Legal

Privacy Policy

What we collect, why we collect it, and how long we keep it.

Scope

This policy describes the data handled by the Ilax Scan application. If you use a self-hosted deployment, the organization operating that deployment is responsible for its infrastructure, retention settings, and legal obligations.

Data we process

We process account identifiers such as your name and email, plan and subscription metadata, and the scan data you create. Scan data can include domains, network targets, discovered hosts, DNS records, HTTP and TLS metadata, open ports, technologies, endpoints, findings, and scan events.

Sensitive scan output

External scan secrets and Ilax Internal collected secrets can be encrypted at rest when a deployment encryption key is configured. Do not submit targets or information that you are not authorized to assess.

How we use your data

We use data to authenticate accounts, enforce plan limits, run requested scans, present results, process billing where configured, and operate the service. We do not use scan results to train third-party models or sell them as a data product.

Service providers

Payment processing is handled by the payment provider you choose at checkout, such as Razorpay. Infrastructure providers process data only as required to host the deployment. Scan results are not shared with other application accounts by default.

Retention and deletion

You can delete domains and scans through the dashboard where those controls are available. Account deletion and infrastructure-level retention are managed by the deployment operator. Backups may persist for a limited operational period.

Your rights

You may export eligible scan data in the formats offered by your plan. For access, correction, or deletion requests in a hosted deployment, contact the organization that provides your Ilax Scan account.

Read the Terms of Service and Security page for related information.