Draft v1 · pending attorney review

Privacy Policy

What we collect, why, how long we keep it, and how to opt out. In one paragraph: MagnusID identity + your scan results + operational telemetry. We do not sell your data.

What we collect

  • · Your MagnusID subject identifier + email (issued by MagnusID, not stored as a separate password by us).
  • · Sites you register: URL, scope rules, auth_config metadata (sealed credentials live in a vault, never in our DB).
  • · Scan artifacts: screenshots, HTTP captures, console logs, repro steps.
  • · Findings (anonymized derivative of scan artifacts, retained for KB).
  • · Operational telemetry: brain events (IDs + classifications, no PII).
  • · Legal trail: ToS acceptances + ownership verification attempts (with IP, timestamp, version).

What we do NOT collect

  • · Card numbers (handled by Stripe / QuikyPay; we store only the merchant reference).
  • · Your end-users’ data. When we scan an authenticated flow, we use the credentials you provide; we never harvest user-account data.
  • · PII about your customers in brain events (only IDs + categories).

Retention

  • · Scan artifacts — 90 days (configurable downward).
  • · Findings — indefinitely, anonymized to (category, fingerprint, severity, suggested_fix).
  • · KB patterns — indefinitely.
  • · Brain events — 180 days.
  • · ToS / verification audit — 7 years per CFAA evidentiary norms.

Training opt-out

Your account exposes a training_opt_out boolean. When true, your samples are excluded from /agent/v1/training-samples exports (the field is enforced server-side; opted-out samples are returned with redacted: true). Defaults to false on signup; toggle any time.

Data subject rights

You can request access, export, correction, or deletion of your data at any time. Email privacy@magnusqa.ai. Deletion follows the 30-day flow described in the Terms.

Contact

Questions: privacy@magnusqa.ai. Security disclosures: security@magnusqa.ai.