Not publishable yet — T-01, T-06
This page still contains unfilled placeholders. It is delivered in this state on purpose: the code is finished, the legal text is not. Open items:
- T-01
- T-06
Privacy policy
This page covers the free surface check at http://134.122.72.232 and the commercial follow-up that may come after it. It does not cover the rest of the Root92 website.
Two things are worth saying before the details, because they are the two questions people actually have.
- If you only run the check and never fill in the form, we do not keep you as a contact: no email, no lead, nothing anyone will write to you about. One line does get recorded — which address was checked, when, from which IP and browser, and how it ended — because a tool that reaches other people’s sites has to be able to show who asked it to. It is described under “Your IP address” below.
- What we scan is the public surface of the app you submitted. We never read your database, and we never use any key we find. The scanner is described in full at http://134.122.72.232/about-scanner.
Who is responsible
Data controller: TODO(gabriel) T-01 — legal name, VAT number, registered address.
For any request about your data, write to: TODO(gabriel) T-01 — privacy contact address.
What we collect, exactly
When you submit the contact form, we store one row with these fields and nothing else:
url— the address of the app you asked us to check.email— the address we reply to.problem— which of five fixed codes you picked (slow,security,cost_lockin,ownership,other). We store the code, not the translated label.lang— the language the page was in, so we answer you in it.consent, plus the timestamp of the row and the version of the consent text you read (currentlyen-2026-08). This is the proof that you authorised the scan.detections— the technical result of the check: which technologies were detected, which security headers were present, sizes and timings. Metadata only. Never page content, never any data from your database.scoreand the status of the scan.
That is the whole list. There is no field for anything else, so there is nothing else to collect by accident.
Your IP address
Your IP address is used for two things, and they are separate.
- Rate limiting, so the tool cannot be turned into a way of hammering someone else’s site. The limits are 20 checks per hour per IP address and 3 per hour against the same target host. For this, it is kept in memory for an hour and then forgotten.
- A record of checks: every check leaves one row saying which address was checked, when, from which IP and browser, and how it ended. This is how we can tell abuse from ordinary use before deciding to block anyone — blocking on thresholds invented without data turns away real customers.
That record does not live on the public server. It is written there for at most 24 hours, moved to the internal server, and deleted from the public one. It is kept for 12 months and then deleted.
Our server log keeps only a truncated prefix of it, alongside the target hostname and the outcome. It never contains your email address or the full address you submitted.
Why we are allowed to do this
There are three separate operations here, with three separate legal bases. They are deliberately not merged into one sentence.
- Running the scan on the app: your consent as its owner, or as someone authorised to have it analysed. That is the checkbox, and it is why we record which version of its text you read.
- Contacting you afterwards about the paid audit: legitimate interest in business-to-business communication, with your own request for the report as the context.
- Keeping the record of checks described above: legitimate interest in the security of the service. A tool that reaches other people’s sites has to be able to show who asked it to, and to notice when it is being misused.
TODO(gabriel) T-06 — to be confirmed with whoever drafts the final policy. The implementation does not change either way: we record proof of consent regardless.
How long we keep it
On the public server that runs the check: 24 hours, for everything, including the record of checks. A scheduled job deletes rows older than that, whether or not anything else has happened to them.
On the internal server we use to reply to you: 24 months from first contact for your contact details, and 12 months for the record of checks. Two different purposes, two different deadlines, two equivalent jobs.
These are fixed deadlines, not intentions. No elastic formula, no wording that could stretch to mean forever.
Who else sees it
The hosting provider of the public server: TODO(gabriel) T-01.
The hosting provider of the internal server: TODO(gabriel) T-01.
The email provider we use to reply: TODO(gabriel) T-01.
Nobody else. We do not use analytics, we do not set cookies, and there is no tracking script on this page or on the home page. The fonts are served from our own server, so loading this page does not tell any third party that you read it.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. You can also object to the commercial follow-up.
All of these go through one address: TODO(gabriel) T-01 — privacy contact address. We answer within one month, as the GDPR requires.
Deletion and opting out
Same address, and we do it by hand.
We are aware that a self-service button would be more convenient. We do not have one because the server holding your data is not reachable from the internet, which is a deliberate part of how this is built: exposing a public endpoint to delete records would mean exposing that server. Until that changes, an email is the honest option, and the one that actually works.