Privacy Policy

Learn how Snyfer.com collects, uses, and protects your personal information.

Last updated: September 9, 2026

Introduction

Snyfer.com ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website snyfer.com and use our services.

By using Snyfer, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Website Security Scans

When you use our scanning tools, we collect:

  • URLs submitted for scanning: The domains and URLs you enter are processed through our security analysis engine
  • Scan results: Security analysis results (antivirus findings, regulatory checks, SSL status, etc.) are stored and may be published as public scan pages
  • Scan metadata: IP address and timestamp for rate limiting purposes

Scan results may become publicly available as scan pages at snyfer.com/scan/{domain}. These pages contain information about the scanned website, not about the user who initiated the scan.

Account Registration

When you create an account, we collect:

  • Email address: Used for authentication and communication
  • Display name: Shown alongside your community feedback
  • Authentication data: Account authentication is handled by Supabase, including email/password sign-in and Google sign-in.
  • Scan history: Scans submitted while signed in can be linked to your account so you can find them in My scans. Business data, including scans and reports, is stored on our VPS infrastructure.

Community Reports

When you submit a report, we collect the website, experience type, your description and any supporting identifiers or evidence you provide. The submission is linked to your account for moderation and your private report history.

Reports are reviewed before publication. You can choose an anonymous public byline or be named. Information you include in the report may become public if it is approved; do not submit passwords, private keys or unrelated personal information.

Contact Form

When you contact us, we collect:

  • Contact information: Your name and email address
  • Message content: Inquiry type, optional organization, and message body

Newsletter

When you request newsletter updates, your email address is sent to our inbox for handling. This form does not automatically create an account or enroll you in an automated mailing platform. Contact us to withdraw your request.

Revision Requests

Website owners or users can request corrections to report pages. We collect:

  • Contact email: To follow up on the request
  • Request details: Domain, type of correction, message, and supporting evidence URLs

Scam Support Cases

When you send a case through our scam support form, we collect:

  • Contact information: Your first name, last name, email address and phone number. All four are required, because a case we cannot reply to or call back is one we cannot act on
  • Case details: The approximate amount you lost, your own description of what happened if you choose to write one, and the domain you came from if you arrived from one of our report pages
  • Contact consent: Whether you agreed to be contacted by email and SMS. This is optional and is not a condition of receiving a reply

Automatically Collected Information

When you visit our website, we automatically collect:

  • Technical and security data: Requests pass through Cloudflare and our hosting infrastructure, which process connection information such as IP addresses, request headers and timestamps for delivery and abuse prevention.
  • Browser storage: The application uses session and request-protection cookies and stores your display preference. See the Cookie Policy.

How We Use Your Information

We use the information we collect to:

  • Provide our services: Process scans, generate report pages, and publish community feedback
  • Communicate with you: Respond to contact form submissions, send newsletter updates, and notify you about your account
  • Prevent abuse: Rate limit excessive usage, detect abusive submissions, and protect against automated abuse
  • Improve our services: Analyze usage patterns to improve our tools and user experience
  • Ensure security: Log security-sensitive actions for audit purposes

Data Sharing with Third Parties

We share your data with the following third-party services:

ServicePurposeData Shared
Cloudflare Email ServiceDelivery of contact messages and newsletter signup notifications to our inboxEmail addresses, names and submitted message content
SupabaseAccount authenticationAccount email, profile and authentication data
HetznerVPS hosting for Snyfer and its databasesStored application data and server request data
Google GmailOperator inbox receiving form notificationsContact messages and newsletter requests delivered to our inbox
CloudflareNetwork delivery, access control and Turnstile abuse preventionIP address, request headers, connection/browser signals and verification tokens

We do not sell your personal data to third parties.

A case sent through the scam support form is handled by our own support desk so that somebody can reply to it and call you back. If you agree to be contacted, that reply may come by email or SMS.

Data Retention

Public scan evidence and published reports are retained as a historical record unless removed following review. Account information and private scan/report history are retained while the account is maintained; contact us to request access, correction or deletion.

Contact messages and newsletter requests are delivered to our inbox. Support cases and moderation records are stored for handling and follow-up. These records do not currently have a uniform automatic twelve-month deletion rule. Requests for deletion are reviewed manually, including any information that needs to be retained for an ongoing dispute or security investigation.

Rate-limit counters use different windows depending on the operation, from one minute to twenty-four hours. A counter resetting is separate from removal of server logs. Operational logs rotate according to their configured age or size; moderation and audit records are separate from these logs.

Automatic database backup rotation is configured for seven days for PostgreSQL and twenty-eight days for graph backups. Separately created maintenance backups can remain longer. Removing a record from the live system does not immediately remove it from every backup or email copy; these copies must be considered when handling a deletion request.

Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • Encryption in transit: All connections use HTTPS/TLS
  • Restricted storage access: Application databases are hosted on our server infrastructure with controlled access
  • Input validation: All form inputs are validated and sanitized using Zod schemas
  • CSRF protection: All form submissions require CSRF tokens
  • Rate limiting: Per-IP limits on all forms to prevent abuse
  • Security headers: CSP, HSTS, and other protective headers configured
  • Access control: Admin-only access to sensitive data, role-based permissions

Your Rights

Under applicable data protection laws (including GDPR), you have the right to:

  • Access your personal data: Request a copy of the information we hold about you
  • Rectification: Request correction of inaccurate personal data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Object: Object to processing of your personal data
  • Data portability: Request your data in a structured, machine-readable format
  • Withdraw consent: Withdraw consent for analytics tracking at any time (see Cookie Policy)

To exercise any of these rights, contact us at [email protected] or through our contact form. We will respond within 30 days.

Children's Privacy

Snyfer is not intended for use by children under the age of 18. We do not knowingly collect personal information from minors. If you believe we have collected data from a minor, please contact us immediately.

International Data Transfers

Your information may be processed in countries other than your country of residence. Our service providers (including Supabase, Cloudflare, Hetzner and Google) may process data in various jurisdictions. We ensure appropriate safeguards are in place for any international data transfers.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Optional audience measurement

With your agreement, Google Analytics processes usage information about public pages to help understand site traffic. Analytics is not loaded before acceptance. The integration does not send form contents, account identifiers, URL query parameters or fragments. You can withdraw through Cookie settings. Google may process this information on its infrastructure outside your country. See the Cookie Policy and Google Privacy Policy.