VulnQuill logoVulnQuill
Legal

Privacy Policy

Last updated: 29 July 2026

This policy explains what data VulnQuill (operated by Animesh Roy, India) collects, why, and how it is handled. The short version: we collect the minimum needed to run the Service, your security data belongs to you, and we never sell data to anyone.

1. What we collect

2. What we do NOT do

3. Where data lives & subprocessors

4. Security

Organization-scoped tenancy enforced in every server action, nonce-based Content-Security-Policy, passkey/WebAuthn sign-in with step-up verification for sensitive actions, bcrypt password hashing, login lockouts, single-use hashed reset tokens, API keys stored hashed, provider keys encrypted at rest (AES-256-GCM), and append-only audit logs.

5. Retention & deletion

Data is retained while your account is active. On request we will export and then permanently delete your organization's data. Encrypted backups age out on a rolling schedule after deletion.

6. Your rights

You can access, correct, export, or delete your personal data. Email mail@anir0y.in and we will respond within 30 days. If you are in the EU/UK, these rights map to GDPR Articles 15–20; we act as processor for content your organization stores about third parties.

7. Changes

Material changes to this policy will be announced in-app or by email before they take effect.

8. Contact

Privacy questions and requests: mail@anir0y.in.