Privacy Policy
Last updated: August 26, 2026. NetRiskScan processes the information needed to deliver network diagnostics, operate developer accounts and paid API subscriptions, protect the service and understand aggregate usage.
IP addresses and diagnostic data
Your public IP address is necessarily visible to our servers. When you run a test, we process the submitted address and relevant connection signals to return the result. Query and security logs may contain IP addresses, timestamps, user-agent information, request paths and diagnostic outcomes.
Developer accounts
If you register a developer account, we process the data needed to run that account: your email address, authentication data for your password (stored as a salted hash, never as recoverable plaintext), account and email-verification status, metadata about your API credentials, your API usage records, and login and security logs used to detect abuse and protect the account.
API key secrets are not stored in a form we can read back. A full key is displayed to you once, at creation or rotation, and only a prefix, a last-four fragment and a one-way hash are retained — so we cannot recover a lost key for you, and a database disclosure would not expose usable keys.
Payments
Payments are processed by Stripe. NetRiskScan does not directly store complete card numbers or card security codes. Card details are entered into Stripe-hosted payment components (Stripe Checkout and the Stripe Customer Portal), not into NetRiskScan forms, and are handled by Stripe under its own privacy policy and payment-security obligations. Stripe may process payment, billing and fraud-prevention information in accordance with Stripe's own privacy policy.
Billing records
To operate subscriptions we retain billing records associated with your account: the Stripe customer identifier, the subscription identifier, the plan, subscription status, current billing period, cancellation state and payment-related status such as whether the latest invoice was paid or failed. We do not retain full card numbers, expiry dates or security codes.
Cookies and local storage
We may use essential browser storage for preferences, session security, developer and administrator authentication, and CSRF protection. Analytics or advertising cookies are used only when the corresponding service is enabled and subject to applicable consent requirements.
Analytics and advertising
We may use privacy-conscious analytics to understand aggregate traffic and page performance. If Google AdSense or another advertising service is enabled, that provider may use cookies or similar technologies to deliver, measure and limit ads. This policy will identify material advertising integrations as they are activated.
Third-party services
Network results may rely on third-party IP intelligence, geolocation, abuse, status or infrastructure services. Requests are limited to information needed for the diagnostic feature. Payment processing relies on Stripe as described above. Those providers handle data under their own privacy terms.
Retention and security
Operational logs are retained only as long as reasonably needed for security, troubleshooting, abuse prevention and legal obligations. Billing and account records are retained while the account exists and afterwards where required for accounting, tax or legal purposes. Retention periods can vary by record type. We use access controls and reasonable technical safeguards, but no internet service can promise absolute security.
Your choices
You can avoid optional analytics or advertising storage where consent controls are offered. Contact support@netriskscan.com with access, deletion, correction or other privacy questions that apply in your jurisdiction. Deleting a developer account does not remove billing records we are required to keep.