Last updated 2 October 2026
Privacy Policy
What Vespez collects about you, why, who helps us process it, and how you stay in control.
Who is responsible
Vespez is a security and GDPR compliance scanner for web applications. It is operated by an individual founder based in Norway, who is the data controller for the personal data described here.
Contact for anything about your data: support@vespez.com. We answer within 30 days.
What we collect and why
Your account
- Email address and, if you sign up with a password, a protected (hashed) version of it. We never see or store the password itself.
- If you choose Continue with Google: the name, email address and profile picture link that Google shares with us at sign-in.
- Your first name, if you choose to give it, your plan (Free or Pro), your email settings and your time zone (used to send update emails in the morning where you are).
We use this to give you access to your account, verify your email address and send you the emails described below. Legal basis: performing our contract with you.
Scans and monitoring
- The URLs you scan, and for each scan the two scores, the findings and the passed checks.
- The sites you monitor on Pro: the address, the app type you chose, your ownership-verification token, which deploy service you connected, and an encrypted secret used to check that deploy notifications are genuine.
- Alerts created for you, and any share links you create for a report.
We do not store the HTML or JavaScript of the sites we scan. Vespez loads public pages the way a normal visitor would, reads them, and keeps only the scores and findings. If a public page happens to contain personal data, it is processed for the few seconds the scan takes and is not saved.
Legal basis: performing our contract with you.
Payments
If you upgrade to Pro, payment is handled by Stripe on Stripe's own page. Stripe collects your card details and billing information; we never see or store your card number. We store a Stripe customer reference, your subscription status and the date your current period ends. Legal basis: performing our contract with you, and our legal obligation to keep accounting records.
Preventing abuse
To limit how many scans can be run from one network, we count scans per IP address. The IP address is scrambled with a one-way hash before it is counted, and the counter is deleted after 24 hours. Our hosting provider also keeps standard server logs, which include IP addresses, for a short period. Legal basis: our legitimate interest in keeping the service secure and available.
Emails we send
- Account emails: verifying your address and resetting your password. These are always sent.
- Deploy alerts (Pro): when a re-scan finds a lower security score or a new critical issue.
- GDPR updates (Pro): at most one email a day with official publications that match your monitored sites.
You can switch deploy alerts and GDPR updates off in Settings or with the unsubscribe link in each email. We do not send marketing email.
Feedback and support
If you send feedback from the app or email us, we receive your message and your email address so we can reply. Legal basis: our legitimate interest in answering you and improving Vespez.
How AI is used
Part of a scan is done by Claude, an AI model from Anthropic. We send it the text of the scanned site's privacy, cookie and terms pages and a list of what our code detected on the page. For GDPR updates, we send it the text of official publications. We do not send your name, email address or payment details. Scores are calculated by our own code, not by AI, and no decision with legal effect on you is made automatically.
Who processes data for us
We use the services below to run Vespez. Each one processes data only on our instructions and under a data processing agreement. We do not sell your data or share it with anyone for advertising.
| Service | What it does for us | Where |
|---|---|---|
| Supabase | Database and sign-in (your account, scans, monitored sites, alerts) | EU (Ireland) |
| Vercel | Hosting; runs the app and the scans, and keeps short-lived server logs | EU (Ireland), company in the USA |
| Stripe | Payments and subscriptions (card details, billing address, invoices) | EU (Ireland) and USA |
| Resend | Sending email (verification, password reset, alerts) | EU, company in the USA |
| Upstash | Rate limiting (hashed IP counters) and queued re-scans | EU (Ireland) |
| Anthropic | AI review of policy pages from scanned sites and of official publications. Your account details are not sent. | USA |
| "Continue with Google" sign-in, if you choose it, and our support mailbox | EU and USA | |
| Cloudflare | Domain, DNS and forwarding of email sent to support@vespez.com | Global network, company in the USA |
Some of these companies are based in, or may access data from, the United States. Where personal data leaves the EU/EEA, the transfer is covered by the EU–US Data Privacy Framework or by the European Commission's standard contractual clauses, as set out in each provider's agreement linked above.
How long we keep it
- Account, scans, monitored sites, alerts and share links: until you delete them or delete your account.
- Hashed IP counters: 24 hours.
- Payment records: kept by Stripe, and by us where bookkeeping law requires it (in Norway, normally five years).
- Server logs and email delivery logs: for the short periods our providers keep them.
Deleting your data
You can delete your account yourself under Settings → Delete account. This immediately and permanently removes your account, scans, reports, monitored sites, alerts and share links, cancels any subscription and removes your customer record at Stripe.
Your rights
Under the GDPR you have the right to:
- get a copy of the personal data we hold about you;
- have incorrect data corrected;
- have your data deleted;
- restrict or object to how we use your data;
- receive your data in a portable format.
Email support@vespez.com to use any of these rights. You also have the right to complain to a data protection authority: in Norway that is Datatilsynet (the Norwegian Data Protection Authority), or you can contact the authority in the country where you live.
Cookies
Vespez sets only the cookies needed to keep you signed in. We use no analytics, advertising or tracking cookies, so there is no cookie banner. When you pay, Stripe's checkout page sets its own cookies under Stripe's policy.
If someone scanned your site
Vespez only reads pages that are publicly available, identifies itself as VespezBot, never logs in and never runs attacks. Automatic monitoring is only possible for sites whose owner has proven ownership. If you have questions about a scan of your site, email support@vespez.com.
Age
Vespez is a tool for people who build and run web applications. You must be at least 18 to create an account, and we do not knowingly collect data from anyone under 18. If you believe a minor has signed up, email support@vespez.com and we will delete the account.
Changes
If we change this policy in a way that matters, we update the date at the top and, for significant changes, tell you by email.