Privacy Policy
Effective Date: September 3, 2026
Tech Cavalry LLC (“Company,” “we,” “us,” or “our”), a Pennsylvania limited liability company, respects your privacy and operational security (OpSec). This Privacy Policy explains how we collect, use, retain, and protect your information when you use our domain intelligence, investigation, and OSINT tools.
1. Information We Collect
We limit data collection to what is necessary to operate our tools, manage usage credits, enforce rate limits, and maintain security.
- Account Information: When you create an account or sign in using Google OAuth, we collect and store only your email address and a unique user ID (UID) via Firebase Authentication. We do not store or request display names, phone numbers, or physical addresses.
- Query & Investigation Data: When you run a query (such as WHOIS lookups, DNS resolutions, screenshots, or AI abuse coaching), we store the target domain or hostname searched.
- Logged-in Users: Queries are associated with your account UID to maintain your credit transaction history and saved scan results.
- Anonymous Users: Queries are associated with a cryptographically hashed version of your IP address (
hashed_IP). We do not store your raw IP address alongside search logs.
- Payment Information: Payment card processing is handled entirely by Stripe via Stripe-hosted checkout pages. Tech Cavalry LLC never receives, processes, or stores raw credit card numbers or banking credentials.
- Automated Security & Analytics: We use Google reCAPTCHA for bot prevention and rate limiting. We also use Google Analytics to gather aggregated, non-identifying traffic statistics to optimize site performance.
2. How We Use Your Information
We use the information collected strictly for the following operational purposes:
- Executing requested domain lookups, automated screenshots, visual link graphs, and analysis tools.
- Tracking and deducting daily free credits and purchased credit pack balances.
- Preventing automated scraping and platform abuse via hashed IP rate limiting and bot detection.
- Sending essential transactional emails (e.g., account updates or credit transaction receipts) via Resend.
- Generating customized abuse reports using AI models.
3. Operational Security & Confidentiality Guarantees
We recognize that OSINT researchers, threat intelligence analysts, and domain investigators require high standards of confidentiality.
- No Data Sales or Public Indexing: Your search queries, investigation logs, and screenshot results are private. We never sell, rent, or trade user search queries to data brokers or third parties, nor do we publicly index or broadcast your searches on public dashboards.
- Third-Party Infrastructure & API Providers: To execute queries, we interface with specialized infrastructure providers:
- Bright Data: Used for datacenter proxies and web unlocker automation to fetch WHOIS and site screenshot data securely.
- Resend: Used to dispatch transactional email communications.
- Stripe: Handles all payment processing and checkout sessions.
- Google Gemini AI: Used to generate tailored abuse report drafts within the Abuse Report Coach tool.
- AI Model Privacy Exemption: Any domain indicators, WHOIS metadata, or text passed to Google Gemini AI via our API integrations are strictly excluded from AI model training or dataset retention by the provider.
4. Data Retention Policy
Scan history, cached WHOIS/DNS payloads, and generated screenshot assets are retained according to access level:
- Anonymous Searches: Search logs and cached outputs associated with hashed IP addresses are automatically purged after 7 days.
- Logged-In Users (Standard): Investigation history and tool outputs are stored in Firestore and Cloud Storage for 30 days to allow you to review recent work without re-expending credits.
- Extended Retention (Paid Queries): Paid queries or custom workspace configurations may offer extended retention of up to 365 days (1 year) upon user selection.
You may request manual deletion of your account and associated search history at any time by contacting us.
5. Cookies & Analytics
We use essential session cookies to maintain your logged-in state, manage security verification, and track credit usage.
Third-party analytics (Google Analytics) and bot mitigation tools (Google reCAPTCHA) may set cookies or collect device signals to verify human interaction and track general website usage patterns. You can manage or disable cookies through your web browser settings, though certain functional features of the platform may require cookies to operate properly.
6. Contact Information & Data Rights
Under applicable privacy laws, you have the right to request access to the personal data we hold about you (your registered email and associated scan history) or request its complete deletion from our active databases.
For privacy inquiries, data deletion requests, or questions regarding our operational security practices, contact us at:
Tech Cavalry LLC
State of Incorporation: Pennsylvania, USA
Privacy Contact Email: privacy@techcavarly.com
