Legal
Privacy Policy
What Vicaratva collects when you scan a URL or hold an account, why, and how long it is kept.
Last updated · Vicaratva, operated by Merlinvicki Creative Services Pvt. Ltd.
Who is responsible
Merlinvicki Creative Services Pvt. Ltd. (“we”) operates Vicaratva and is the data controller for personal data processed through it.
What we collect
When you run a scan without an account
- The URL you submit and the audit results generated from it.
- A hashed IP address. Your IP is put through SHA-256 and only the hash is stored — used for rate limiting and to verify ownership if you later claim the report. The raw address is never written to our database.
Anonymous reports are deleted automatically 30 days after creation. Claiming a report links it to your account and removes that expiry.
When you hold an account
- Email address, and name if you provide one or your OAuth provider supplies it.
- Authentication data — a hashed password, or your GitHub account identifier.
- Two-factor secrets and recovery codes, if you enable 2FA.
- Your saved reports and scan history.
- Subscription and plan state. Card details go to Stripe and never reach our servers.
What we send to third parties
Running an audit necessarily involves other processors. The full list, what each receives and where it operates is maintained on the Data Processing page.
Two points worth stating plainly. First, UX, CRO and privacy audits send the text content of the page being scanned to Anthropic’s API to generate the written findings. Second, when you scan a URL our headless browser requests that page from its host, which will see the request in its own logs.
What we do not do
- We do not sell personal data.
- We do not run third-party advertising or cross-site tracking on this site.
- We do not store raw IP addresses.
Scanning sites you do not own
Vicaratva fetches publicly reachable URLs. If you submit a URL, you are asserting you are entitled to have it tested. Requests to private, loopback and internal network ranges are blocked before any connection is made.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to or restrict certain processing. You can delete individual reports and deactivate your account from within the app, or email hello@vicaratva.com.
Retention
- Anonymous reports — 30 days from creation.
- Account reports — until you delete them or close your account.
- Rate-limit records — held in memory only and cleared when the service restarts.
Changes
We will update the date at the top of this page when this policy changes, and notify account holders by email where the change is material.
Questions about this document? Email hello@vicaratva.com.