Privacy Policy

Version 1.1 · Effective 21 September 2026 · Protocol 42

The short version: the Software collects nothing. ASIScan runs entirely on your machine, makes no network calls, and contains no telemetry, analytics, or phone-home of any kind. Your source code never leaves your infrastructure. You get the source, so you can verify that claim rather than trust it.

1. Who we are

Protocol 42, operating from Ontario, Canada, is the controller of personal data described in this policy. Contact: hello@protocol42.io.

2. What the Software collects

Nothing. ASIScan is a command-line tool that reads files on your filesystem and writes reports to your filesystem. Specifically, it does not:

This is verifiable. The full source ships with every licence, and the scan runs offline — you can confirm it on an air-gapped machine.

3. What the website collects

The website is a static site. We do not run advertising trackers, session recording, or behavioural profiling, and we do not set non-essential cookies.

We use Vercel Web Analytics to count page views, so we know which pages are read and roughly where our readers are. It does not use third-party cookies and does not track you across other websites. Visits are recorded anonymously and are not tied to you or your IP address; a visitor is recognised only by a hash of the incoming request, which is discarded after 24 hours. For each page view it records the time, the page address, the referring site, approximate location (country, region and city), device type, operating system and browser. We see only aggregate totals and cannot identify you from them.

Our hosting provider (Vercel Inc.) also processes standard server request data — IP address, user agent, requested URL, timestamp — as part of delivering the site and protecting it from abuse. This is handled under Vercel's own privacy terms.

4. What we collect when you buy

Payments are processed by Stripe, Inc. Stripe acts as an independent controller of your payment data and is subject to its own privacy policy and PCI-DSS obligations.

We never see or store your card number, CVC, or full banking details. From Stripe we receive:

Lawful bases (UK/EU GDPR): performing our contract with you (Art. 6(1)(b)) for order fulfilment and support; complying with a legal obligation (Art. 6(1)(c)) for tax and accounting records; and our legitimate interests (Art. 6(1)(f)) in preventing fraud and keeping records of licence grants.

5. What we collect when you contact us

If you email us, we receive your email address, your message, and anything you choose to include. Please do not send us your source code, credentials, API keys, or customer data — we do not want it and do not need it. To report a false positive, a redacted snippet or a rule ID is enough.

If you do send us material we did not ask for, we will delete it on request.

6. How we use personal data

We do not sell personal data. We do not share it with advertisers or data brokers. We do not use it to train machine-learning models. We do not send marketing email unless you have separately opted in, and any such email carries a one-click unsubscribe.

7. Who we share it with

ProcessorPurposeLocation
Stripe, Inc.Payment processing, tax calculationUSA / global
Vercel Inc.Website hosting and anonymous page-view analyticsUSA / global
Email providerSupport correspondenceUSA / Canada

We may also disclose personal data where required by law, court order, or a lawful request from a public authority, or to establish, exercise, or defend legal claims.

8. International transfers

We are based in Canada, and our processors operate internationally. Where personal data is transferred out of the UK, EEA, or Switzerland, transfers rely on an adequacy decision (Canada holds a partial adequacy decision from the European Commission) or on Standard Contractual Clauses implemented by the relevant processor.

9. Retention

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent where processing is based on it. These rights arise under the EU/UK GDPR, Canada's PIPEDA, Quebec's Law 25, the California Consumer Privacy Act, and comparable laws.

To exercise any right, email hello@protocol42.io. We will respond within 30 days and will not charge you or degrade your service for asking.

California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months.

If you are in the EEA or UK you may lodge a complaint with your local supervisory authority. In Canada you may complain to the Office of the Privacy Commissioner. We would rather you came to us first.

11. Security

We keep the personal data we hold to a minimum, which is the most effective security control available to us. What we do hold is protected by access controls and encryption in transit, and is held with processors that maintain recognised security certifications.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify you and the relevant authorities where required by law.

12. Children

The Software is a professional developer tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.

13. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.

14. Changes to this policy

We may update this policy. The version and effective date at the top will change, and material changes will be announced on this page. Continued use after a change constitutes acceptance of the updated policy.

Contact

Protocol 42
Ontario, Canada
hello@protocol42.io