Scan a site →

Your information

Privacy notice

This Privacy Notice describes the current SafetyVibe hackathon prototype and its processing of personal data.

Last updated: 04/10/2026

Who is responsible

Controller: SafetyVibe Hackathon Team.
Privacy contact: safetyvibe@advertis.ee

Information processed during a public URL scan

The service processes the URL you submit and fetches the public page plus selected same-origin assets to run the requested checks. The submitted URL may contain a path or query string; do not include private tokens, personal data or secret values in it.

For service analytics, the server stores the target URL and host, timestamp, scan success/error, duration, scores, severity counts, engines run or skipped, detected technologies, Supabase/secret-detection flags, the request User-Agent, and a shortened SHA-256 hash of the visitor IP. The analytics event does not store full finding text or fetched response bodies.

Saved and shareable reports

After a successful scan, SafetyVibe automatically saves a report containing the target URL and host, findings, categories and engine results. The service returns a unique /r/<id> link. Anyone who has that link can view the report without signing in; it is not access-controlled by an account.

If you request a PDF, the generated PDF is also written to report storage. The current code does not automatically expire or delete saved JSON reports or PDFs. They remain until the operator removes them or deletes the storage volume. Treat a report link as shareable: do not scan URLs that contain private information, and do not distribute the link if the findings are sensitive. Report storage and analytics storage are separate records.

Feedback you send

If you use the feedback form, SafetyVibe stores the message you write, any email address you choose to provide, and the page URL you were on, and emails them to the team so we can read and respond. Your IP address is not stored with feedback. Please do not include passwords or other secrets in a feedback message.

Deep Supabase and MCP inputs

Deep Supabase tests are separate from a URL-only scan. They may process a Supabase project URL, a public anon/publishable key, and credentials for two owner-authorized test users. The hosted service receives inputs sent to its endpoint. Do not submit production passwords or privileged service-role keys.

The current deep-test route passes test credentials to a child CLI process as command-line arguments. Hosted MCP credential logging, retention and access controls have not been verified from this repository. Confirm those controls before enabling or using hosted deep tests with real credentials.

Purpose and legal basis

Scan data is processed to perform the website security scan requested by the user and to generate the scan report.

Limited technical metadata may be processed for service security, reliability monitoring and service analytics. Where applicable, processing for these purposes is based on the operator's legitimate interests in operating, securing and improving the service.

SafetyVibe is currently a hackathon prototype and does not offer paid services.

Retention, providers and transfers

Analytics, saved reports and generated PDFs may be retained for as long as reasonably necessary to operate and evaluate the hackathon prototype. The prototype does not currently implement an automatic deletion schedule.

Before production launch, the operator will define and implement specific retention periods for analytics, reports and generated PDFs. The hosting provider, storage location, processors and any third-party services used by the prototype will be identified and reviewed before production launch.

The service does not intentionally request or store private passwords, service-role keys or other secrets as part of a public URL scan. The site may use technical logs provided by the hosting infrastructure. Cookie and analytics practices will be reviewed before production launch.

Automated decision-making

SafetyVibe does not make decisions producing legal or similarly significant effects about individuals based solely on automated processing.

Your rights

Depending on the applicable law and circumstances, you may request access to, correction or deletion of your personal data, request restriction of processing, or object to processing. Where applicable, you may also have the right to data portability.

For privacy-related questions or requests, contact:
SafetyVibe Hackathon Team
Email: safetyvibe@advertis.ee

You may also lodge a complaint with the Estonian Data Protection Inspectorate.