Skip to main content

Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how seeshare LLC (“seeshare,” “we,” “us”) collects, uses, shares, and protects information when you visit seeshare.io or use the seeshare security scanning service (the “Service”). By using the Service you agree to the practices described here and to our Terms of Service.

This policy covers seeshare’s own practices. It does not cover the practices of websites you scan with the Service, and scan output about a website’s privacy or compliance posture is informational only — it is not a statement about how that website actually handles personal data.

1. Information We Collect

Account information

When you create an account we collect your name, email address, and a password (stored in hashed form). If you sign in with Google, we receive your name, email address, and basic profile information from Google. If you enable multi-factor authentication, we store the enrollment data needed to verify you. Organization accounts may also include branding you upload for white-label reports (logo, colors).

Billing information

Payments are processed by Stripe. Your full card details are provided directly to Stripe and are not stored on our servers. We store your Stripe customer and subscription identifiers, plan and billing status, and payment history metadata (amounts, dates, and outcomes).

Scan targets and scan data

When you add a website and run scans, we collect and store:

  • the domains and URLs you designate for scanning;
  • scan results, including findings, severities, evidence excerpts (portions of the scanned site’s pages, code, and server responses that demonstrate a finding), crawled URLs, detected technologies, and raw scanner output;
  • captured excerpts of scanned-site content used for analysis, such as homepage HTML, response headers, robots.txt, security.txt, sitemap files, and portions of the site’s JavaScript files;
  • consent records for certain scan types (for example, when you enable network port scanning we record the consenting user, timestamp, and IP address as part of the authorization trail).

Scanned-site content can incidentally include personal data that appears on the scanned pages. You are responsible for having the right to scan each target, as described in the Terms of Service.

Usage and device information

We collect log and usage data such as IP address, browser and device information, pages viewed, and actions taken in the Service. Errors and diagnostic events (which may include IP address and account identifiers) are collected through our error-tracking provider.

Communications

If you contact us, join a waitlist, or submit a form, we collect the information you provide (such as name, email, company, and message contents).

2. Cookies and Analytics

We use:

  • Essential cookies — authentication and session cookies required to sign you in and keep the Service secure; and
  • Analytics tags — we load Google Tag Manager, which may set Google Analytics and similar cookies to help us understand how the site is used.

You can control cookies through your browser settings; blocking essential cookies may prevent the Service from working. To opt out of analytics-based sharing of your information, see Section 8.

3. How We Use Information

  • to provide, operate, and secure the Service, including running scans you request and generating reports;
  • to process payments, manage subscriptions and scan credits, and prevent fraud and abuse;
  • to communicate with you about the Service, including scan notifications, receipts, and support;
  • to analyze usage and improve the Service, including in aggregated or de-identified form;
  • to enforce our Terms, maintain authorization records, and comply with law.

4. AI Processing

Some features send scan data to third-party artificial-intelligence model providers to generate analysis — for example, correlating findings, explaining an issue in plain language, or summarizing a report. The data sent can include finding details (titles, descriptions, evidence excerpts, URLs) and the captured scanned-site content described in Section 1. Our primary model provider is Anthropic; depending on configuration and the features you use, alternative providers (such as OpenAI or Zhipu AI) may process this data instead. These providers are engaged to process the data only to provide the analysis back to the Service and are not authorized by us to use it for other purposes.

5. How We Share Information

We do not sell your personal information. We share information with service providers that process it on our behalf to run the Service:

  • Supabase — database, authentication, file storage, and job queueing;
  • Vercel — application hosting;
  • DigitalOcean — scanning infrastructure and hosting for our WordPress content management system;
  • Stripe — payment processing;
  • Anthropic (and, where configured, OpenAI or Zhipu AI) — AI analysis (Section 4);
  • Google — Tag Manager/Analytics and BigQuery (analytics and reporting infrastructure);
  • Sentry — error tracking;
  • Resend — transactional email;

We may also share information:

  • via share links you create — if you enable a share link for a report, anyone with the link can view that report without logging in until the link expires or you revoke it;
  • for legal reasons — to comply with law, legal process, or enforceable government requests; to enforce our Terms; or to protect the rights, safety, or property of seeshare, our users, or others, including investigating suspected unauthorized scanning; and
  • in a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

6. Data Retention

We retain account information for as long as your account is active and as needed for the purposes above. Scan data is retained so you can view historical results; you can delete individual scans and targets in the product, which removes their associated results. When you close your account or ask us to delete your data (Section 8), we delete or de-identify personal information within a reasonable period, except where we must retain it for legal, billing, security, or dispute-resolution purposes (including scan-authorization consent records, which we may retain as evidence of authorization).

7. Security

We use reasonable technical and organizational measures to protect information, including encryption in transit, hashed passwords, access controls, and optional multi-factor authentication. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent.

  • Access, correction, deletion: you can update account details in the product and delete scans and targets you no longer want stored. For account deletion or any other request, email support@seeshare.io and we will respond as required by applicable law.
  • Marketing: you can opt out of non-essential emails using the unsubscribe link in the message.
  • Analytics / “sharing” opt-out (U.S. state privacy laws): our use of Google analytics tags may be considered “sharing” or targeted-advertising processing under some U.S. state laws. You can opt out by emailing support@seeshare.io or by using browser-level controls such as Global Privacy Control, which we honor where required.
  • EEA/UK (GDPR): our legal bases are performance of a contract (providing the Service), legitimate interests (securing and improving the Service, preventing abuse), consent where required, and legal obligations. You may lodge a complaint with your local supervisory authority.
  • California: we do not sell personal information and we do not use or disclose sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising your rights.

9. International Transfers

We are based in the United States and process information there and in other countries where our service providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers of personal data from the EEA, UK, or Switzerland.

10. Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to This Policy

We may update this policy from time to time. We will post the revised version with an updated “Last updated” date, and for material changes we may provide additional notice by email or in the product. Continued use of the Service after changes take effect constitutes acceptance.

12. Contact

Privacy questions or requests: support@seeshare.io.