Legal
Data Processing
The sub-processors that receive data when you run an audit, and the measures protecting it.
Last updated · Vicaratva, operated by Merlinvicki Creative Services Pvt. Ltd.
Roles
For your account data, Merlinvicki Creative Services Pvt. Ltd. acts as controller. Where you scan a site you operate and that scan captures personal data belonging to your own users, we act as processor on your instructions.
Sub-processors
We use the following third parties. We will update this list before adding a new sub-processor that handles personal data.
| Sub-processor | Purpose | Data received | Region |
|---|---|---|---|
| Anthropic | Generates UX, CRO and privacy audit narratives from page content | Stripped page HTML, collected scan signals | United States |
| Stripe | Subscription billing and payment processing | Name, email, billing details | United States / Ireland |
| Resend | Transactional and authentication email delivery | Email address, message content | United States |
| Google PageSpeed Insights | Performance metrics for scanned URLs | The public URL being scanned | United States |
Page content sent to Anthropic
This deserves calling out separately. For UX, CRO and privacy audits we strip scripts and styles from the scanned page, truncate the remaining markup, and send it to Anthropic’s API so a model can write the findings. If the page you scan contains personal data in its markup, that data is included. Do not scan authenticated or sensitive pages you would not want processed this way.
International transfers
Several sub-processors operate outside India and the EEA, so audit and account data may be transferred internationally.
Security measures
- All traffic served over HTTPS.
- Passwords stored as salted hashes; optional TOTP two-factor authentication.
- IP addresses stored only as SHA-256 hashes — never in raw form.
- Scanner requests are validated against an SSRF guard that resolves DNS and blocks private, loopback and carrier-grade NAT ranges before any connection is made.
- Rate limiting on scan endpoints to prevent abuse of the service and of scanned hosts.
- Anonymous report data expires automatically after 30 days.
Sub-processor changes and incidents
Related documents
See the Privacy Policy for what we collect and Terms of Service for the scope and limits of the reports.
Questions about this document? Email hello@vicaratva.com.