Privacy Policy
Talon Audit is a website-analysis tool. When you submit a URL, we fetch and render that website on your behalf so it can be inspected. This policy explains what we collect about you, and how we handle the content of the sites you analyse.
01 Scope & who we are
Talon Audit ("Talon Audit", "the Service") is operated by RaptorLabs ("we", "us", "our"). This policy applies to the Talon Audit website and application. For personal data of users in the EEA and UK, RaptorLabs acts as the data controller for account and usage data, and as a data processor for the website content you direct us to analyse.
02 Information we collect
Account data
- Your email address.
- A cryptographic hash of your password (we never store or see your plaintext password — it is salted and hashed with PBKDF2 before storage).
- Account timestamps (created, last sign-in).
Analysis data
- The URLs you submit for analysis.
- The rendered HTML, a screenshot, and structural signals of the target page, captured at the moment of analysis.
- The findings, scores and generated fix recommendations produced from that page.
Technical data
- A single essential session cookie (
talon_session) to keep you signed in — see the Cookie Policy. - Standard server and edge logs (IP address, request time, user agent) generated by our infrastructure provider for security and reliability.
- Aggregate, anonymous page-view analytics from Plausible, a cookieless analytics service — see the Cookie Policy for details.
We do not use advertising cookies, cross-site tracking pixels, or sell any data. Our analytics provider does not use cookies or persistent identifiers and cannot track you across sites.
03 How we use information
- To run the analyses you request and return findings and recommendations.
- To create and secure your account and keep you signed in.
- To store your analyses privately so you can revisit prior reports. Analyses are never published or listed publicly.
- To operate, secure, debug and improve the Service, and to prevent abuse.
- To comply with legal obligations and enforce our Terms and Acceptable Use Policy.
We do not use your submitted content or account data to train foundation models.
04 Legal bases (GDPR / UK GDPR)
- Contract — to provide the Service you request.
- Legitimate interests — to secure, maintain and improve the Service and prevent misuse, balanced against your rights.
- Consent — where required, e.g. optional communications; you may withdraw it at any time.
- Legal obligation — where processing is required by law.
05 Infrastructure & sub-processors
The Service runs entirely on Cloudflare's global platform. To deliver analyses we use the following categories of processing, all provided by Cloudflare, Inc.:
- Edge compute & hosting — to serve the application and run analyses.
- Headless browser rendering — to load and capture the target website you submit.
- AI inference — the submitted page content is processed by machine-learning models to reason about findings. This processing occurs within the infrastructure provider's platform; content is sent to the models only to produce your report.
- Object storage, database and edge cache — to store reports, screenshots, your account record and session state.
We also use one further sub-processor:
- Plausible Analytics (Plausible.io) — website analytics. Plausible is cookieless, uses no persistent identifiers, and cannot track you across sites; it only reports aggregate, anonymous page-view counts.
Cloudflare and Plausible act as our sub-processors under their respective data-processing terms. We do not transfer your data to advertising networks or data brokers.
06 Websites you analyse (important)
When you submit a URL, you instruct us to fetch and render that website. You are responsible for ensuring you own the target or are otherwise authorised to test it, as required by our Acceptable Use Policy. Captured page content may incidentally include personal data present on that page; we process it solely to produce your analysis and act as your processor for that content. Do not submit targets you are not authorised to test.
07 Data retention
- Account data — kept while your account is active, then deleted within 30 days of account closure or an accepted deletion request.
- Reports & screenshots — reports owned by signed-in accounts are retained so you can revisit them until you delete the report, delete your account or submit an accepted deletion request.
- Operational logs — request and diagnostic logs are handled by our infrastructure provider (Cloudflare) and automatically rotated after a short period (currently on the order of a few days); we do not retain long-term raw logs ourselves.
We do not store raw response bodies, cookie values or browser-storage values; sensitive values (tokens, cookies, authentication headers) are redacted before any evidence is stored. Signed-in users can delete reports and accounts in the dashboard, or request deletion at any time (see §09); we complete accepted deletions within 30 days.
08 Security
We apply industry-standard safeguards: TLS in transit, salted PBKDF2 password hashing, HttpOnly, Secure, SameSite session cookies signed with HMAC, least-privilege access, and an edge-only architecture with no self-managed origin servers. No method of transmission or storage is perfectly secure, but we work to protect your data proportionate to its sensitivity.
09 Your rights
Depending on your location (including under GDPR, UK GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, port, restrict or object to processing of your personal data, and to withdraw consent. California residents have the right not to be discriminated against for exercising these rights; we do not sell or "share" personal information as those terms are defined under the CCPA/CPRA.
To exercise any right, contact us at privacy@raptorlabs.dev. We will respond within the timeframe required by applicable law. You may also lodge a complaint with your local data-protection authority.
10 Children & changes & contact
The Service is not directed to children under 16, and we do not knowingly collect their data. We may update this policy; material changes will be posted here with a revised effective date. Questions or requests: privacy@raptorlabs.dev.