Privacy Policy
Last updated August 20, 2026
This is a product-stage draft of our Privacy Policy, based on how Nyrolo Trust actually works today. It should be reviewed by qualified legal counsel — particularly for jurisdiction-specific requirements — before being relied on as a final legal document.
1. Introduction
This Privacy Policy describes how Nyrolo Trust ("Nyrolo," "we," "us") handles information when you visit our website or use the Nyrolo Trust service (the "Service").
2. Information We Collect
We collect the following categories of information:
- Account information. When you create an account, we collect your name, email address, and password. Your password is handled by our authentication provider, Supabase, and is not stored by Nyrolo in plain text.
- Scan information. When you submit a website URL to be scanned, we store that URL, the resolved hostname, the scan's status, the resulting trust score, and the full structured check breakdown (including any external reputation result — see Section 4) against your account.
- Feedback you submit. The feedback form collects what you liked, what confused you, whether you'd use Nyrolo again, a numeric rating, and any comments. If you're signed in when you submit feedback, it's associated with your account; feedback can also be submitted anonymously.
- Usage and analytics information. We use Google Analytics and Microsoft Clarity to understand how the product is used (see Section 5). These services may collect technical information such as your browser, device, approximate location, and pages visited.
3. How We Use Information
We use the information described above to:
- Provide and operate the Nyrolo Trust service
- Authenticate you and keep your account secure
- Perform the website scans you request and store your scan history
- Respond to feedback, questions, and support requests
- Understand product usage and improve Nyrolo Trust
- Detect and prevent abuse of the Service
We do not sell your personal data.
4. Website URLs Submitted for Scanning
When you submit a URL to be scanned, Nyrolo Trust's server makes a live HTTP request to that site to read its public response headers and TLS certificate — the same information a browser would see when visiting the page. We do not send any of your personal data (your name, email, or account details) to the site being scanned.
Where configured, Nyrolo Trust may also check the submitted domain against an external reputation/threat-intelligence provider (currently, Google Safe Browsing) to determine whether it has a known association with malicious activity. This capability is only active when the corresponding provider is configured on the server; when it isn't, the scan clearly reports reputation as "not checked" rather than implying a result exists. When it does run, the domain or URL you submitted is shared with that provider for the purpose of the lookup.
5. Third-Party Services
Nyrolo Trust relies on the following third-party services:
- Supabase — provides authentication and database hosting for account, scan, and feedback data.
- Google Analytics — provides aggregate usage analytics for the website.
- Microsoft Clarity — provides usage analytics and session insights for the website.
- Google Safe Browsing — an optional reputation/threat-intelligence check used during a scan, when configured (see Section 4).
We don't use any other third-party data or analytics providers today.
6. Cookies and Similar Technologies
Nyrolo Trust uses cookies. Signing in sets a first-party session cookie (via Supabase) that keeps you authenticated and is required for the dashboard and scanning features to work. When enabled, Google Analytics and Microsoft Clarity also set their own cookies to distinguish visitors and measure usage. We do not currently present a cookie-consent banner; where one is legally required for your jurisdiction, treat this as an item to be addressed before launch in that jurisdiction.
7. Data Retention
Your account and scan history are retained for as long as your account exists, or until you delete individual scans yourself. We haven't defined a fixed retention period beyond that; in general, we retain information for as long as necessary to provide the Service, maintain security, comply with legal obligations, or resolve disputes. Deleting your account removes your account data; associated scan history is removed with it.
8. Data Security
We use reasonable technical and organizational measures — including row-level access controls on our database and encrypted connections — to help protect information against unauthorized access, disclosure, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you. You can update your account details in the app, delete individual scans yourself, and contact us (Section 12) to request account deletion or ask about the data we hold. We have not yet formally established which specific data-protection regimes (for example, GDPR or CCPA) apply to the Service — this should be confirmed as part of a legal review before this policy is treated as final for a given jurisdiction.
10. Children's Privacy
Nyrolo Trust is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us (Section 12) and we will take appropriate steps to remove it.
11. Changes to This Privacy Policy
We may update this Privacy Policy as Nyrolo Trust evolves. When we do, we'll post the updated version on this page and update the "Last updated" date above.
12. Contact
Questions about this policy or your data can be sent to support@nyrolo.com or through our contact page. See also our Terms of Service.