// privacy

Privacy Policy

No accounts, no tracking, no third-party fonts. Your source code and credentials are never stored.

Last updated: 16 June 2026

1. Who is responsible

QuickAudit (quickaudit.dev) is operated by codelake Technologies LLC (an Akyros Labs Brand) ("codelake", "we", "us"), the data controller for the processing described here. For any privacy question or to exercise your rights, contact us at privacy@quickaudit.dev.

2. What we process

When you run a scan we process: the URL you submit (to perform the security analysis), the public content of that URL retrieved by our scanner, and the resulting findings. For security and abuse prevention we briefly process technical request data such as your IP address (used for rate limiting). Scan results are kept only transiently so you can view them and are removed automatically; unclaimed scans are deleted within 24 hours.

3. What we never collect

We do not store your source code, API keys, or any credentials we may detect during a scan — these are analysed in memory and discarded. We do not run user accounts, ask for your email, use advertising, profiling, or third-party analytics, and we never sell or share your data.

4. Legal basis (GDPR)

We process the scan URL and content to provide the service you requested (Art. 6(1)(b) GDPR — performance of a service at your request). We process minimal technical data such as IP addresses for security and abuse prevention based on our legitimate interest in keeping the service available and safe (Art. 6(1)(f) GDPR).

5. Cookies

We use only strictly necessary cookies: a session cookie and a CSRF-protection token required for the scan form to work securely. There are no analytics, advertising, or tracking cookies, so no consent banner is required for them.

6. Fonts & third parties

All fonts are self-hosted on our own server — we do not load Google Fonts or any external font service, so your browser sends no data to Google when visiting QuickAudit. The codelake logo is loaded from our own CDN (cdn.codelake.dev). We do not embed third-party trackers, social widgets, or ad networks.

7. Hosting & processors

QuickAudit is hosted on servers located in the European Union. Data is processed within the EU. We only use the subprocessors strictly necessary to run the service (hosting and our own CDN); we do not transfer your scan data to third parties.

8. Retention

Scan results are cached only transiently and deleted automatically — unclaimed scans within 24 hours. Server and security logs are kept for a short period for abuse prevention and then rotated out.

9. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and to data portability. Because we keep no accounts and only transient scan data, there is normally little to no personal data on file. To make a request, email privacy@quickaudit.dev. You also have the right to lodge a complaint with your local data protection authority.

10. Changes

We may update this policy as the service evolves. The current version always lives at this URL with the date below.

Questions about your data?

Email privacy@quickaudit.dev — we respond to every request.