Privacy Policy

Last updated: 9 September 2026

ReconScope is a free cyber-exposure diagnostic service. This page explains what data we process, why, how long we keep it, and what control you have over it. It is written to be read, not to be skimmed past.

Who to talk to

ReconScope operates the service available at reconscope.com.

For any question about this policy, or to exercise any of the rights described below, write to contact@reconscope.com. We answer within one month.

What we process

We process three sets of data, depending on what you do on the service.

  • Running a scan. The domain name you submit, the result of the scan (score, findings, the public data collected), the date and the number of times that domain has been submitted. No account is required for this.
  • Creating an account. Your email address, a password (stored hashed with bcrypt, never in clear text), the status and tier of your account, its creation and last-login dates, and the list of scans you have run.
  • Asking to be contacted or to receive a report. Your email address, optionally your company name, and a snapshot of the diagnostic concerned (domain, score, main findings).

A scan only reads public data

ReconScope never connects to the infrastructure it analyses. Every module queries open sources: DNS records, Certificate Transparency logs, search-engine indexes, public registries and public breach databases. It is a passive diagnostic, not a penetration test, and it requires no authorisation to run because it touches nothing you own.

This also means a scan can be run on a domain by someone who does not own it. If a diagnostic concerning a domain you are responsible for has been published through a permalink and you want it removed, write to contact@reconscope.com and we will delete it.

Audience measurement

We measure site traffic with Umami, which we host ourselves. It sets no tracking cookie, builds no advertising profile, and shares nothing with ad networks. The data is aggregated — page views, referrer, device type — and is used only to understand how the site is used.

Cookies and local storage

We use no advertising cookie and no third-party tracker. The site stores only what it needs to work:

  • rh_user — a strictly necessary session cookie, set when you sign in so that your session persists. It is httpOnly, meaning page JavaScript cannot read it.
  • language — your language preference, kept in your browser local storage so we do not ask again.
  • rh_admin_token — the internal console session token, for administrators only.

Who else sees your data

We do not sell, rent or trade your data, and we never pass it to a third party for that party to prospect on its own behalf. It reaches only the providers the service needs to run:

  • Anthropic. The plain-language summary of your diagnostic is written by a Claude model, and the technical content of the scan is sent for that generation alone. This module can be switched off and the service stays fully functional without it.
  • Our hosting provider, which runs the site, the API and the database.
  • Our email provider, used for account activation links and for sending reports.

How long we keep it

  • Scan results. Kept so that a permalink stays shareable and so an analysis is not needlessly re-run. A public scan can be refreshed at any time; a private scan belongs to the account that ran it and is deleted with that account.
  • User accounts. Kept for as long as the account exists. Deleting it also deletes the private scans attached to it.
  • Contact requests. Kept for the duration of the commercial follow-up, then deleted on request.
  • Audience measurement. Aggregated data, with no individual identification.

Your rights

Under the GDPR you have the right to access, correct, erase, restrict, object to and port the data concerning you.

To exercise any of them, write to contact@reconscope.com, stating the domain or the email address concerned. If you believe your rights have not been respected, you may lodge a complaint with the CNIL, the French data protection authority, at cnil.fr.

How we protect it

The site is served over HTTPS only, with HSTS, a strict Content Security Policy, and headers that forbid embedding the site in a third-party iframe. Passwords are hashed with bcrypt. Scan result pages and the internal console are never indexed by search engines, and a locked finding is never serialised to the browser at all — only its shape is sent.

Changes to this policy

This policy will evolve with the service. The date at the top of this page is the date of the latest version, and any substantial change will be reflected there.

Back to home