Legal

Privacy Policy

How PhredSec™ collects, uses, and protects your data when you use PhantomRed.

Last updated: April 22, 2026 · Effective: April 22, 2026
Table of Contents
  1. Information We Collect
  2. How We Use Your Information
  3. Data Storage & Retention
  4. Data Sharing
  5. Security
  6. Your Rights (GDPR / CCPA)
  7. Cookies
  8. Children's Privacy
  9. Changes to This Policy
  10. Contact Us
PhantomRed is built for ethical security testing. We never sell your data, never share scan results with third parties, and you always remain in full control of your information.

1 Information We Collect

We collect the minimum information necessary to provide the PhantomRed service:

We do not collect IP addresses for marketing purposes, and we do not use tracking pixels or third-party ad networks.

2 How We Use Your Information

Your information is used solely to provide and improve the PhantomRed service:

We will never use your scan data, findings, or target information for any purpose other than delivering your results to you.

3 Data Storage & Retention

Your data is stored in a PostgreSQL database hosted on Railway's infrastructure, located in the United States. We retain different categories of data for different periods based on operational and legal requirements.

Retention Schedule

Account Deletion

You may delete your account at any time from the Dashboard. Upon deletion:

Data Export & Deletion Requests

To request a copy of your data or to request deletion outside of the in-app flow, email privacy@phantomred.com. We will respond within 30 days. Include the email address associated with your account.

4 Data Sharing

We do not sell, rent, or trade your personal information to any third party.

We share data only with the following service providers, and only to the extent necessary to operate the service:

We may disclose information if required by law or to protect the rights, property, or safety of PhredSec™, our users, or the public.

5 Security

We take security seriously — it's literally what we do:

No system is 100% secure. If you discover a security vulnerability in PhantomRed, please disclose it responsibly to security@phantomred.com.

6 Your Rights (GDPR / CCPA)

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@phantomred.com. We will respond within 30 days.

7 Cookies

PhantomRed uses minimal browser storage:

You can clear your browser's local storage at any time to sign out of PhantomRed on that device.

8 Children's Privacy

PhantomRed is not intended for users under the age of 18. Security testing tools require legal authorization — minors cannot legally consent to terms that involve potential legal liability.

We do not knowingly collect personal information from anyone under 18. If we become aware that a minor has registered, we will delete their account immediately.

9 Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify registered users via email for material changes.

Your continued use of PhantomRed after any changes constitutes acceptance of the updated policy.

10 Contact Us

For any privacy-related questions, requests, or concerns: