Legal

Privacy Policy

What WatchTower OS collects, why, and what we do to keep it safe.

Last updated 10 August 2026

What we collect

Because you gave it to us:

  • your name, email address and password (hashed with bcrypt — we never see the original);
  • your profile picture, if you upload one;
  • your workspace name, logo and company website;
  • the websites you add, and the domains they sit on;
  • payment details you submit for manual review: the sending number or wallet, the transaction reference, and the amount. Never a PIN, never a card number.

Because you use the service:

  • scan results and findings for the sites you monitor;
  • signed-in device records — browser, IP address and last-seen time — so you can see and end sessions you do not recognise;
  • an audit log of significant actions, particularly every pen test authorisation and run.

What we do not collect

We do not track you across other websites. There are no advertising pixels and no third-party analytics scripts on the application. We do not sell your data to anyone, in any form, for any price.

Our scanners read the public surface of the sites you add. They do not log into your site, read your database, or collect your visitors' personal data.

How it is protected

  • Credentials are encrypted at rest. API keys, SMTP passwords, integration tokens and two-factor secrets are encrypted with AES-256-GCM before they touch the database, so a database dump alone does not expose them.
  • Password reset and email verification links are stored as hashes only. The link that reaches your inbox exists nowhere in our systems, so it cannot be stolen from us and reused.
  • Uploaded images are re-encoded. That strips the EXIF block, including the GPS coordinates phones write into photographs. Your profile picture does not publish where you live.
  • Sessions can be revoked. Every signed-in device has a record you can end from your account page, and ending it stops that device on its next request.
  • Everything travels over HTTPS.

A limit worth being honest about

We are not end-to-end encrypted, and we cannot be. The product's entire job is to read your scan data — to score it, explain it, compare it over time and write reports from it. Software that cannot read the data cannot do any of that.

So what we promise is narrower and true: the things that do not need to be readable — passwords, API keys, two-factor secrets, integration credentials — are not readable, by us or by anyone who obtains a copy of the database.

Who else sees it

Only the services we need to run the product:

  • our hosting and database provider;
  • the email provider your administrator configures, for alerts and reports;
  • an AI provider, when you use the assistant — the question and the relevant scan context are sent so it can answer, and nothing else;
  • a payment provider, if and when card payment is enabled. Manual payments are handled by us directly.

People in your workspace see the workspace's data. That is the point of a workspace.

How long we keep it

Scan history stays until you delete the website or your account. Deleting a website removes its scans, findings and uptime history permanently — that is not recoverable, so be sure. Audit log entries for pen test authorisations are kept longer, because their purpose is to be a durable record of who permitted what.

Your rights

You can see and correct your details from your account page, remove your profile picture, end any session, and delete your workspace. For a copy of everything we hold about you, or for deletion of your account entirely, write to info@webhaat.org and we will act on it within thirty days.

Cookies

One cookie, holding your session so you stay logged in. It is HttpOnly, so scripts cannot read it. No advertising or tracking cookies are set.

Changes and contact

We will email you before any material change to this policy. Questions, or a request about your data: info@webhaat.org.