Lexicon Media Holdings LLC d/b/a AllScanTool

Privacy Policy

Last Updated: July 15, 2026 Effective Date: July 15, 2026
Version 1.2
This Privacy Policy explains how Lexicon Media Holdings LLC ("AllScanTool," "we," "us," or "our") collects, uses, discloses, and protects information when you use the AllScanTool website and scanning platform at allscantool.com (the "Service"). By accessing or using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.

1. Who We Are

AllScanTool is operated by Lexicon Media Holdings LLC, a US-based entity. We act as the data controller for personal data processed through the Service.

For privacy inquiries and to exercise your rights:
Email: privacy@allscantool.com
Mailing Address: 1209 Mountain Road PL NE #10912, Albuquerque, NM 87110, USA

2. Information We Collect and Process

a) Payment Information

When you purchase a full report unlock ($7.95 one-time payment), we collect: transaction ID, payment confirmation token, payment timestamp, and amount paid. Payment processing is handled by a third-party payment processor. AllScanTool does not store full payment card details.

Payment Processor: Stripe Inc. — stripe.com/legal/privacy

b) Technical Data

  • IP address — retained only in ephemeral memory during active processing, never logged
  • Browser type and version
  • Operating system
  • Referring URL
  • Timestamp of access
  • Session cookie for active scan state

c) Code Submitted for Scanning

Source code you paste into the scanner is processed in real time to generate scan results.

AllScanTool does not store, log, cache, or retain your source code at any stage. Code is processed and discarded immediately after results are delivered.
Submitted code is transmitted to our AI/ML sub-processor (Mistral AI) for vulnerability pattern detection over encrypted connections (TLS 1.2+). See Sections 5 and 7 for complete details.

Data We Do NOT Collect

  • User accounts or registration information
  • Email addresses (unless required by payment processor for receipt delivery)
  • Analytics or behavioral tracking data
  • Cross-site tracking cookies
  • Social media pixels or tags
  • Personal data sold or shared to third parties

Special Categories of Data

We do not knowingly collect special categories of personal data as defined under GDPR Article 9. Source code submitted may inadvertently contain embedded personal data. We do not inspect, extract, or store such data. Users agree via our Acceptable Use Policy not to submit code containing live, production-grade personal data unless necessary for authorized processing.

3. How We Use Your Information

PurposeDescription
Provide the ServiceProcess code submissions and deliver scan results
Validate PaymentsProcess and verify one-time unlock payments; maintain 30-day access via payment tokens
Platform SecurityPrevent abuse, fraud, and unauthorized access
Improve the ServiceAnalyze aggregate usage patterns (not individual submissions) to improve scanning rules and performance
Legal ComplianceMeet legal obligations where applicable

We do not use your personal information for profiling, targeted advertising, selling personal data, building user profiles for third parties, or training AI/ML models on your code.

5. AI Processing and Your Code

AI/ML Sub-Processor: Mistral AI

AllScanTool uses Mistral AI as its AI/ML sub-processor for vulnerability scanning. Your submitted source code is transmitted over TLS 1.2+ to Mistral AI's servers located in the European Union.

Mistral AI DPA in effect via API agreement: legal.mistral.ai/terms/data-processing-addendum
Confirmed endpoint: api.mistral.ai/v1/chat/completions — EU-based servers. Model: open-mistral-nemo-2407.

No Training on Your Code

Under AllScanTool's paid API plan with Mistral AI, submitted source code is NOT used to train, fine-tune, or improve any AI model — ours or our sub-processor's.

Retention by Mistral AI

Mistral AI may retain submitted code for up to 30 days for abuse monitoring purposes, after which it is permanently deleted. Zero Data Retention (ZDR) options are available on Mistral's Scale plan.

If you require elimination of the 30-day retention window, contact privacy@allscantool.com to discuss whether current plan configuration supports ZDR for your use case.

Your Consent

By submitting source code for scanning, you acknowledge and consent to: transmission of your code over TLS 1.2+ to AllScanTool's backend and Mistral AI for vulnerability pattern detection; and temporary retention by Mistral AI for up to 30 days for abuse monitoring as governed by the DPA. AllScanTool itself retains no copies at any point.

6. Data Retention Schedules

Data TypeRetentionDeletion Method
Source code (AllScanTool)Not retainedImmediate discard (ephemeral memory)
Source code (Mistral AI)Up to 30 daysAuto-delete by Mistral per DPA
Scan resultsNot retainedImmediate discard (ephemeral memory)
Payment token30 daysAuto-purge from KV store
Transaction ID30 daysAuto-purge from KV store
Session cookieSession onlyDeleted on browser close
IP addressNot retainedImmediate discard (ephemeral memory)
Payment records (processor)Per processor policyPer processor policy

Full retention details are documented in our No-Logs Policy.

7. Who We Share Data With

Sub-Processors

ProviderServiceData AccessedLocation
Stripe Inc.Payment processingTransaction data, payment method infoUnited States
CloudflareCDN, DDoS protection, TLSIP address, request metadata (ephemeral)Global edge
Mistral AIAI/ML vulnerability scanningSource code submitted for scanningEU (default)
Cloudflare Inc.Key-value token storagePayment token, transaction IDUnited States

A complete sub-processor list is maintained at allscantool.com/sub-processors.

Sub-Processor Change Notification

If AllScanTool adds a new sub-processor or replaces Mistral AI, we will post a notice at allscantool.com/sub-processors at least 14 days before the change takes effect, update this Privacy Policy, and ensure any replacement operates under an equivalent DPA.

Objection to New Sub-Processors

Any change in sub-processor will require a corresponding update to all retention disclosures in this policy before the new sub-processor begins processing user data.

You may object to AllScanTool's appointment of a new sub-processor during the 14-day notice period by emailing privacy@allscantool.com. If you object, your sole and exclusive remedy is to terminate use of the Service before the new sub-processor takes effect.

Law Enforcement Disclosure

We may disclose personal information if required by law or valid public authority request. Given our No-Logs Policy, the only data available for disclosure is payment tokens and transaction IDs within the 30-day retention window, and any ephemeral data present during an active session.

8. International Data Transfers

If you access the Service from outside the European Economic Area (EEA), your data may be transferred to and processed in other countries where we or our sub-processors operate.

  • Source code to Mistral AI: European Union servers — confirm exact endpoint in Worker code
  • Payment processing data: Depends on payment processor location
  • KV token storage: Cloudflare Inc., United States

We rely on the Data Processing Agreement with Mistral AI, which incorporates Standard Contractual Clauses (SCCs) for international transfers where required.

9. Your Rights

GDPR Rights (EEA / UK / Switzerland)

  • Right of Access (Art. 15) — Request confirmation and access to your data. Requires Unlock URL or transaction ID as proof.
  • Right to Rectification (Art. 16) — Request correction of inaccurate personal data.
  • Right to Erasure (Art. 17) — Upon verified request, we will purge payment tokens and transaction IDs from KV storage. Note: Code transmitted to Mistral AI may be retained for 30 days per their DPA.
  • Right to Data Portability (Art. 20) — Receive your data in JSON or CSV format. Limited to payment token and transaction ID.
  • Right to Object (Art. 21) — Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7) — Our primary legal bases are contract and legitimate interest, not consent.
  • Right to Lodge a Complaint — With your local supervisory authority.

CCPA / CPRA Rights (California)

  • Right to Know — Categories collected, sources, purposes, and third-party sharing
  • Right to Delete — Request deletion subject to statutory exceptions
  • Right to Correct — Request correction of inaccurate information
  • Right to Opt-Out — We do not sell or share personal information. Do Not Sell or Share link provided.
  • Right to Non-Discrimination — We will not discriminate for exercising your rights

Other US State Rights (2026)

StateLawKey RightsContact
CACCPA/CPRAAccess, delete, correct, opt out of sale/sharingprivacy@allscantool.com
VAVCDPAAccess, delete, correct, portability, opt out of profilingprivacy@allscantool.com
COCPAAccess, delete, correct, portability, opt out (GPC honored)privacy@allscantool.com
CTCTDPAAccess, delete, correct, portability, opt out of profilingprivacy@allscantool.com
TXTDPSAAccess, delete, correct, portability, opt out of sale/sharingprivacy@allscantool.com

Global Privacy Control (GPC)

AllScanTool honors GPC signals at the infrastructure level where supported.

Verification Process

For access and deletion requests, verification requires: Unlock URL, OR transaction ID from payment receipt, OR email proof of payment. GDPR requests fulfilled within one calendar month. CCPA requests within 45 days.

Authorized Agent

You may designate an authorized agent to submit requests on your behalf with proof of authorization.

10. Cookies and Tracking Technologies

Please see our dedicated Cookie Policy for complete details.

10.1 Cookies We Use

CookieTypePurposeRetention
Session cookieEssentialMaintains active scan sessionSession (browser close)
Payment token referenceEssentialValidates Unlock URL access30 days (or local storage equivalent)

10.2 Cookies We Do Not Use

We do not use analytics cookies, advertising cookies, cross-site tracking, session replay, social media pixels, or fingerprinting technologies.

11. Data Security Measures

  • Encryption in transit: TLS 1.2+ on all connections
  • No-Logs architecture: Scan content processed in ephemeral memory, never written to AllScanTool storage
  • Payment security: Processed by PCI-DSS compliant processor; we do not store card details
  • Access controls: Backend systems restricted to authorized personnel
  • Infrastructure security: Firewalls, WAF via Cloudflare, rate limiting, DDoS protection, regular security assessments
  • Token security: Payment tokens stored in KV are auto-purged after 30 days and not linked to user identity

For detailed security information, contact privacy@allscantool.com.

12. Children's Privacy

The Service is not directed to children under 13 (or the applicable age of digital consent in your jurisdiction) and we do not knowingly collect personal information from children. Contact privacy@allscantool.com if you believe a child has submitted information through the Service.

13. Automated Decision-Making

The Service uses AI/ML technology to generate scan results. This does NOT constitute automated decision-making under GDPR Article 22 because scan results are informational findings, not binding decisions; they do not produce legal effects; they do not significantly affect users' rights; and users retain full control over how to act on scan results.

14. Privacy by Design Statement

AllScanTool is designed with data protection by default in accordance with GDPR Article 25.

Minimal Data CollectionStateless, no accounts, no registration required
Ephemeral ProcessingCode never stored by AllScanTool at any stage
No-Logs PolicyOperationalized through documented architecture
Encryption in TransitTLS 1.2+ on all connections
Limited Retention30-day token expiry, automatic purge
No TrackingNo analytics or tracking on code submissions

15. Data Protection Impact Assessment (DPIA)

AllScanTool has conducted a Data Protection Impact Assessment (DPIA) in accordance with GDPR Article 35. The assessment evaluated risks associated with AI/ML processing of source code that may contain embedded personal data. Mitigating measures include: ephemeral processing, No-Logs Policy, limited sub-processor retention (30-day Mistral window), encryption in transit, and no training on user code. Summary of findings is available upon request at privacy@allscantool.com.

16. Data Protection Officer (DPO)

AllScanTool has determined that a Data Protection Officer is not required under GDPR Article 37 because our core activities do not involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data (Article 9) or criminal offense data (Article 10). For privacy inquiries: privacy@allscantool.com

17. EU Representative (Article 27)

AllScanTool has determined that an EU representative under GDPR Article 27 is not currently required because AllScanTool is a US-focused service that does not intentionally target or market to individuals in the European Union. AllScanTool does not offer euro pricing, operate an EU-specific domain, maintain an EU establishment, or regularly process personal data of EU residents. Current processing involving EU residents, if any, is incidental and occasional.

This position is reviewed at least annually or when AllScanTool's geographic marketing, payment practices, customer base, or processing activities materially change. If AllScanTool begins intentionally offering services to EU individuals, an EU representative will be appointed before such expansion.

18. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised Last Updated date. Material changes will be announced via a prominent site banner at least 14 days before taking effect. You can always review the latest version at allscantool.com/privacy.

19. Contact Information

Lexicon Media Holdings LLC d/b/a AllScanTool
Email: privacy@allscantool.com
Mailing Address: 1209 Mountain Road PL NE #10912, Albuquerque, NM 87110, USA

Related Resources