DenyFirst ← Legal & company

Privacy Policy

What we read, and what we never keep.

DenyFirst audits your app's access control from the outside. The whole product is built on a simple promise: we read as little as possible, we prove instead of guess, and the contents of your data never enter a report.

Effective 8 August 2026 · Operated by Synton.ai LLC (Wyoming, USA), which does business as DenyFirst · Contact: hello@denyfirst.com

The short version

  • A scan makes read-only external requests. Evidence is status codes, counts, and a few redacted key names — never the values, rows, documents, or files behind them.
  • To confirm you own the backend under test, you authorize us through your provider (Google, Supabase). We read only the list of projects your account can access, match the one you named, and discard the access token.
  • We do not sell your data, and we do not use it for advertising or to train models.

1. Who we are

DenyFirst is operated by Synton.ai LLC, a limited liability company registered in Wyoming, USA ("we", "us"). "DenyFirst" is the product and trading name. If you contract with us, you contract with Synton.ai LLC. Our company details are on the legal page.

2. Information we collect

Account information

When you create an account we store your email address and, if you set one, an organization name. We use it to authenticate you, send transactional email (verification codes, scan results, billing notices), and provide support.

Ownership authorization

Before any scan, DenyFirst requires proof that you control the backend being tested. Depending on the backend, that proof is one of:

We store the result of this check — which project was authorized, by which account identifier, and when — as a signed authorization grant. This is what lets us refuse to scan a target you have not proven you own.

Scan evidence

A scan issues read-only requests to the app you authorized and records what came back: HTTP status codes, whether a response looked like data, record counts, and a small sample of redacted field or collection names (names only, never values). We deliberately do not read row bodies, documents, files, or user records. Findings and this evidence are stored as your scan report so you can review and re-check them.

Billing

Payments are processed by Stripe. We store your plan, subscription status, and Stripe customer/subscription identifiers. We never see or store full card numbers — Stripe handles card data directly.

3. Google API Services — Limited Use

DenyFirst's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: information obtained through Google OAuth (the list of Google Cloud projects your account can access) is used solely to verify that you own the project you asked us to scan. It is not used for any other purpose, is not sold or transferred except as needed to provide this feature, is not used for advertising, and is not used to train generalized machine-learning models.

4. How we use information

5. Sharing and sub-processors

We do not sell personal data. We share data only with the service providers that run DenyFirst, each acting on our instructions:

We may also disclose information where required by law, or to protect the rights, safety, and security of our users and our service.

6. Retention

We keep account and scan data for as long as your account is active, and for a limited period afterward to meet legal, tax, and dispute-resolution obligations. Provider OAuth tokens are used only during the ownership check and are not persisted. You can ask us to delete your account and its associated data at any time.

7. Security

Scans run in isolated, disposable sandboxes and are read-only by default; any escalation (such as creating a throwaway test record) happens only when you explicitly enable it, and is cleaned up afterward. Authorization grants are integrity-protected so that a database compromise cannot mint or widen the right to scan a backend. We restrict internal access to production data on a need-to-know basis. No system is perfectly secure, but minimizing what we collect is our first line of defense.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email hello@denyfirst.com and we will respond within a reasonable period. You can also close your account, which removes your access and begins deletion of associated data subject to the retention above.

9. International transfers

We operate from the United States and use providers that may process data in the United States and the European Union. Where required, we rely on appropriate safeguards for cross-border transfers.

10. Children

DenyFirst is a tool for developers and businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

We may update this policy as the product evolves. When we make material changes we will update the effective date above and, where appropriate, notify you by email.


Questions about this policy or your data? Write to hello@denyfirst.com. See also our security & trust page and legal & company information.