Privacy policy
What we collect, why we collect it, and how you can delete it. Written to be read, not skimmed past.
Last updated 9 October 2026
The short version
- We collect only what the service needs: your account details and the reports for the websites you scan.
- We don't sell your data, show ads, or use tracking or analytics cookies.
- You can delete your account and everything in it from the account page at any time.
Who is responsible
This service is run by AACL, which decides how your data is used. You can reach us through the contact page.
What we collect
When you scan a website
We store the address you scanned and the report it produced: the score, the findings and the time. A scan looks only at what any visitor's browser can see, such as pages, headers and public DNS records. If a sensitive file is exposed, we record that it exists, never what is inside it.
A scan you run without an account can be saved to an account for 24 hours. If nobody saves it, it is deleted after about 7 days.
To check a website we also look up its public DNS records and its domain registration record. Those lookups send the website's domain name, and nothing about you, to public DNS and registry services.
On the Business plan, a scan also asks two outside services about the domain: the public Certificate Transparency logs, through crt.sh, for the certificates issued for it, and a security blocklist, Google Web Risk, for whether it is listed as dangerous. Only the domain name is sent. Nothing about you or your account goes with it. Subdomains that appear in those logs are listed in your report and are never visited.
When you tick the agreement
Before every check, when you create an account with an email address, and when you add a website to daily monitoring, you tick a box to agree to our terms and this policy and to confirm you may have the website tested. Each time, we record that you agreed: the time, your account if you are signed in, the website address, the IP address the request came from, and which version of the terms applied. We keep that record for up to 12 months as proof of the agreement.
When you switch on daily monitoring
Monitoring is part of the paid plans, which aren't open yet. When you add a website to monitor, we store its address and the time you confirmed you own it or have the right to have it tested. We then scan that website once a day and save each report to your account.
We email you only when something important changes, at most once a day per website, to the email address on your account. Every alert email has a link that switches alerts off for that website without logging in. We keep a short record of the alerts we sent so you can see them in your dashboard.
When you create an account
We store your name, your email address and, if you sign up with a password, a scrambled (hashed) version of it. We never store the password itself. If you sign in with Google or GitHub, we receive your name, email address and profile picture link from them, and store the sign-in tokens encrypted. From GitHub we ask only for your email address.
While you are signed in we keep a session record with the time it started, your IP address and your browser type.
When you use the site
We keep your IP address for a short time, at most a few days, to limit how many scans and sign-in attempts one person can make. Our hosting provider also keeps standard server logs.
When you contact us
The contact form sends your name, email address and message to our inbox so we can reply. It is not stored on the website.
Cookies
We only set cookies the site needs to work: the ones that keep you signed in, for up to 30 days, and a short-lived one while you sign in with Google or GitHub. There are no advertising, tracking or analytics cookies, which is why you don't see a cookie banner.
Emails we send
We email you to verify your address and to reset your password when you ask. These emails contain no tracking pixels. We don't send marketing email.
Who helps us run the service
We use a small number of companies to run Royals Security. They process data on our behalf and only to provide their service to us:
- netcup hosts the website, on a server in Nuremberg, Germany.
- Neon hosts the database, in Frankfurt, Germany.
- Resend delivers our emails.
- Google and GitHub, only if you choose to sign in with them.
Paid plans are not open yet. When they open, payments will be handled by Paddle, which acts as the merchant of record. Your card details will go to them, not to us.
Some of these companies are based in the United States, so your data may be processed there under their own safeguards.
How long we keep it
- Account details and saved reports: until you delete your account.
- Scans that were never saved to an account: about 7 days.
- Sign-in sessions: up to 30 days.
- IP addresses kept for rate limits: a few days at most.
Your choices and rights
You can change your name and password, and delete your account with all its websites and reports, on the account page. Deleting takes effect straight away.
If you are in the European Union or the United Kingdom, you also have the right to ask for a copy of your data, to have it corrected, to object to how we use it, and to complain to your local data protection authority. To use any of these, contact us.
Children
Royals Security is for people who run websites. It is not meant for children under 16, and we don't knowingly collect their data.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and the date at the top. For significant changes we'll also tell account holders by email.
Contact
Questions about your data? Contact us.