hackymacky

Policy

Privacy Policy

Effective 10 September 2026

Plain language for an opt-in scanner: public HTML and JS until you prove the domain, fingerprints instead of secrets, and a way to ask us to delete your account.

  1. 01

    Who runs this

    hackymacky is the security scanner at hackymacky.vercel.app. It is operated by an individual in Hungary (EU). There is no separate registered company name for this product - when these pages say we, they mean the operator of hackymacky.

    Contact: support@hackymacky.vercel.app. That is the address for privacy requests too.

  2. 02

    What we scan

    You opt in by pasting a URL or adding a project. We do not get git access, server SSH, or your Vercel/Supabase dashboards.

    Preview scan (no account): we fetch the public HTML and JavaScript any browser would download from that URL. We look for secret-like strings in those assets. If a public Supabase URL and anon key show up there, we probe what that anon key can list (REST resources, OpenAPI, storage buckets). We do not dump database rows.

    Verified deep scan (signed in, domain claimed): the same public-asset scan, plus anon-key Auth settings, public-profile, and admin-API posture probes. Finding titles are stored on your project. Deep scan runs only after you prove you control the hostname: DNS TXT hackymacky-verify=… or a file at /.well-known/security-scan.txt.

    We refuse private, loopback, and cloud-metadata addresses. Preview returns a score and up to three redacted finding titles. Nothing in that response is enough to rebuild a secret.

  3. 03

    What we store

    Depends on which path you used:

    • Preview: the URL, score, timestamps, and an audit row (URL, score, client IP for rate-limit / abuse). We do not persist preview findings or secret fingerprints.
    • Account: email, via magic-link auth (Supabase). No password.
    • Projects: URL, hostname, verification token, optional detected Supabase project URL, fingerprint of a public anon key (never the key itself).
    • Full scans: score, finding title/category/severity, SHA-256 fingerprint of evidence, a short redacted prefix, remediation, and a location hint (for example which script). Score history over time.
    • Finding triage (project owner): fixed or ignored status keyed by a stable finding identity (fingerprint, then code + title). Optional short note. Never secret plaintext or evidence dumps. Public reports and badges do not include triage.
    • Billing: Stripe customer and subscription IDs, plan, status, extra project quantity. Not card numbers.
    • Audit log of product actions (preview, verify, full scan, and similar).
    • Feedback form: the message, optional name and email, optional page URL, user agent, and (if you were signed in) your user id. We reject submissions that look like pasted API keys or private keys.
    • Regression alerts (optional): if Resend is configured, we email the account address when a later full scan shows a lower score or new/worsened critical/high findings. The message includes titles, finding codes, severity, and the score change — not secrets, fingerprints, or evidence.
    • Shareable report (opt-in): if you enable a share link on a verified project, anyone with that tokenized URL can see the latest score, score history, finding titles, severities, and remediations. The public page and PDF/Markdown exports never include plaintext secrets, evidence prefixes, verification tokens, or query row dumps. Revoking the link invalidates it.
  4. 04

    What we never store

    • Plaintext secrets. Fingerprint plus a short prefix only.
    • Query-result row dumps from anon probes.
    • Your source repo, env files, or dashboard credentials.
    • The Supabase anon key after the in-memory probe. We may keep a fingerprint of it on the project.
  5. 05

    Why we process this (GDPR)

    • Contract (Art. 6(1)(b)): running the scan you asked for, keeping your account, billing a subscription if you buy one.
    • Legitimate interests (Art. 6(1)(f)): stopping abuse, rate limits, understanding whether the product is used (see analytics below).
    • Legal obligation (Art. 6(1)(c)): keeping payment records if the law requires it.
  6. 06

    Who else sees data

    We use these processors to run the product:

    • Vercel: hosting and Web Analytics.
    • Supabase: magic-link auth and the database.
    • Stripe: checkout, customer portal, and invoices.

    They may process data outside Hungary, including the US, under their own terms and transfer safeguards. We do not sell your data.

  7. 07

    Analytics

    Every page loads Vercel Web Analytics. It is cookieless: no advertising cookie, no cross-site profile. It records page views, referrers, and coarse device / location using a request hash that resets daily. Details are on the Cookie Policy.

  8. 08

    How long we keep it

    Account, project, scan, and audit records stay while your account is active. Score history in the UI is the full stored history. That is a display window, not an automatic wipe.

    Preview URLs and IPs in the audit log are kept to limit abuse. There is no self-serve delete button yet. Email support@hackymacky.vercel.app and we will delete or export what we hold on you, unless we must keep a slice for security, billing, or law.

  9. 09

    Your rights

    If GDPR (or UK GDPR) applies to you, you can ask us to access, correct, delete, or restrict your data, to export it, or to object to processing based on legitimate interests. Email support@hackymacky.vercel.app. Magic-link sign-in is the account we have; we do not run automated decisions with legal effects.

    You can complain to the Hungarian authority (NAIH, naih.hu) or to your local EU supervisory authority.

  10. 10

    Children, changes

    The product is not aimed at children under 16. If we change this policy in a material way, we will update the date at the top of this page.