Legal
Privacy Policy
Last updated: 29 July 2026
This policy explains what data VulnQuill (operated by Animesh Roy, India) collects,
why, and how it is handled. The short version: we collect the minimum needed to run the Service,
your security data belongs to you, and we never sell data to anyone.
1. What we collect
- Account data — name, email, password hash (bcrypt) or passkey public key, role, and
organization membership.
- Content you create — engagements, findings, evidence files, comments, reports, and
client-portal records. This may include your clients' confidential security information; you are
the controller of that content, we process it on your behalf.
- Operational data — activity logs (who did what, for audit trails), IP-derived
rate-limiting counters, and error telemetry with personal data scrubbed before storage.
- Billing data — plan, payment status, and Razorpay payment references. Card/UPI details
are handled entirely by Razorpay and never touch our servers.
2. What we do NOT do
- No selling or renting of data. No advertising, no trackers, no third-party analytics cookies —
the only cookies are session cookies required for sign-in.
- AI features run only when your organization's admin configures a provider; finding text is sent
to that configured provider (or your own self-hosted model) only when you invoke an AI action.
3. Where data lives & subprocessors
- Hosting & database — self-managed infrastructure; encrypted database backups stored
on Cloudflare R2.
- Cloudflare — DNS, tunnel, and content delivery.
- Resend — transactional email (verification, invites, password resets, notifications).
- Razorpay — payment processing.
- AI providers (optional, org-configured) — Anthropic, Google, OpenAI, or a self-hosted
Ollama instance.
4. Security
Organization-scoped tenancy enforced in every server action, nonce-based Content-Security-Policy,
passkey/WebAuthn sign-in with step-up verification for sensitive actions, bcrypt password hashing,
login lockouts, single-use hashed reset tokens, API keys stored hashed, provider keys encrypted at
rest (AES-256-GCM), and append-only audit logs.
5. Retention & deletion
Data is retained while your account is active. On request we will export and then permanently
delete your organization's data. Encrypted backups age out on a rolling schedule after deletion.
6. Your rights
You can access, correct, export, or delete your personal data. Email
mail@anir0y.in and we will respond within 30 days. If you are in
the EU/UK, these rights map to GDPR Articles 15–20; we act as processor for content your
organization stores about third parties.
7. Changes
Material changes to this policy will be announced in-app or by email before they take effect.
8. Contact
Privacy questions and requests: mail@anir0y.in.