Privacy
Deploy Doctor is built to be boring and transparent with your data. We scan public deploy endpoints from the outside, keep the minimum data required to render reports, and delete the rest.
When you submit a URL, Deploy Doctor performs a non-intrusive HTTP audit of the publicly accessible endpoint. We fetch the page response, headers, status codes, redirect chains, caching directives, security headers, and publicly linked assets to generate a deploy analysis report. We do not crawl behind authentication, submit forms, or attempt any form of vulnerability probing beyond reading public HTTP responses.
We store the account information you use to sign up (email, encrypted password hash), the URLs you request to scan, the generated report scores and findings, and the timestamp of each scan. Raw HTTP response bodies are discarded after the rule engine runs; we do not retain full page HTML snapshots long-term. If you enable premium Lighthouse audits, Lighthouse JSON snapshots may be retained for up to 30 days for report rendering.
Deploy Doctor never reads or accesses your source code, environment variables, build logs, Vercel account, or server-side execution. The scanner operates from the outside like any visitor on the public internet. We never sell, share, or rent account data or scan history with third parties. We do not run ad network tracking scripts against scanned URLs on your behalf.
The application runs on Vercel serverless infrastructure. Relational data is stored in a managed PostgreSQL database hosted by Neon. Outbound HTTP probes originate from Vercel's AWS us-east-1 region. Emails are delivered via Resend. Payment processing (when enabled) is handled by Stripe — we never see or store full card numbers on our systems.
Free-tier scan reports are retained for 90 days. Paid plans retain reports for 12 months. You can delete individual reports from your dashboard at any time. To request full account deletion, email privacy@store-leak.com from the address associated with your account — we will fulfill verified requests within 14 days and send you a confirmation when complete.
All traffic is served over TLS 1.2+. Passwords are hashed with Argon2id. Authentication tokens are signed with HMAC-SHA-256 and rotated on logout. Database connections enforce TLS. Production systems run under least-privilege IAM roles. We do not log raw request bodies that may contain sensitive information.
For privacy questions, deletion requests, or data export inquiries, email privacy@store-leak.com. We may update this policy as the product evolves; material changes will be flagged in-product and via the email on file. This policy was last updated in August 2026.
Short version (TL;DR)
We're a scanner, not a store. We never touch your source code or Vercel account. We never sell your data. You can delete anything, anytime. If something is unclear, just ask — we'd rather over-explain than under-deliver on trust.