Privacy Policy
Last updated: February 11, 2026
1. Introduction
ScanU ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our visual regression testing platform.
We are compliant with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
ScanU.eu is the data controller for the personal data collected through our platform. For any privacy-related inquiries, please contact us at: privacy@scanyou.eu
3. Data We Collect
3.1 Account Information
- Email address (required for account creation)
- Name (optional)
- Password (securely hashed, never stored in plain text)
3.2 Project Data
- Project names and website URLs you choose to test
- Test configuration settings (browsers, resolutions, thresholds)
- Screenshots of websites you test
- Visual diff comparisons
3.3 Usage Data
- Number of tests run
- Subscription tier and billing status
- Timestamps of account activities
3.4 Technical Data
- IP address (for rate limiting and security)
- Browser type and version (for error tracking)
4. How We Use Your Data
We use your data to:
- Provide and maintain our visual regression testing service
- Process your subscription payments via Stripe
- Communicate with you about your account and service updates
- Improve our platform and develop new features
- Ensure security and prevent abuse
- Comply with legal obligations
5. Legal Basis for Processing (GDPR)
Under GDPR, we process your data based on:
- Contract performance: To provide the services you signed up for
- Legitimate interests: To improve our services and ensure security
- Legal obligations: To comply with applicable laws
- Consent: Where specifically requested
6. Data Storage and Retention
Account data is stored in a managed PostgreSQL database in the EU (eu-central-1), and screenshots and related media are stored in DigitalOcean Spaces object storage in the Frankfurt (fra1) region. Our screenshot workers run on DigitalOcean infrastructure in Frankfurt.
Retention periods:
- Screenshots and related media: retained while the associated run, project, and account exist, and permanently deleted — with the deletion verified against object storage — when you delete the run, the project, or your account. Plan-level history figures describe product access windows, not automatic deletion schedules.
- Account data: deleted immediately upon confirmed erasure when you delete your account — not retained for a further period.
- Billing records: retained in pseudonymised form for the statutory period (up to 10 years) after account deletion, as required by German commercial and tax law (HGB §257, AO §147, §14b UStG). The link to your identity is erased; the financial record itself must be kept (Art. 17(3)(b) GDPR).
7. Processing Locations and International Transfers
We want this to be precise rather than reassuring, because the distinction matters for your own compliance assessment:
- Application processing runs in the EU. The server functions that handle your account, authentication, screenshots and billing data are configured to execute in the Frankfurt (fra1) region.
- Delivery and routing use a global network. Our hosting provider (Vercel) operates a worldwide edge network that terminates TLS and routes requests. As a result, request metadata — including IP address, connection details and the URL path of the page you request — may be processed by that infrastructure outside the EU before the request reaches our EU application functions. URL paths can contain identifiers such as a project or test-run ID.
- No credentials are verified at that layer. Our edge routing code does not read authentication cookies and does not verify session tokens; every authentication decision is made by the EU-region application functions.
- Some processors operate outside the EU. Where that is the case (see the list below), transfers rely on the transfer mechanism agreed with that provider, such as EU Standard Contractual Clauses.
We do not claim that no data ever leaves the EU. If you need a transfer impact assessment or a data processing agreement covering these flows, contact us at the address in the Impressum.
8. Third-Party Services
We use the following third-party services:
- Vercel: Application hosting and global edge delivery (application functions configured for the EU; edge network worldwide)
- Neon: Managed PostgreSQL database (EU, eu-central-1)
- DigitalOcean: Screenshot workers and object storage (Frankfurt, fra1)
- Stripe: Payment processing (PCI-DSS compliant)
- Sentry: Error monitoring (for service reliability)
- Cloudflare: Turnstile bot protection on public forms
9. Your Rights (GDPR)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Data portability: Receive your data in a structured, machine-readable format (JSON)
- Restriction: Request limitation of data processing
- Objection: Object to certain types of processing
- Withdraw consent: Withdraw cookie consent at any time via the "Cookie Settings" link in the footer
How to Exercise Your Rights
- Data Export: Use the "Export My Data" button in your Account Settings to download all your personal data in JSON format
- Account Deletion: Use the "Delete Account" option in your Account Settings to permanently delete your account and your personal data. Billing records required by law are retained in pseudonymised form for the statutory period — see "Retention periods" above.
- Cookie Preferences: Click "Cookie Settings" in the footer on any page to update your cookie consent choices
- Contact Us: For any other requests, email us at privacy@scanyou.eu
We will respond to all data rights requests within 30 days as required by GDPR.
10. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS)
- Secure password hashing (bcrypt)
- Access controls and authentication
- Regular security assessments
- Rate limiting and abuse prevention
11. Cookies
We use cookies to operate our website. When you first visit, a cookie consent banner allows you to accept or reject non-essential cookies. Essential cookies (for authentication and session management) are always active as they are strictly necessary for the website to function.
We categorize cookies into four types: Essential, Functional, Analytics, and Marketing. No non-essential cookies are set until you give explicit consent. You can change your cookie preferences at any time by clicking the "Cookie Settings" link in the website footer.
For full details about the cookies we use, their purposes, and durations, please see our Cookie Policy.
12. Children's Privacy
Our service is not directed to children under 16. We do not knowingly collect personal data from children under 16.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a notice on our platform.
14. Contact Us
For any questions about this Privacy Policy or our data practices, contact us at:
Email: privacy@scanyou.eu
Data Protection Officer: dpo@scanyou.eu
15. Supervisory Authority
If you are in the EU and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority.