Privacy Policy
What we collect, why we collect it, and what you can do about it. Last updated 28 April 2026.
This Privacy Policy explains how Secly ("Secly", "we", "our", "us") collects, uses, stores, and shares personal data when you visit our website at secly.com, sign up for an account, or use the Secly audit platform (the "Service"). It also covers our use of cookies and how to exercise your data-protection rights.
Secly is the data controller for the personal data described in this policy. For data-protection enquiries, write to privacy@secly.com.
This policy is written with UK GDPR and the Data Protection Act 2018 in mind. If you are accessing the Service from another jurisdiction, additional rights may apply to you under your local law.
1. Scope
This policy applies to:
- Visitors to
secly.comand its subdomains. - Users who create a Secly account, whether on a free or paid plan.
- Operators of websites that are submitted to Secly for audit, where personal data may incidentally appear in fetched pages.
- People who contact us by email, social channels, or in-product.
Where you use Secly on behalf of an organisation that pays for or controls your account, that organisation may also have its own privacy notices that apply to you.
2. What We Collect
2.1 Account Data
When you sign up, our authentication provider (Clerk) collects the data needed to identify and authenticate you. We receive from Clerk:
- Your name (where supplied) and any avatar image.
- Your email address and verification status.
- An opaque user identifier and sign-in timestamps.
- Where you sign in via a third-party identity provider (such as Google or GitHub), the identifier and email returned by that provider.
We additionally store profile data that you set in-product, such as a display name override or notification preferences.
2.2 Project and Audit Data
As you use the Service, we store:
- The URLs you submit for audit.
- The screenshots, rendered HTML, and other artifacts captured by SeclyBot when fetching those URLs.
- The structured findings, summaries, and scoring produced by our analysis pipeline.
- Configuration you set (project names, schedules, sharing settings, custom rules).
- Comments, annotations, and notes you add inside the product.
2.2a API and Webhook Data
If you are an API customer, we additionally store:
- API keys you mint, including a hash of the secret, the owning user, label, daily quota, and last-used timestamp.
- Per-scan metadata for every
POST /v1/scanscall: the requested URL, your webhook URL, any external reference you supplied, and the API key that authorised the call. - Webhook delivery state — attempt count, status code, response excerpt, and next-retry time — so we can debug failures and stop redelivery on success.
These artifacts may incidentally contain personal data that is publicly visible on the audited URL — for example, the names of authors of public blog posts, public contact details on a "Contact Us" page, or images of people that appear in a public website's design.
2.3 Operational Telemetry
We collect operational telemetry needed to run, secure, and bill the Service:
- Audit duration, timing, and outcome.
- Provider-cost events from third-party providers (LLM tokens, browser session minutes, storage operations).
- Error logs and stack traces.
- IP address and basic request metadata for security and abuse prevention.
- Aggregate usage counts (audits per project, requests per endpoint).
2.4 Communications
If you contact us, we keep a copy of the communication and our reply. If you sign up to product or release announcements, we keep your email address against that subscription until you unsubscribe.
2.5 Payment Data
If you purchase a paid plan, payment-card details are collected and processed directly by our payment provider. We do not see or store full card numbers; we receive a transaction reference, the amount, the currency, and a partial card descriptor for invoicing.
3. How We Use It
We use the data described above for the following purposes:
- To deliver the Service — running audits, generating findings, displaying results, sharing artifacts as you direct, and operating the marketplace.
- To run your account — authentication, account management, billing, plan enforcement, and customer support.
- To communicate with you — operational notices, security alerts, billing emails, replies to your enquiries, and (where you have asked for them) product updates.
- To secure the Service — detecting and preventing abuse, fraud, brute-force attempts, scraping, and breaches of clause 3 of our Terms.
- To improve the Service — debugging, performance analysis, and aggregate usage analysis. Where we use aggregated data, it is de-identified.
- To comply with the law — meeting our legal, tax, and regulatory obligations and responding to lawful requests.
We do not sell personal data, and we do not use audit content to train third-party general-purpose AI models on your behalf.
4. Lawful Basis (UK GDPR)
We rely on the following lawful bases:
- Contract (Article 6(1)(b)) — to provide the Service to you under our Terms and to operate your account and billing.
- Legitimate interests (Article 6(1)(f)) — to secure the Service, prevent abuse, debug, and improve the product, and run modest direct marketing to existing users about closely related features. You can object to any of this at any time (see clause 8).
- Legal obligation (Article 6(1)(c)) — to meet tax, accounting, and other regulatory requirements.
- Consent (Article 6(1)(a)) — for any optional communications that require it (such as marketing emails to people who are not existing users).
Where audit content incidentally contains personal data of third parties, we process it as a service-provider-style data processor on behalf of the account owner, who is responsible for the lawful basis on which that processing occurs.
5. Subprocessors
We use the following third parties to operate the Service. Each is bound by a data-processing agreement or equivalent protections.
- Replit — application hosting, PostgreSQL database, object storage.
- Clerk — user authentication and identity (dashboard users only — API customers authenticate by Bearer token and do not have Clerk identities).
- Anthropic — large-language-model inference (Claude family) used to analyse audit artifacts. Calls run through the Replit AI Integrations proxy.
- Browserbase — hosted headless-browser execution for rendering audited URLs.
- Resend — transactional email delivery.
We may add, change, or remove subprocessors as the Service evolves. The list above is canonical at the date of this policy. Where a change is material, we will give reasonable notice in-product or by email before it takes effect.
6. Sharing Data with Other Parties
We do not sell your personal data. We may share data in the following limited circumstances:
- Subprocessors — as described in clause 5, in order to deliver the Service.
- Legal requirements — where we believe disclosure is required by law, regulation, court order, or by an authority with appropriate jurisdiction.
- Protection — where we believe disclosure is necessary to protect the rights, safety, or property of Secly, our users, or the public.
- Corporate transactions — in the event of a merger, acquisition, financing, reorganisation, or sale of all or part of our business, in which case any acquirer will be bound by privacy commitments at least equivalent to those in this policy.
- At your direction — where you choose to share an artifact (such as a public marketplace listing or a shared report link).
7. Retention
We retain personal data only for as long as needed for the purposes described above:
- Account data — for the lifetime of the account, plus a short window after closure for billing reconciliation and abuse-prevention records.
- Audit artifacts (screenshots, HTML snapshots, findings) — retained for the life of the project they belong to. Deleting a project deletes its artifacts. Deleting an account deletes all projects and their artifacts.
- API keys, per-scan metadata, and webhook delivery records — retained for the lifetime of the API integration. Revoking a key marks it inactive immediately; the row is kept for audit. Deleting an API customer deletes the keys, the per-scan metadata, and the webhook delivery history.
- Operational telemetry — retained for up to 12 months in raw form, after which it is aggregated or deleted.
- Billing records — retained for the period required by tax and accounting law (typically 6 years in the UK).
- Support correspondence — retained for up to 24 months after the last interaction.
You may also request earlier deletion at any time (see clause 8).
8. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectification of personal data that is inaccurate or incomplete.
- Erasure of your personal data ("right to be forgotten"), subject to our need to retain certain records by law.
- Restriction of processing in certain circumstances.
- Portability of personal data you have provided to us, in a commonly used machine-readable format.
- Object to processing carried out on the basis of legitimate interests, including direct marketing.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, write to privacy@secly.com. We will acknowledge within 7 days and respond substantively within 30 days. We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or the supervisory authority in your country of residence.
9. Cookies and Similar Technologies
Secly uses only strictly necessary cookies. These include:
- A session cookie used to keep you signed in, set by our authentication provider.
- A small number of functional cookies used to remember UI preferences (such as theme or sidebar state).
We do not use analytics cookies, advertising cookies, third-party tracking pixels, or social-media trackers on the Secly site. Because we use only strictly necessary cookies, we do not currently show a cookie consent banner. If we ever add non-essential cookies, we will introduce a consent flow before doing so.
10. International Transfers
Some of our subprocessors are based outside the UK and the European Economic Area (notably in the United States). Where personal data is transferred outside the UK or EEA, we rely on:
- The UK or EU adequacy decisions where they apply, or
- Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), combined with supplementary measures where appropriate.
You can request a summary of the transfer mechanisms in place by writing to privacy@secly.com.
11. Security
We take reasonable technical and organisational measures to protect personal data, including:
- TLS encryption in transit.
- Encryption at rest for object storage and database backups, where supported by the provider.
- Authentication and authorisation enforced at every API endpoint.
- Principle-of-least-privilege access for our team and contractors.
- Logging and monitoring of administrative access.
- Routine dependency updates.
No system is perfectly secure. If you believe you have found a security issue, please report it responsibly to security@secly.com.
12. Breach Notification
In the event of a personal-data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will notify affected users without undue delay where the risk is high.
13. Children
The Service is not directed at children. You must be at least 16 to create an account. We do not knowingly collect personal data from children under 16. If you believe a child has supplied us with personal data, write to privacy@secly.com and we will delete it.
14. Changes to this Policy
We may update this policy from time to time. The current version is always published at secly.com/privacy, with the date stated at the foot. Where changes are material, we will give reasonable notice (typically by email or in-product notice) before they take effect.
15. Contact
Data-protection enquiries and rights requests: privacy@secly.com.
Last updated: 28 April 2026.