Privacy Policy
Last updated 30 August 2026
This is a small, single-operator service. Where this policy names "we" or "us", it means one person — see Who we are below — not a department. If anything here is unclear, the fastest way to get an answer is to write to the address at the bottom of this page.
Who we are
Glarion is operated by Aurelio Avila, trading as an individual at this stage rather than through a registered company. For the purposes of data protection law, Aurelio Avila is the data controller for the personal data described below.
What we collect, and why
| Data | Why |
|---|---|
| Name, email address, date of birth, password (stored as a hash, never in plain text) | To create and secure your account, and to confirm you are old enough to hold a paid contract. |
| Business name and logo, if you add them | To put your identity, not ours, on the reports you send to your clients. |
| The domains you add, and any client name you attach to them | To run the scans and reports you ask for. This is data about your clients' sites, which you control — see Acting on your behalf. |
| IP address and browser identifier at the moment you authorize a scan | Recorded permanently as evidence of who authorized a scan against a domain and when. This is the record that protects both of us if a scan is ever disputed — see Retention for why it outlives the rest of your account. |
| Payment details | Never collected by us. Checkout and billing are handled entirely by Stripe — see Who else touches your data. |
The legal basis for each
- Account, scanning, and billing data — necessary to perform the contract you enter by creating an account (Article 6(1)(b) GDPR).
- Date of birth — a legal obligation, since a contract cannot be entered into with a minor (Article 6(1)(c)).
- The scan-authorization record (IP address, browser identifier, timestamp) — our legitimate interest in being able to prove who authorized a scan, which is also the legal basis the law allows us to keep it on after you delete your account (Article 6(1)(f) and Article 17(3)(e)).
Acting on your behalf
The domains you add and the findings a scan produces are, legally, your data or your client's — we process it because you asked us to, not because we have a use for it of our own. We do not scan a domain you have not proven you control, and we do not sell, share, or use scan results for anything beyond running the product you asked for.
Who else touches your data
| Service | What it handles |
|---|---|
| Supabase (Postgres, EU region) | Stores the account and scan data described above. |
| Fly.io | Runs the application. |
| Stripe | Processes payment and stores payment details — we never see a card number. |
| Resend | Delivers transactional email (confirmation links, scan notifications). |
| ProjectDiscovery Nuclei (open-source, run on our own servers) | Performs the scan itself; nothing is sent to a third party by the scanner. |
None of the above is paid to run analytics or advertising against your data, because none of it exists here — see Cookies and tracking.
Retention
Your account data is kept for as long as the account exists. If you delete your account, your name, email, date of birth, and password are permanently overwritten within the same request — see Deleting your account.
The scan-authorization record described above is the one exception. It is kept after deletion, stripped of everything except the fact that an account authorized this scan on this date from this address — the law explicitly allows keeping exactly this much, for exactly this reason (Article 17(3)(e)).
Deleting your account
From Settings, "Delete my account" removes your name, email, date of birth, business identity, and password immediately and irreversibly. A subscription has to be cancelled first, from Manage billing — we do not cancel it for you as a side effect of deletion, for the same reason cancelling always goes through Stripe's own portal rather than a button here.
Your rights
Under GDPR you can ask us to:
- Send you a copy of the personal data we hold about you.
- Correct anything that is wrong — most of this you can already edit yourself in Settings.
- Delete your account, as above.
- Object to how we use your data, where our legal basis is legitimate interest.
Write to the address below for any of these. If you are not satisfied with the answer, you can complain to the Garante per la protezione dei dati personali, the Italian data protection authority.
Cookies and tracking
Glarion sets no analytics, advertising, or tracking cookies. The only thing stored in your browser is the session token that keeps you signed in, which is not a cookie and is never sent to anyone but this site.
Changes to this policy
If this changes in a way that matters — a new sub-processor, a change to what we collect — we will say so here and update the date at the top.