Privacy Policy
1. Who We Are
AllScanTool is operated by Lexicon Media Holdings LLC, a US-based entity. We act as the data controller for personal data processed through the Service.
For privacy inquiries and to exercise your rights:
Email: privacy@allscantool.com
Mailing Address: 1209 Mountain Road PL NE #10912, Albuquerque, NM 87110, USA
2. Information We Collect and Process
a) Payment Information
When you purchase a full report unlock ($7.95 one-time payment), we collect: transaction ID, payment confirmation token, payment timestamp, and amount paid. Payment processing is handled by a third-party payment processor. AllScanTool does not store full payment card details.
Payment Processor: Stripe Inc. — stripe.com/legal/privacy
b) Technical Data
- IP address — retained only in ephemeral memory during active processing, never logged
- Browser type and version
- Operating system
- Referring URL
- Timestamp of access
- Session cookie for active scan state
c) Code Submitted for Scanning
Source code you paste into the scanner is processed in real time to generate scan results.
Data We Do NOT Collect
- User accounts or registration information
- Email addresses (unless required by payment processor for receipt delivery)
- Analytics or behavioral tracking data
- Cross-site tracking cookies
- Social media pixels or tags
- Personal data sold or shared to third parties
Special Categories of Data
We do not knowingly collect special categories of personal data as defined under GDPR Article 9. Source code submitted may inadvertently contain embedded personal data. We do not inspect, extract, or store such data. Users agree via our Acceptable Use Policy not to submit code containing live, production-grade personal data unless necessary for authorized processing.
3. How We Use Your Information
| Purpose | Description |
|---|---|
| Provide the Service | Process code submissions and deliver scan results |
| Validate Payments | Process and verify one-time unlock payments; maintain 30-day access via payment tokens |
| Platform Security | Prevent abuse, fraud, and unauthorized access |
| Improve the Service | Analyze aggregate usage patterns (not individual submissions) to improve scanning rules and performance |
| Legal Compliance | Meet legal obligations where applicable |
We do not use your personal information for profiling, targeted advertising, selling personal data, building user profiles for third parties, or training AI/ML models on your code.
4. Legal Bases for Processing (GDPR)
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Payment token + transaction ID | Process and validate unlock payment | Contract — Art. 6(1)(b) |
| Payment token in KV | Maintain 30-day unlock access | Contract — Art. 6(1)(b) |
| Source code submitted | Perform security scan and deliver findings | Contract — Art. 6(1)(b) |
| Source code transmitted to Mistral AI | AI/ML-assisted vulnerability detection | Contract — Art. 6(1)(b) |
| IP address, browser data | Deliver service, prevent abuse, security | Legitimate interests — Art. 6(1)(f) |
Under CCPA/CPRA, the business purpose for all data collected is to provide the Service, process payments, and maintain platform security.
5. AI Processing and Your Code
AI/ML Sub-Processor: Mistral AI
AllScanTool uses Mistral AI as its AI/ML sub-processor for vulnerability scanning. Your submitted source code is transmitted over TLS 1.2+ to Mistral AI's servers located in the European Union.
No Training on Your Code
Retention by Mistral AI
If you require elimination of the 30-day retention window, contact privacy@allscantool.com to discuss whether current plan configuration supports ZDR for your use case.
Your Consent
By submitting source code for scanning, you acknowledge and consent to: transmission of your code over TLS 1.2+ to AllScanTool's backend and Mistral AI for vulnerability pattern detection; and temporary retention by Mistral AI for up to 30 days for abuse monitoring as governed by the DPA. AllScanTool itself retains no copies at any point.
6. Data Retention Schedules
| Data Type | Retention | Deletion Method |
|---|---|---|
| Source code (AllScanTool) | Not retained | Immediate discard (ephemeral memory) |
| Source code (Mistral AI) | Up to 30 days | Auto-delete by Mistral per DPA |
| Scan results | Not retained | Immediate discard (ephemeral memory) |
| Payment token | 30 days | Auto-purge from KV store |
| Transaction ID | 30 days | Auto-purge from KV store |
| Session cookie | Session only | Deleted on browser close |
| IP address | Not retained | Immediate discard (ephemeral memory) |
| Payment records (processor) | Per processor policy | Per processor policy |
Full retention details are documented in our No-Logs Policy.
7. Who We Share Data With
Sub-Processors
| Provider | Service | Data Accessed | Location |
|---|---|---|---|
| Stripe Inc. | Payment processing | Transaction data, payment method info | United States |
| Cloudflare | CDN, DDoS protection, TLS | IP address, request metadata (ephemeral) | Global edge |
| Mistral AI | AI/ML vulnerability scanning | Source code submitted for scanning | EU (default) |
| Cloudflare Inc. | Key-value token storage | Payment token, transaction ID | United States |
A complete sub-processor list is maintained at allscantool.com/sub-processors.
Sub-Processor Change Notification
If AllScanTool adds a new sub-processor or replaces Mistral AI, we will post a notice at allscantool.com/sub-processors at least 14 days before the change takes effect, update this Privacy Policy, and ensure any replacement operates under an equivalent DPA.
Objection to New Sub-Processors
Any change in sub-processor will require a corresponding update to all retention disclosures in this policy before the new sub-processor begins processing user data.
You may object to AllScanTool's appointment of a new sub-processor during the 14-day notice period by emailing privacy@allscantool.com. If you object, your sole and exclusive remedy is to terminate use of the Service before the new sub-processor takes effect.
Law Enforcement Disclosure
We may disclose personal information if required by law or valid public authority request. Given our No-Logs Policy, the only data available for disclosure is payment tokens and transaction IDs within the 30-day retention window, and any ephemeral data present during an active session.
8. International Data Transfers
If you access the Service from outside the European Economic Area (EEA), your data may be transferred to and processed in other countries where we or our sub-processors operate.
- Source code to Mistral AI: European Union servers — confirm exact endpoint in Worker code
- Payment processing data: Depends on payment processor location
- KV token storage: Cloudflare Inc., United States
We rely on the Data Processing Agreement with Mistral AI, which incorporates Standard Contractual Clauses (SCCs) for international transfers where required.
9. Your Rights
GDPR Rights (EEA / UK / Switzerland)
- Right of Access (Art. 15) — Request confirmation and access to your data. Requires Unlock URL or transaction ID as proof.
- Right to Rectification (Art. 16) — Request correction of inaccurate personal data.
- Right to Erasure (Art. 17) — Upon verified request, we will purge payment tokens and transaction IDs from KV storage. Note: Code transmitted to Mistral AI may be retained for 30 days per their DPA.
- Right to Data Portability (Art. 20) — Receive your data in JSON or CSV format. Limited to payment token and transaction ID.
- Right to Object (Art. 21) — Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7) — Our primary legal bases are contract and legitimate interest, not consent.
- Right to Lodge a Complaint — With your local supervisory authority.
CCPA / CPRA Rights (California)
- Right to Know — Categories collected, sources, purposes, and third-party sharing
- Right to Delete — Request deletion subject to statutory exceptions
- Right to Correct — Request correction of inaccurate information
- Right to Opt-Out — We do not sell or share personal information. Do Not Sell or Share link provided.
- Right to Non-Discrimination — We will not discriminate for exercising your rights
Other US State Rights (2026)
| State | Law | Key Rights | Contact |
|---|---|---|---|
| CA | CCPA/CPRA | Access, delete, correct, opt out of sale/sharing | privacy@allscantool.com |
| VA | VCDPA | Access, delete, correct, portability, opt out of profiling | privacy@allscantool.com |
| CO | CPA | Access, delete, correct, portability, opt out (GPC honored) | privacy@allscantool.com |
| CT | CTDPA | Access, delete, correct, portability, opt out of profiling | privacy@allscantool.com |
| TX | TDPSA | Access, delete, correct, portability, opt out of sale/sharing | privacy@allscantool.com |
Global Privacy Control (GPC)
AllScanTool honors GPC signals at the infrastructure level where supported.
Verification Process
For access and deletion requests, verification requires: Unlock URL, OR transaction ID from payment receipt, OR email proof of payment. GDPR requests fulfilled within one calendar month. CCPA requests within 45 days.
Authorized Agent
You may designate an authorized agent to submit requests on your behalf with proof of authorization.
10. Cookies and Tracking Technologies
Please see our dedicated Cookie Policy for complete details.
10.1 Cookies We Use
| Cookie | Type | Purpose | Retention |
|---|---|---|---|
| Session cookie | Essential | Maintains active scan session | Session (browser close) |
| Payment token reference | Essential | Validates Unlock URL access | 30 days (or local storage equivalent) |
10.2 Cookies We Do Not Use
We do not use analytics cookies, advertising cookies, cross-site tracking, session replay, social media pixels, or fingerprinting technologies.
11. Data Security Measures
- Encryption in transit: TLS 1.2+ on all connections
- No-Logs architecture: Scan content processed in ephemeral memory, never written to AllScanTool storage
- Payment security: Processed by PCI-DSS compliant processor; we do not store card details
- Access controls: Backend systems restricted to authorized personnel
- Infrastructure security: Firewalls, WAF via Cloudflare, rate limiting, DDoS protection, regular security assessments
- Token security: Payment tokens stored in KV are auto-purged after 30 days and not linked to user identity
For detailed security information, contact privacy@allscantool.com.
12. Children's Privacy
The Service is not directed to children under 13 (or the applicable age of digital consent in your jurisdiction) and we do not knowingly collect personal information from children. Contact privacy@allscantool.com if you believe a child has submitted information through the Service.
13. Automated Decision-Making
The Service uses AI/ML technology to generate scan results. This does NOT constitute automated decision-making under GDPR Article 22 because scan results are informational findings, not binding decisions; they do not produce legal effects; they do not significantly affect users' rights; and users retain full control over how to act on scan results.
14. Privacy by Design Statement
AllScanTool is designed with data protection by default in accordance with GDPR Article 25.
15. Data Protection Impact Assessment (DPIA)
AllScanTool has conducted a Data Protection Impact Assessment (DPIA) in accordance with GDPR Article 35. The assessment evaluated risks associated with AI/ML processing of source code that may contain embedded personal data. Mitigating measures include: ephemeral processing, No-Logs Policy, limited sub-processor retention (30-day Mistral window), encryption in transit, and no training on user code. Summary of findings is available upon request at privacy@allscantool.com.
16. Data Protection Officer (DPO)
AllScanTool has determined that a Data Protection Officer is not required under GDPR Article 37 because our core activities do not involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data (Article 9) or criminal offense data (Article 10). For privacy inquiries: privacy@allscantool.com
17. EU Representative (Article 27)
AllScanTool has determined that an EU representative under GDPR Article 27 is not currently required because AllScanTool is a US-focused service that does not intentionally target or market to individuals in the European Union. AllScanTool does not offer euro pricing, operate an EU-specific domain, maintain an EU establishment, or regularly process personal data of EU residents. Current processing involving EU residents, if any, is incidental and occasional.
This position is reviewed at least annually or when AllScanTool's geographic marketing, payment practices, customer base, or processing activities materially change. If AllScanTool begins intentionally offering services to EU individuals, an EU representative will be appointed before such expansion.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised Last Updated date. Material changes will be announced via a prominent site banner at least 14 days before taking effect. You can always review the latest version at allscantool.com/privacy.
19. Contact Information
Lexicon Media Holdings LLC d/b/a AllScanTool
Email: privacy@allscantool.com
Mailing Address: 1209 Mountain Road PL NE #10912, Albuquerque, NM 87110, USA