Privacy Policy

Last updated: 5 July 2026

Your investigation data stays on your device. This policy covers the limited account and billing data the Deep Detect website processes to run your subscription.

1. Overview

Deep Detect is built around a simple principle: your investigation data never leaves your device. This policy explains what the browser extension does with data (almost nothing) and what the Deep Detect website and licensing service collect to run your account and subscription.

2. The extension keeps investigation data local

All IOC investigation data — the IOCs you look up, the results returned, and your source API keys — is stored in chrome.storage.local on your own device. It is never synced, uploaded, or sent to Deep Detect.

When you run a pivot, your browser calls each threat-intelligence source directly (VirusTotal, AbuseIPDB, Shodan, GreyNoise, ipinfo) using the API keys you supplied. Those requests go from your browser to those providers; Deep Detect is not in the path and never sees the queries or results.

The only network call the extension makes to our infrastructure is license validation: it sends your license key and account email to the licensing service to confirm the key is active. No investigation data is included.

3. What the website collects

To create an account and manage a subscription, we collect and store:

  • Account details — your name and email address, managed through our authentication provider (Supabase).
  • Billing details — subscription status and history. Payment and card data are handled entirely by Dodo Payments, our Merchant of Record; we never see or store card numbers. Because Dodo is the seller of record, it is the controller of the billing and tax records it collects to complete your purchase, including the billing address and any tax identifier you provide at checkout.
  • License keys — the keys issued to your account, so you can view, copy, and regenerate them from the dashboard.

4. Sub-processors

We rely on a small set of vetted providers to deliver the service:

  • Supabase — authentication and account database.
  • Dodo Payments — Merchant of Record for all subscriptions: hosted checkout, card processing, invoicing, and sales-tax/VAT/GST compliance. Dodo acts as the seller of record rather than solely as our processor, so it is an independent controller for the payment and tax data it collects, under its own privacy policy.
  • Resend — transactional email (license delivery, renewal and expiry notices, support replies).
  • Cloudflare — hosts the licensing service that validates keys.
  • Netlify — hosts this website.

The threat-intelligence sources you configure in the extension are not our sub-processors — you contract with them directly under your own API keys and their terms.

5. Cookies

The website uses strictly necessary cookies to keep you signed in and to secure authentication. We do not use advertising or cross-site tracking cookies.

6. Data retention

Account and billing records are retained while your account is active and for as long as required to meet legal, tax, and accounting obligations. You can request deletion of your account at any time.

Extension data lives only on your device; uninstalling the extension or clearing local storage removes it. The extension also enforces a configurable local history retention window (90 days by default).

7. Your rights (PDPL & GDPR)

Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact us via the details below.

8. Contact

For any privacy question or data-subject request, reach us through the contact form at /contact. We respond by email.