Glarion

Privacy Policy

Last updated 30 August 2026

This is a small, single-operator service. Where this policy names "we" or "us", it means one person — see Who we are below — not a department. If anything here is unclear, the fastest way to get an answer is to write to the address at the bottom of this page.

Who we are

Glarion is operated by Aurelio Avila, trading as an individual at this stage rather than through a registered company. For the purposes of data protection law, Aurelio Avila is the data controller for the personal data described below.

What we collect, and why

DataWhy
Name, email address, date of birth, password (stored as a hash, never in plain text) To create and secure your account, and to confirm you are old enough to hold a paid contract.
Business name and logo, if you add them To put your identity, not ours, on the reports you send to your clients.
The domains you add, and any client name you attach to them To run the scans and reports you ask for. This is data about your clients' sites, which you control — see Acting on your behalf.
IP address and browser identifier at the moment you authorize a scan Recorded permanently as evidence of who authorized a scan against a domain and when. This is the record that protects both of us if a scan is ever disputed — see Retention for why it outlives the rest of your account.
Payment details Never collected by us. Checkout and billing are handled entirely by Stripe — see Who else touches your data.

The legal basis for each

Acting on your behalf

The domains you add and the findings a scan produces are, legally, your data or your client's — we process it because you asked us to, not because we have a use for it of our own. We do not scan a domain you have not proven you control, and we do not sell, share, or use scan results for anything beyond running the product you asked for.

Who else touches your data

ServiceWhat it handles
Supabase (Postgres, EU region)Stores the account and scan data described above.
Fly.ioRuns the application.
StripeProcesses payment and stores payment details — we never see a card number.
ResendDelivers transactional email (confirmation links, scan notifications).
ProjectDiscovery Nuclei (open-source, run on our own servers)Performs the scan itself; nothing is sent to a third party by the scanner.

None of the above is paid to run analytics or advertising against your data, because none of it exists here — see Cookies and tracking.

Retention

Your account data is kept for as long as the account exists. If you delete your account, your name, email, date of birth, and password are permanently overwritten within the same request — see Deleting your account.

The scan-authorization record described above is the one exception. It is kept after deletion, stripped of everything except the fact that an account authorized this scan on this date from this address — the law explicitly allows keeping exactly this much, for exactly this reason (Article 17(3)(e)).

Deleting your account

From Settings, "Delete my account" removes your name, email, date of birth, business identity, and password immediately and irreversibly. A subscription has to be cancelled first, from Manage billing — we do not cancel it for you as a side effect of deletion, for the same reason cancelling always goes through Stripe's own portal rather than a button here.

Your rights

Under GDPR you can ask us to:

Write to the address below for any of these. If you are not satisfied with the answer, you can complain to the Garante per la protezione dei dati personali, the Italian data protection authority.

Cookies and tracking

Glarion sets no analytics, advertising, or tracking cookies. The only thing stored in your browser is the session token that keeps you signed in, which is not a cookie and is never sent to anyone but this site.

Changes to this policy

If this changes in a way that matters — a new sub-processor, a change to what we collect — we will say so here and update the date at the top.

Contact

aurelio_11@outlook.it