Draft v1 · pending attorney review
Privacy Policy
What we collect, why, how long we keep it, and how to opt out. In one paragraph: MagnusID identity + your scan results + operational telemetry. We do not sell your data.
What we collect
- · Your MagnusID subject identifier + email (issued by MagnusID, not stored as a separate password by us).
- · Sites you register: URL, scope rules, auth_config metadata (sealed credentials live in a vault, never in our DB).
- · Scan artifacts: screenshots, HTTP captures, console logs, repro steps.
- · Findings (anonymized derivative of scan artifacts, retained for KB).
- · Operational telemetry: brain events (IDs + classifications, no PII).
- · Legal trail: ToS acceptances + ownership verification attempts (with IP, timestamp, version).
What we do NOT collect
- · Card numbers (handled by Stripe / QuikyPay; we store only the merchant reference).
- · Your end-users’ data. When we scan an authenticated flow, we use the credentials you provide; we never harvest user-account data.
- · PII about your customers in brain events (only IDs + categories).
Retention
- · Scan artifacts — 90 days (configurable downward).
- · Findings — indefinitely, anonymized to
(category, fingerprint, severity, suggested_fix). - · KB patterns — indefinitely.
- · Brain events — 180 days.
- · ToS / verification audit — 7 years per CFAA evidentiary norms.
Training opt-out
Your account exposes a training_opt_out boolean. When true, your samples are excluded from /agent/v1/training-samples exports (the field is enforced server-side; opted-out samples are returned with redacted: true). Defaults to false on signup; toggle any time.
Data subject rights
You can request access, export, correction, or deletion of your data at any time. Email privacy@magnusqa.ai. Deletion follows the 30-day flow described in the Terms.
Contact
Questions: privacy@magnusqa.ai. Security disclosures: security@magnusqa.ai.