← Home

Privacy Policy

Last updated: June 22, 2026

This Privacy Policy explains how VitalSite ("VitalSite", "we", "us") collects, uses, and protects information when you use the VitalSite website and security-scanning service (the "Service"). VitalSite is operated from Israel. For privacy questions, contact support@vitalsite.io.

1. Information we collect

Account information. When you create an account, we collect your email address and (optionally) your name. If you sign in with Google, we receive your name and email from Google; we do not receive your Google password.

Scan data. When you run a scan, we process the target domain and the data our checks retrieve from its public pages (headers, HTML, DNS records, certificate details, and similar). We store scan results and findings so you can view history, share reports, and track changes over time.

Usage data. We collect basic technical data needed to run the Service, such as IP address (for rate limiting), timestamps, and which features you use.

Payment data. Payments are handled by Paddle, our Merchant of Record. Paddle collects and processes your payment details directly; we never receive or store your card numbers. We store only a Paddle customer/subscription identifier and your plan status.

Contact form. If you contact us, we collect the name, phone, email, and message you submit so we can respond.

2. Admin-panel credentials (Deep Scan)

The optional Deep Scan feature (Agency tier) requires admin-panel credentials that you provide. These credentials are used only in memory for the duration of that single scan to perform passive configuration checks, and are then discarded. We never store, log, or persist your admin-panel username or password anywhere — not in our database, logs, or backups. We only retain a record that a Deep Scan ran (timestamp and a non-sensitive result summary).

3. How we use information

We use information to:

  • Provide, operate, and secure the Service and generate your reports.
  • Authenticate you and manage your account and subscription.
  • Send transactional and account emails (welcome, verification, scan results, weekly digests, billing notices) — you can adjust digest frequency in your dashboard.
  • Respond to your messages and provide support.
  • Monitor, debug, prevent abuse, and comply with legal obligations.

We do not sell your personal information.

4. Third-party processors

To deliver the Service, scan data and/or limited account data are shared with the following processors, each only for the purpose shown:

  • Paddle — payment processing, billing, and tax (Merchant of Record).
  • Resend — sending transactional and digest emails.
  • Anthropic (Claude API) — generating the text-based fix guides and report summaries from your scan findings. Findings are sent server-side; your data is not used to train models per Anthropic's API terms.
  • Google Safe Browsing and VirusTotal — checking the scanned domain's malware/blacklist reputation.
  • NVD (NIST) — matching detected software versions against the public vulnerability database.
  • GeoPageScan — running the optional Visibility Intel (GEO/AEO/SEO) audit (Pro/Agency).
  • Google OAuth — if you choose to sign in with Google.
  • Railway and Vercel — hosting our backend, database, and frontend.

These providers process data under their own privacy terms. We share only what is needed for each function.

5. Cookies and local storage

We use minimal storage needed to run the Service — primarily a login token stored in your browser to keep you signed in, and a short-lived value to protect the sign-in flow. We do not use third-party advertising cookies.

6. Data retention

We retain account and scan data while your account is active and as needed to provide the Service. You can delete your account, after which we delete or anonymize your personal data within a reasonable period, except where we must retain limited records to comply with legal, tax, or accounting obligations (billing records are also held by Paddle). Admin-panel credentials are never retained (see Section 2).

7. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can update your name in your dashboard, manage email preferences, and request account deletion by emailing support@vitalsite.io. We will respond within a reasonable time.

8. Security

We protect your data with measures including encryption in transit (HTTPS), hashed passwords, scoped access tokens, and server-side handling of all sensitive API keys. No method of transmission or storage is perfectly secure, but we work to safeguard your information.

9. International transfers

We and our processors may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.

10. Children

The Service is not directed to children under 18, and we do not knowingly collect their personal information.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "last updated" date above and, for material changes, provide additional notice where appropriate.

12. Contact

For any privacy request or question, email support@vitalsite.io or use our contact page.

See also our Terms of Service.

Was this page helpful?

Rate it — it helps us improve the site.

4.7 out of 5 · 3 ratings