Legal
Privacy Policy
This says what personal data Data Armour collects, why we are allowed to hold it, who else sees it, how long we keep it, and what you can make us do about it. It is written to the Digital Personal Data Protection Act, 2023.
Last updated 17 September 2026
This page is not finished. It is still missing the registered company name, the registered office address, the grievance officer's name. Until those are filled in at app/lib/legal/company.ts, this page must not be treated as published. It should also be read by a lawyer qualified in India before it is.
1. Who is responsible
FILL THIS IN: registered company name, at FILL THIS IN: registered office address, city, state, PIN, India, operates Data Armour. Under the DPDP Act we are the Data Fiduciary for the personal data described here, which means we decide why and how it is processed and we are the ones answerable for it.
Our Grievance Officer is named in the contact page, and answers within 7 days.
2. What we collect
Because you gave it to us
- Your account. Name, email address, and a profile picture if you signed in with Google or GitHub. If you signed up with a password we store a hash of it and never the password.
- What you want tested. The addresses, repositories and API specifications you add as targets, and the labels you give them.
- Source code you upload, or that we fetch from a repository you connected, for the duration of a scan. See section 5, which is about this alone.
- Anything you write to us. Support messages, and the reason you give if you ask for your account to be erased.
Because using the product creates it
- Tests and results. Every scan you start, what it cost, how long it ran, and the findings it produced, including the request and response evidence behind them.
- Sessions. When you signed in, from what browser, and from what IP address. We keep this so you can see where your account is signed in and end a session you do not recognise.
- Payments. Amount, currency, method, gateway, whether it succeeded, and if it did not, why. Card numbers, UPI IDs and bank details are handled by the payment gateway and never reach us.
- The credit ledger. Every credit added or spent, and against what.
We run no analytics, no advertising, no trackers and no third party scripts on this product. We do not buy personal data, we do not sell it, and we do not profile you.
3. Why we are allowed to hold it
The DPDP Act permits processing on consent or for certain legitimate uses. Ours are:
- To give you the service you asked for. You cannot be shown the results of a scan you ran without us keeping the scan and the account that ran it.
- Because the law requires it. Payment and tax records, which we keep whatever else happens. See section 6.
- Your consent, for anything beyond that, such as email about a test finishing. You can withdraw it in your profile at any time, and withdrawing it is as easy as giving it.
4. Who else sees it
A short list, and it is the whole list. Each of these is a processor acting on our instructions, under contract, and none of them may use your data for their own purposes.
- Google and GitHub
- Only if you choose to sign in with them. They tell us your name, email and picture. We tell them nothing about what you test.
- GitHub, as an app
- If you connect repositories, we read the ones you grant and the pull requests you ask us to review. We only ever read what the installation you approved allows.
- Our payment gateway
- Takes the payment and tells us whether it worked. Your card and bank details go to them directly and are never stored by us.
- Our email provider
- Delivers the messages we send you: results, and account notices.
- Our testing engine and its language model
- The scan itself runs on our own infrastructure and is driven by a large language model. What reaches it is the target you asked us to test and what that target returns. See section 5.
- Our hosting and database provider
- Stores the data described above, encrypted at rest.
We will also hand over data if a court or a law with force over us requires it. If that happens and we are allowed to tell you, we will.
5. Your source code, and what a scan touches
This is the part that matters most, so it is stated plainly.
- Code you upload, or that we fetch from a repository you connected, is written to a temporary file on our server, handed to the testing engine, and deleted. We do not keep a copy of your repository.
- Scan output is held by the testing engine for one hour and then deleted. After that only what we have already saved as findings remains: the title, the severity, the file and line, and the evidence needed to explain and reproduce the issue.
- The engine is driven by a language model, and the parts of your code and your site relevant to a test are sent to it in order to test them. That provider is contractually barred from training on it.
- We test only targets you have added and confirmed you own or are authorised to test. We never test private or internal network addresses.
6. How long we keep it
- Your account
- Until you erase it.
- Tests and findings
- Until you erase them, or the account they belong to.
- Raw scan output
- One hour, at the testing engine, then deleted automatically.
- Uploaded source code
- The length of the scan. Deleted when it ends, whether it succeeded or not.
- Sessions
- Until they expire, you sign out, or you end them from your profile.
- Payments and the credit ledger
- Eight years, because Indian tax and company law require financial records to be kept. After an account is erased these rows remain but no longer name anybody.
- The record that you asked to be erased
- Kept, with your email stored only as a one way hash. It lets us prove the erasure happened and answers no other question.
7. What you can make us do
These are your rights under the DPDP Act. Every one of them is a button in your profile, not a form to fill in and wait on.
- Get a copy, and know what we have done with it. Section 11. Your profile has Take a copy, which downloads everything we hold about you as one file, immediately.
- Correct it. Section 12. Your name and email are editable in your profile. Write to us for anything you cannot change yourself.
- Erase it. Section 12. Two separate things, and you can do either: Erase what the tests found removes your scans and their results and keeps the account, and Erase your account removes the account itself. The account is disabled the moment you ask. You have 15 days to change your mind, we email you before it happens, and then it is gone.
- Withdraw consent. Section 6(4). Turn off the emails in your profile, or disconnect GitHub, and we stop.
- Nominate somebody. Section 14. You may name a person to exercise these rights if you die or become incapable of exercising them yourself. Write to our Grievance Officer and we will record it.
- Complain. Section 13. To our Grievance Officer first. If we have not resolved it, to the Data Protection Board of India.
8. Children
Data Armour is not for anybody under 18. We do not knowingly hold data about a child. If you believe we do, tell our Grievance Officer and we will remove it.
9. Keeping it safe
Data is encrypted in transit and at rest. Access tokens for connected accounts are encrypted with a key held separately from the database. Sessions are bound to a server side record so signing out really ends them. Access to production data is limited to the people who need it and is logged.
If a breach affects your personal data, the DPDP Act requires us to tell you and the Data Protection Board, and we will.
10. Changes
If we change this policy in a way that affects what we do with your data, we will email you before it takes effect. The date at the top is when it last changed.