Privacy Policy
Last updated: September 9, 2026
Introduction
Snyfer.com ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website snyfer.com and use our services.
By using Snyfer, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Website Security Scans
When you use our scanning tools, we collect:
- URLs submitted for scanning: The domains and URLs you enter are processed through our security analysis engine
- Scan results: Security analysis results (antivirus findings, regulatory checks, SSL status, etc.) are stored and may be published as public scan pages
- Scan metadata: IP address and timestamp for rate limiting purposes
Scan results may become publicly available as scan pages at snyfer.com/scan/{domain}. These pages contain information about the scanned website, not about the user who initiated the scan.
Account Registration
When you create an account, we collect:
- Email address: Used for authentication and communication
- Display name: Shown alongside your community feedback
- Authentication data: Account authentication is handled by Supabase, including email/password sign-in and Google sign-in.
- Scan history: Scans submitted while signed in can be linked to your account so you can find them in My scans. Business data, including scans and reports, is stored on our VPS infrastructure.
Community Reports
When you submit a report, we collect the website, experience type, your description and any supporting identifiers or evidence you provide. The submission is linked to your account for moderation and your private report history.
Reports are reviewed before publication. You can choose an anonymous public byline or be named. Information you include in the report may become public if it is approved; do not submit passwords, private keys or unrelated personal information.
Contact Form
When you contact us, we collect:
- Contact information: Your name and email address
- Message content: Inquiry type, optional organization, and message body
Newsletter
When you request newsletter updates, your email address is sent to our inbox for handling. This form does not automatically create an account or enroll you in an automated mailing platform. Contact us to withdraw your request.
Revision Requests
Website owners or users can request corrections to report pages. We collect:
- Contact email: To follow up on the request
- Request details: Domain, type of correction, message, and supporting evidence URLs
Scam Support Cases
When you send a case through our scam support form, we collect:
- Contact information: Your first name, last name, email address and phone number. All four are required, because a case we cannot reply to or call back is one we cannot act on
- Case details: The approximate amount you lost, your own description of what happened if you choose to write one, and the domain you came from if you arrived from one of our report pages
- Contact consent: Whether you agreed to be contacted by email and SMS. This is optional and is not a condition of receiving a reply
Automatically Collected Information
When you visit our website, we automatically collect:
- Technical and security data: Requests pass through Cloudflare and our hosting infrastructure, which process connection information such as IP addresses, request headers and timestamps for delivery and abuse prevention.
- Browser storage: The application uses session and request-protection cookies and stores your display preference. See the Cookie Policy.
How We Use Your Information
We use the information we collect to:
- Provide our services: Process scans, generate report pages, and publish community feedback
- Communicate with you: Respond to contact form submissions, send newsletter updates, and notify you about your account
- Prevent abuse: Rate limit excessive usage, detect abusive submissions, and protect against automated abuse
- Improve our services: Analyze usage patterns to improve our tools and user experience
- Ensure security: Log security-sensitive actions for audit purposes
Data Sharing with Third Parties
We share your data with the following third-party services:
| Service | Purpose | Data Shared |
|---|---|---|
| Cloudflare Email Service | Delivery of contact messages and newsletter signup notifications to our inbox | Email addresses, names and submitted message content |
| Supabase | Account authentication | Account email, profile and authentication data |
| Hetzner | VPS hosting for Snyfer and its databases | Stored application data and server request data |
| Google Gmail | Operator inbox receiving form notifications | Contact messages and newsletter requests delivered to our inbox |
| Cloudflare | Network delivery, access control and Turnstile abuse prevention | IP address, request headers, connection/browser signals and verification tokens |
We do not sell your personal data to third parties.
A case sent through the scam support form is handled by our own support desk so that somebody can reply to it and call you back. If you agree to be contacted, that reply may come by email or SMS.
Data Retention
Public scan evidence and published reports are retained as a historical record unless removed following review. Account information and private scan/report history are retained while the account is maintained; contact us to request access, correction or deletion.
Contact messages and newsletter requests are delivered to our inbox. Support cases and moderation records are stored for handling and follow-up. These records do not currently have a uniform automatic twelve-month deletion rule. Requests for deletion are reviewed manually, including any information that needs to be retained for an ongoing dispute or security investigation.
Rate-limit counters use different windows depending on the operation, from one minute to twenty-four hours. A counter resetting is separate from removal of server logs. Operational logs rotate according to their configured age or size; moderation and audit records are separate from these logs.
Automatic database backup rotation is configured for seven days for PostgreSQL and twenty-eight days for graph backups. Separately created maintenance backups can remain longer. Removing a record from the live system does not immediately remove it from every backup or email copy; these copies must be considered when handling a deletion request.
Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption in transit: All connections use HTTPS/TLS
- Restricted storage access: Application databases are hosted on our server infrastructure with controlled access
- Input validation: All form inputs are validated and sanitized using Zod schemas
- CSRF protection: All form submissions require CSRF tokens
- Rate limiting: Per-IP limits on all forms to prevent abuse
- Security headers: CSP, HSTS, and other protective headers configured
- Access control: Admin-only access to sensitive data, role-based permissions
Your Rights
Under applicable data protection laws (including GDPR), you have the right to:
- Access your personal data: Request a copy of the information we hold about you
- Rectification: Request correction of inaccurate personal data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Object: Object to processing of your personal data
- Data portability: Request your data in a structured, machine-readable format
- Withdraw consent: Withdraw consent for analytics tracking at any time (see Cookie Policy)
To exercise any of these rights, contact us at [email protected] or through our contact form. We will respond within 30 days.
Children's Privacy
Snyfer is not intended for use by children under the age of 18. We do not knowingly collect personal information from minors. If you believe we have collected data from a minor, please contact us immediately.
International Data Transfers
Your information may be processed in countries other than your country of residence. Our service providers (including Supabase, Cloudflare, Hetzner and Google) may process data in various jurisdictions. We ensure appropriate safeguards are in place for any international data transfers.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
- Email: [email protected]
- Web: Contact Form
- Response time: Within 30 days for data rights requests
Optional audience measurement
With your agreement, Google Analytics processes usage information about public pages to help understand site traffic. Analytics is not loaded before acceptance. The integration does not send form contents, account identifiers, URL query parameters or fragments. You can withdraw through Cookie settings. Google may process this information on its infrastructure outside your country. See the Cookie Policy and Google Privacy Policy.