Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how Kraftwire Software ("we", "us", "our") collects, uses, and protects your information when you use SimplyScan ("Service"), including its security scanning, speed optimization, and uptime monitoring features.
1. Information We Collect
Account Information
When you create an account, we collect your email address. You may sign up using email and password, or through a social sign-in provider (Google or Apple). We use your email for authentication, scan history association, and service communications. Your profile may also include an optional display name and avatar image that you choose to upload.
Social Sign-In (Google, Apple)
When you sign in with Google or Apple:
- We receive your email address and basic profile information (name) from the provider.
- We do not access your contacts, calendar, drive, files, or any other account data.
- Social sign-in data is used exclusively to create and authenticate your account.
Tokens. We do not store OAuth tokens long-term; your session is managed via secure, short-lived session tokens.
Independence. SimplyScan (operated by Kraftwire Software) is not affiliated with, endorsed by, or sponsored by Google LLC or Apple Inc. Social sign-in is offered purely as an authentication convenience, and your use of it is also subject to those providers' terms and privacy policies. You are responsible for maintaining the security of the third-party account you use to sign in.
Google User Data Disclosure
SimplyScan's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes requested:
- email · Your Google account email address
- profile · Your name
- openid · Authentication identity verification
We do not request access to your Google Drive, Gmail, Calendar, Contacts, or any other Google services. Google user data is not used for advertising, analytics, profiling, or training AI/ML models · only for authentication and account identification. We do not sell, share, rent, or transfer your Google user data to any third parties, except as required by law.
Payment Information
Payments (Pro Reports and Pro Monitoring subscriptions) are processed through Stripe. We do not store your credit card number, CVV, or billing address. Stripe handles all payment data in accordance with PCI DSS standards. From Stripe we receive and store the payment status, a transaction reference, and the billing email address associated with the purchase, so we can link purchases and subscriptions to your scans and account.
Scan Data
- URL Scans: We analyze the publicly served output of your application (HTML, JavaScript, HTTP headers, configuration files) · the same content any visitor to your URL can already see. We store the scanned URL and the scan results (findings, score, summary). Scans run while signed in are associated with your account; you can also run free scans without an account and attach them to your account when you later sign in.
- Request metadata: We log the IP address that requested each scan. We use this for rate limiting (free scans are limited per IP per day), abuse prevention, and to attribute anonymous scans and rescans to their owner.
- Speed Optimization Scans: Speed analysis examines publicly visible JavaScript bundles, HTTP responses, and resource loading patterns · no additional data beyond what is publicly accessible is collected or processed.
- GitHub Repo Scans (Pro): We fetch and analyze files from your public GitHub repository during the scan. We do not permanently store your source code. Source files are processed in memory during the scan and discarded after results are generated. Only the scan findings and metadata are retained.
- MCP server: Scans started through our MCP server (from AI tools such as Claude, Cursor, or Windsurf) are processed and stored exactly like scans started on the website.
- Verification pages & trust badges: If you enable a trust badge or share a scan verification link, the scanned site's hostname, score, and scan date become publicly visible on that page and badge. Full findings are never shown publicly.
Usage Data
We use Google Tag Manager (GTM) to manage analytics tags. The tags loaded through GTM are Google Analytics 4 and Microsoft Clarity, which may collect usage data such as page views, device type, and browser information. These tags load only after your first interaction with the page (scroll, tap, or keypress) · never on initial page load · and not at all if you have chosen "Essential only" in our cookie banner. We do not use browser fingerprinting, and we do not sell your data to advertisers or data brokers.
Session Recording and Heatmaps
Microsoft Clarity records session replays and heatmaps: the pages you open, how far you scroll, and where you click. Clarity runs in strict masking mode, which masks all text inside your browser before anything is sent · Microsoft does not receive the text displayed on the page, nor anything you type into a field. A replay shows the layout of the page and where you moved and clicked, with the text blanked out.
This matters most for our free tools. Our client-side tools (JWT debugger, hash and password generators, environment-file linter, and the other browser-only utilities) process what you paste entirely on your device. Nothing you enter into them is transmitted to us, and strict masking means it is not captured in a Clarity recording either.
Clarity does not load if you choose "Essential only" in our cookie banner. You can also read Microsoft's Privacy Statement.
Free Tools Usage Data
When you run one of our free live-check tools (SSL checker, security headers, email security, DNS security, SEO checker, AI visibility, CORS tester, security.txt validator, exposed files scanner), we log the domain or URL you checked, the result summary (score or grade), your IP address, browser user-agent, referring page, and a timestamp. We use this for rate limiting, abuse prevention, and to understand which tools help and how results improve over time. Our client-side tools (generators, converters, debuggers) run entirely in your browser · nothing you enter into them ever leaves your device; we record only that the tool was used.
Uptime Monitoring & Status Pages
If you use Pro Monitoring, we store the monitors you configure (the monitored URL and its name) and the results of the automated checks our infrastructure performs against them roughly every five minutes. Check history is retained for 95 days and then automatically deleted. Status pages are visible publicly only for monitors you choose to make public; a public status page shows the monitor's name, current status, and recent uptime to anyone with the link.
Emailed Reports & Email Delivery
You can email a scan report to an address you enter; we store that recipient address as part of our email delivery log (recipient, template, and delivery status), which we keep for transactional and newsletter email so we can trace delivery problems and honor unsubscribes. Report and newsletter emails are sent from notify.simplyscan.io via our email delivery provider.
Feedback
Our in-app feedback widget is provided by Feedback Fish. Feedback you submit · and, if you are signed in, your account email address · is processed by Feedback Fish solely to deliver the feedback to us.
Workflow Integrations (Slack, GitHub, Linear)
If you connect Slack, GitHub, or Linear, we store the webhook URL, token, or API key you provide and use it solely to send scan findings to that service when you ask us to. You can remove a connected integration at any time, which deletes the stored credential.
2. How We Use Your Information
- To provide and deliver security scan and speed optimization reports.
- To maintain your scan history and dashboard.
- To run uptime monitoring and deliver findings to the integrations you configure.
- To process payments for Pro Reports and Pro Monitoring subscriptions.
- To enforce rate limits and prevent abuse of the Service.
- To respond to support requests.
- To improve the Service's accuracy, features, and speed optimization analysis.
- To send you product updates, new features, security tips, and service announcements.
3. Data Sharing
We do not sell or rent your personal information. We share data only with the service providers needed to operate SimplyScan, and only to the extent necessary:
- Stripe: For payment and subscription processing.
- AI providers: Scan content (the publicly served output of the scanned URL, or repository source files during a Pro repo scan) is sent through an AI gateway to large-language-model providers · currently Google Gemini models · for analysis. No personally identifiable information is included in AI requests beyond the content being scanned.
- Analytics: Google (Tag Manager, Analytics 4) and Microsoft (Clarity) receive usage data through the tags described in Usage Data above. Microsoft Clarity also receives session replay and heatmap data, with all page text masked in the browser before it is sent.
- Feedback Fish: Processes in-app feedback you submit.
- Your integrations: If you connect Slack, GitHub, or Linear, scan findings are sent to that service at your request.
- Infrastructure & email delivery: Our hosting, database, and email providers process data on our behalf on the certified infrastructure described in Data Security.
- Legal obligations: If required by law, regulation, or valid legal process.
4. Data Retention
- Account data: Retained while your account is active. Deleting your account from Settings permanently removes your account, profile, and scan history. Any active Pro Monitoring subscription stops renewing and ends at the end of the current billing period; no refund is given.
- Scan results: Retained for your scan history while your account is active. You may request deletion of individual scans (including anonymous scans) by contacting support.
- Source code (repo scans): Not stored. Processed in memory during the scan only.
- Uptime check history: Retained for 95 days, then automatically deleted.
- Payment records: Retained as required for accounting and legal compliance.
- Free tools usage logs: Retained for 12 months, then automatically deleted.
5. Data Security
We implement robust security measures to protect your personal data. SimplyScan and all associated Kraftwire products are built on and exclusively use infrastructure that is SOC 2 Type 2, ISO 27001:2022 & GDPR certified. These certifications are held by our infrastructure providers · not by Kraftwire Software directly.
Our security measures include:
- Encryption at rest: AES-256 encryption for all stored data.
- Encryption in transit: TLS 1.3 for all data transmission.
- Row-level security: Fine-grained database access controls ensuring users can only access their own data.
- Infrastructure auditing: Our infrastructure providers undergo continuous independent security audits to maintain their certification compliance.
- Regular security assessments: Penetration testing and vulnerability scanning.
- Access controls: Role-based access with principle of least privilege.
- Incident response: Documented procedures for security incident handling.
While no method of transmission over the Internet is 100% secure, we strive to use commercially acceptable means to protect your personal data in accordance with the security standards provided by our certified infrastructure.
6. Communications & Newsletter
Essential Account Communications
These are required for the operation of your account and cannot be opted out of while your account is active. They include: password resets, email address changes, account security alerts, account deletion or freezing notices, billing confirmations, and service disruption notifications.
Product Updates & Newsletter
By creating an account or subscribing to our newsletter, you agree to receive product news, new feature announcements, security tips, and promotional content. The newsletter is double opt-in: when you subscribe, we send a confirmation email to verify your address, and you only start receiving the newsletter after you click the confirmation link. If you subscribe while signed in with the same verified email address, your subscription is confirmed immediately without a separate confirmation email. We store your email address, subscription status, and subscription date solely to send you the newsletter.
Opting Out & Deletion
You can unsubscribe at any time using the link in any newsletter email, or by emailing simplyscan@kraftwire.com. Unsubscribing is a soft delete: we mark your address as unsubscribed and stop emailing you, but retain a minimal record so we can honor your opt-out. To have your subscriber data permanently and fully deleted (a hard delete) · including if you subscribed without ever creating an account · email us or use the in-app feedback widget, and we will remove it. Opting out of marketing does not affect essential account communications.
7. Your Rights
You may:
- Request a copy of your stored data.
- Delete your account and associated scan data yourself at any time from Settings, or request deletion by contacting us.
- Opt out of product updates and newsletter emails as described in Communications & Newsletter. Essential account communications cannot be opted out of while your account is active.
To exercise these rights, contact us at simplyscan@kraftwire.com.
8. Cookies & Local Storage
We use essential cookies and browser local storage for authentication, session management, and interface preferences such as your theme choice. Analytics tags loaded via Google Tag Manager also set cookies: Google Analytics 4 sets cookies whose names begin with _ga, and Microsoft Clarity sets _clck and _clsk, as described in Usage Data. You can decline these non-essential tags by choosing "Essential only" in our cookie banner · they will not load for you · or block them in your browser settings, though this may affect some Service functionality.
9. Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect information from children.
10. Third-Party Platform Information
The Service may display publicly available information about the features and capabilities of third-party platforms for comparison purposes. This information is gathered from public sources such as official documentation, release notes, and marketing materials. We do not access private or proprietary data from any third-party platform. This comparison data is provided "as is" for informational purposes and may not reflect the most current state of any third-party product.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via the Service or email. Continued use after changes constitutes acceptance.
12. Contact
For privacy-related questions or data requests, contact us at simplyscan@kraftwire.com.