Privacy
Last updated: 2026-08-15
ArgusLeaf is operated by an independent security researcher ("Operator"). Contact for privacy matters: [email protected].
| Category | Data | Retention |
|---|---|---|
| Account data | Name, email, organisation, domain, brand terms, phone number (used for identity verification at sign-up, not contacted directly), LinkedIn profiles, sector | Until account closure + 30 days |
| Verification data | DNS TXT record presence (token only — full TXT value not stored beyond verification) | Until monitoring is active |
| Technical / server logs | IP address, timestamp, HTTP method, user-agent, response code | 30 days |
| Submission fingerprints | Browser fingerprint metadata included in application emails for identity verification in case of disputes (user-agent, timezone, screen resolution, language, submission timestamp) | Retained with the email indefinitely |
| CT log data | Public metadata: domain names, certificate serials, issuer names, issuance dates | Indefinitely (public data) |
| Enrichment data | HTTP status codes, page titles, DNS records for matched domains | 90 days |
| Evidence screenshots | PNG screenshots of high-risk domains captured during enrichment; stored in private cloud storage | 90 days |
We don't sell data. We don't share personal data for advertising or marketing purposes. We use the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Brevo (Sendinblue SAS) | Transactional email delivery — OTP verification codes only. No personal data beyond email address is shared. | EU (France) |
| Cloudflare, Inc. | DDoS protection, CDN, WAF, DNS. Processes IP addresses and request metadata per Cloudflare's DPA. | US (with EU SCCs) |
All monitoring alert emails are delivered via our own SMTP infrastructure (not third-party platforms). We share no personal data except where legally compelled (court order, law enforcement request under applicable law).
To exercise any right, email [email protected]. We'll respond within 30 days.
We process personal data in accordance with Turkey's Personal Data Protection Law (KVKK, Law No. 6698). Data subjects may exercise their rights under Article 11 — including access, correction, deletion, and restriction — by writing to [email protected]. Requests will be addressed within 30 days.
We use one functional cookie: al-theme — stores your light/dark mode preference in browser localStorage. No tracking cookies. No analytics. No advertising cookies. No third-party scripts.
Server infrastructure is located in the European Union. We do not transfer personal data outside the EEA unless legally required.
We'll notify active users by email before material changes take effect, with at least 14 days notice. The "last updated" date at the top of this page will change accordingly.
Privacy questions: [email protected]