauthorized security testing, and protect users and the Service;
  • troubleshoot errors, provide support and improve service quality;
  • meet legal obligations and establish, exercise or defend legal claims.

3. Legal bases in the EEA

We rely on contract performance where processing is necessary to provide the Service you request; legitimate interests in maintaining, securing and improving the Service, subject to your rights and interests; legal obligations where applicable; and consent where required. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.

4. Scan Data and Security Analysis

Our current URL scanner performs read-only checks against publicly accessible resources and does not intentionally modify target applications. It makes network requests to analyze the submitted target; public accessibility alone does not establish authorization to test it.

Results are informational and may contain false positives, false negatives or incomplete findings. A score or grade is not a certification of security. You remain responsible for reviewing findings, testing proposed changes, remediating issues and obtaining appropriate professional security testing.

5. Personal Data in Scan Targets

Submitted URLs and publicly accessible resources may incidentally contain personal data relating to third parties. You are responsible for ensuring that you are authorized and have a lawful basis to submit the target and any such data for scanning.

PreflightX processes such information only as necessary to perform the requested scan, provide the report, maintain authorized scan history and comparisons, protect the Service, prevent abuse, and comply with law.

Avoid submitting personal data, credentials, secrets, or sensitive information in URLs or support messages unless necessary for the requested scan or support.

6. Sharing and service providers

We do not sell personal data or share it for cross-context behavioral advertising.

We use Supabase for database and authentication services and Render for hosting. These providers process information needed to operate their services. Stripe will process payments and related fraud-prevention information when paid billing is enabled and you use payment features.

When cookieless analytics is enabled, PostHog processes the limited analytics information described above for us. See PostHog's Privacy Policy.

We may disclose relevant information to professional advisers or authorities where needed to comply with law, respond to valid legal requests, prevent fraud or abuse, or protect rights and safety. If our business is reorganized, acquired or transferred, relevant information may be transferred with appropriate safeguards and any notice required by law.

7. International transfers

Our company is based in Slovakia. Some service providers may process information outside the European Economic Area. Where legally required, transfers must be supported by appropriate mechanisms, such as an applicable adequacy decision or approved contractual safeguards. Contact us for information about safeguards relevant to your data.

8. Retention and deletion

We keep personal information only for as long as reasonably necessary for the purposes described here, considering account status, service delivery, security, fraud prevention and applicable legal obligations. Different records may be needed for different periods; we do not promise a single fixed retention period for all data.

You may request account or data deletion at hello@preflightx.io. We may verify your identity and retain information where lawful and necessary for security, fraud prevention, legal obligations or legal claims. Backup copies may remain until their normal replacement cycle, subject to appropriate restrictions.

9. Your privacy rights

Depending on applicable law, EEA individuals may request access to personal data, correction, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests and withdraw consent where processing relies on it. These rights have legal conditions and exceptions.

Contact hello@preflightx.io to exercise your rights. You may complain to your local supervisory authority or Slovakia's Úrad na ochranu osobných údajov SR at dataprotection.gov.sk.

Residents of certain US states may have rights to access, correct or delete personal information, obtain a copy, or appeal a decision where applicable law provides them. Applicability depends on the law and circumstances; we do not represent that every state privacy law applies to PreflightX. We do not sell personal information or share it for cross-context behavioral advertising, and we do not discriminate against you for exercising applicable privacy rights.

10. Security

We use reasonable safeguards designed to protect information, including HTTPS/TLS for the hosted Service, authentication controls, HttpOnly authentication cookies, and database access controls, including row-level security where applicable. Administrative access is restricted to authorized operators. No internet service or security measure can guarantee absolute protection.

11. Children

The Service is intended for people aged 18 or older. We do not knowingly collect personal information from children under 18. Contact us if you believe a child has provided personal information so we can investigate and take appropriate action.

12. Changes and contact

We may update this policy as the Service or legal requirements change. We will update the date above and provide additional notice where required. For privacy questions or requests, contact the company below.

Company & contact

ContentHub s.r.o.
Banícka 703/16
990 01 Veľký Krtíš
Slovak Republic
IČO: 56508395

Email: hello@preflightx.io
Website: https://preflightx.io

✕PreflightX

A safer internet starts with you.

GuidesPrivacyTermsRefundsAcceptable UseCookiesContact
© 2026 PreflightX