Legal
Privacy Policy
Last updated September 4, 2026
This Privacy Policy explains how Defen.so ("Defen.so", "we", "us") collects, uses, and protects information when you use https://defen.so and https://app.defen.so (together, the "service").
1. Information we collect
- Account data: name, email, hashed password, avatar, preferred language, and, when you sign in with Google, your Google account ID.
- Billing data: Stripe customer and subscription identifiers. We never store full card numbers; card data is handled by Stripe under PCI-DSS.
- Service telemetry: HTTP request metadata (IP, ASN, country, user-agent, route, verdict, timing) for domains you actively route through the service. This is required to deliver WAF, DDoS, and bot protection.
- Uptime probes: latency, HTTP status, and error messages for URLs you register as uptime monitors.
- Product usage: dashboard events (login, plan changes, feature usage) for security and analytics.
2. How we use it
- Deliver the security, uptime, and dashboard features you signed up for.
- Detect and block malicious traffic across the customer base (attack signatures, botnets, credential-stuffing rings). This uses aggregate signals only.
- Bill, prevent fraud, and comply with legal obligations.
- Send transactional emails (verification, alerts, invoices) and, only if you opt in, product updates.
3. Google sign-in
When you sign in with Google, we receive your email address, name, avatar, and Google account ID. We use these solely to create and authenticate your account. We do not read your Gmail, Drive, Calendar, or Contacts. You can revoke access at any time from your Google account permissions page.
4. Sharing
We share data only with subprocessors necessary to deliver the service: Stripe (payments), our email provider (transactional email), our infrastructure providers (compute, storage, edge), and analytics tools operating on aggregate data. We do not sell personal data. We do not use your data to train third-party AI models. We may disclose data if required by law or to protect our users and infrastructure.
5. Retention
Account data is retained while your account is active. Attack logs and uptime history are retained per plan (7 days on Free, 30 days on Pro, 90 days on Max, contractual on Agency). Backups are retained for up to 90 days. After account closure, all personal data is deleted within 30 days.
6. Your rights
You may access, correct, export, or delete your personal data from the profile dashboard, or by emailing info@defen.so. If you are in the EU, UK, or California, you have additional rights under GDPR / UK-GDPR / CCPA, including the right to object to processing and the right to lodge a complaint with your local data protection authority.
7. Security
We use TLS in transit, encryption at rest for sensitive fields, hashed passwords (bcrypt), least-privilege access controls, and rate-limited administrative interfaces. No system is 100% secure. If you notice a vulnerability, please report it responsibly to info@defen.so.
8. Cookies
We use strictly necessary cookies for authentication, CSRF protection, and language selection. We do not use advertising cookies. Analytics, if enabled, is anonymized and self-hosted.
9. International transfers
Our edge infrastructure is global. Personal data may be processed outside your country of residence, protected by standard contractual clauses where applicable.
10. Children
The service is not directed at children under 16. We do not knowingly collect personal information from children.
11. Changes
We may update this Policy from time to time. Material changes will be announced by email or in-app notice at least 14 days before taking effect.
12. Contact
Data protection questions? Email info@defen.so.