Khalaq.tech Khalaq.tech
SERVICES CASES ABOUT US CONTACTS CHECK MY APP
Mobile menu
Close
SERVICES CASES ABOUT US CONTACTS CHECK MY APP

PRIVACY POLICY

Last updated: 9 September 2026

Who we are

KHALAQ PORTAL EST, United Arab Emirates. Contact: hello@khalaq.tech.

What we collect

When you submit a form on this site: your name, email address, and the answers you give in that form — including the app URL, if you leave one for a first check. Standard server logs (IP address, user agent, requested URL) are kept for security and troubleshooting.

The free Scan is automated: it checks what is publicly visible against the URL you send us and shows the result on screen, with no signup. Report, Audit, Production Readiness and Rescue are still a person reading the evidence and writing it up, on request, with the result sent back to you. The rules in the next two sections apply to both — the automated scanner and the checks we run by hand.

What we never store

We never store the value of any secret or credential we find during a check. If a key is exposed, we record its type, where it was found, a one-way hash and a masked sample such as sk_live_••••7f2a — never the key itself, in any system or log.

When you fill in a form

The forms on this site ask for your name, your email address, the address of your app, and — if you choose to answer them — a few questions about the app and what worries you about it. We store your answers, the page you arrived from, and the campaign parameters in the link you followed, so we know which of our own pages are worth keeping.

If you write to us because something is already broken, the form also asks how to reach you quickly — a phone, WhatsApp or Telegram — along with what happened, when it started, and whether data is at risk. We store those answers too. From everything you send we work out a rough priority for ourselves, and we store that alongside your answers; it decides how fast we come back to you and nothing else.

We do not store your IP address. We store a one-way hash of it, which we use for one thing only: refusing a sixth submission from the same connection within an hour. The address itself cannot be recovered from the hash, and the hash is not used to recognise you anywhere else.

Someone else — an AI assistant, on your behalf — can also file a request for an audit of your app. When that happens we write to you once, and nothing else: the request does nothing until you press the link in that email. Pressing it is how you agree to what is on this page. If you never press it, we delete the request after 14 days and never write again. We store the sender's name — "Claude", say — only so we can tell you where the request came from.

We keep form submissions for 24 months, then delete them — and a request an assistant filed keeps the same 24 months once you have pressed the link, because from that moment it is a request you made. You can have yours deleted sooner: write to hello@khalaq.tech from the address you used in the form, and we remove every record tied to it. We keep a note that the request was made and honoured — the date, a one-way hash of the address, and how many records were removed. That note is what lets us show the request was carried out, and it does not contain the address itself.

Scanning and how to opt out

When we check an app — by hand today, and with the automated scanner once it launches — we only request pages that are already publicly accessible, in the same way an ordinary visitor's browser would. We never submit forms, never click destructive controls, and never attempt to authenticate. If you own a domain and do not want it checked, write to hello@khalaq.tech from an address at that domain and we will add it to our permanent exclusion list.

Domain ownership attestations

If you ask us to run active checks against a domain, we record the domain, the name you gave, the date, the method you chose to prove ownership, and a hash of the exact wording you agreed to. Active checks send real requests to your running system: we test whether credentials found in your public bundle are still valid, and whether your database can be read without authentication. We never store a credential value and we never read a row of your data — only the name of a table, how many rows it holds, and what its columns are called. An attestation lasts 90 days, and you can withdraw it at any time from your account. If you erase your account, the attestation record is stripped of your name and address and permanently revoked; what remains is the fact that a scan was once authorised, which we keep so that question always has an answer.

Aggregate statistics we publish

We publish anonymised aggregate statistics about the problems we find: how many apps we have checked, how many of them had a finding of a given severity, and how many findings their owners have since closed. The count of apps checked runs from the day we started; the severity and closed-finding numbers are computed over a rolling window of the last 30 days. They never identify an application, a URL, a hostname or a customer — the stored aggregate contains no such value and cannot contain one.

A slice is published only when it covers at least 50 applications, so no individual application can be inferred from it. Slices below that size are not shown at all. The aggregate outlives the scan results it was computed from: the underlying results are still deleted after 30 days, and only the anonymised counts remain.

How long we keep it

Results of a first check and their artifacts are deleted 30 days after the check — this is the retention period that will also apply to automated scans when the scanner launches. Enquiries and client records are kept while the business relationship lasts and for as long as required for accounting purposes afterwards.

We take an encrypted backup of our database every night and keep each one for at most 60 days, after which it is destroyed. Before each deployment we also store an encrypted archive of our server logs, which can contain a URL or an address someone sent us; those log archives are kept for at most the same 60 days and then destroyed. Both are encrypted to a key we hold offline: the servers that write them cannot read them back.

Sharing

We do not sell data. We use processors to run the service: email delivery, hosting, and team messaging. They process data only to provide those services to us.

Your rights

You can ask us for a copy of your data, ask for it to be corrected, or ask for it to be deleted. If you have confirmed your address for a scan report, you can delete everything yourself and immediately: open your reports, ask for a link, and use the delete button there. It is irreversible: your address is removed from every record we hold, and scans nobody else has asked for are deleted with it. The exceptions are the encrypted backups and log archives described above: one written before you pressed delete still contains what it contained then, and it is destroyed when it reaches 60 days old. We never restore one to bring deleted data back. Otherwise write to hello@khalaq.tech and we will respond within 30 days. There is no charge either way.

Cookies

This site uses a session cookie required for form submission security, and stores your currency choice and your cookie banner choice in your browser's local storage. If you open your scan reports, one further cookie holds that session for 30 days; it is scoped to the reports area, it ends when you log out or delete your data, and it does not renew itself. There is no advertising or analytics tracking on this site. If that changes, this policy will be updated first.

@all rights reserved
SERVICES CASES ABOUT US CONTACTS PRIVACY POLICY
HELLO@KHALAQ.TECH