Privacy Policy

    Last updated: July 21, 2026

    What this covers

    This policy explains what data PTKD (the mobile app security scanning service at ptkd.com and app.ptkd.com) collects, why, how long it is kept, and the rights you have over it. For any privacy question or request, contact [email protected].

    Data we collect, and why

    • Account data — email address, name, and (if you set one) a password stored only as a bcrypt hash. Used to operate your account. If you sign in with Google, we receive your email and name from Google; we never see your Google password.
    • App binaries you upload (APK/IPA) — processed to run the security scan, checked for malware, then deleted from storage within 24 hours. Scan results are kept so you can review findings.
    • Payment data — handled by Stripe; PTKD never stores card numbers.
    • Operational logs — session records (IP address, browser user-agent), an audit trail of account and workspace actions, and email delivery status. Used for security, abuse prevention, and support.
    • Support messages — problem reports and tickets you submit.

    We run no advertising or analytics trackers. Fonts and all page assets are served from our own domain — visiting our sites triggers no requests to third-party trackers.

    Cookies

    The app uses a single strictly-necessary session cookie to keep you signed in. There are no analytics, advertising, or cross-site cookies, which is why you do not see a cookie banner.

    Retention

    • • Uploaded binaries: deleted within 24 hours of upload.
    • • Scan results: kept until you delete them, your workspace's own retention policy purges them, or your account is deleted.
    • • Account data: deleted when you delete your account (self-service, below).
    • • Operational and audit logs: kept only as long as needed for security and legal obligations.

    Where data is processed

    PTKD runs on infrastructure hosted in the United States. The service providers that process data on our behalf are:

    • Railway — application hosting, database, and file storage (US)
    • Cloudflare — DNS and network security in front of our sites
    • Resend — transactional email delivery
    • Stripe — payment processing
    • Google — only if you choose "Sign in with Google"

    Where the GDPR applies to you, transfers outside the EEA rely on these providers' EU-approved transfer mechanisms (EU-U.S. Data Privacy Framework certification or Standard Contractual Clauses).

    Your rights

    • Access & rectification — view and edit your account data in the app's account settings.
    • Erasure — delete your account yourself in Account → Delete account (works for both password and Google sign-in accounts); this permanently removes your data.
    • Portability — export your workspace's data as JSON from workspace settings.
    • Email choices — as an account holder you may receive product news and marketing about PTKD; every non-essential email carries a one-click unsubscribe link and a preference center, and opting out never affects your account.
    • Objection, restriction, complaints — write to [email protected]; you also have the right to complain to your local data-protection authority.

    Security

    • • All traffic is encrypted in transit (TLS, HSTS-enforced).
    • • Passwords are stored only as bcrypt hashes; 2FA and SSO secrets are stored encrypted.
    • • Uploads are malware-scanned before processing and purged within 24 hours.
    • • Accounts lock automatically after repeated failed sign-in attempts, and sensitive actions are rate-limited and audited.
    • • Databases are backed up automatically and backups are verified.