Privacy Policy
What we read, and what we never keep.
DenyFirst audits your app's access control from the outside. The whole product is built on a simple promise: we read as little as possible, we prove instead of guess, and the contents of your data never enter a report.
The short version
- A scan makes read-only external requests. Evidence is status codes, counts, and a few redacted key names — never the values, rows, documents, or files behind them.
- To confirm you own the backend under test, you authorize us through your provider (Google, Supabase). We read only the list of projects your account can access, match the one you named, and discard the access token.
- We do not sell your data, and we do not use it for advertising or to train models.
1. Who we are
DenyFirst is operated by Synton.ai LLC, a limited liability company registered in Wyoming, USA ("we", "us"). "DenyFirst" is the product and trading name. If you contract with us, you contract with Synton.ai LLC. Our company details are on the legal page.
2. Information we collect
Account information
When you create an account we store your email address and, if you set one, an organization name. We use it to authenticate you, send transactional email (verification codes, scan results, billing notices), and provide support.
Ownership authorization
Before any scan, DenyFirst requires proof that you control the backend being tested. Depending on the backend, that proof is one of:
- Google (Firebase / Google Cloud): you sign in with Google and grant the
cloud-platform.read-onlyscope. We call the Cloud Resource Manager API once to retrieve the list of projects your account can access, confirm that the project you asked us to scan is among them, and record that a match was made. We do not read project contents, billing, IAM, or any resource data, and we do not retain the OAuth access or refresh token beyond completing this check. - Supabase: you authorize our Supabase OAuth application. We call the Supabase Management API once to list the projects your account can manage and match the project reference under test. The same limits apply — project list only, token discarded after the check.
- Websites (Next.js / WordPress on your own domain): you publish a one-time token as a DNS record or a file on your domain. No third-party account or token is involved.
We store the result of this check — which project was authorized, by which account identifier, and when — as a signed authorization grant. This is what lets us refuse to scan a target you have not proven you own.
Scan evidence
A scan issues read-only requests to the app you authorized and records what came back: HTTP status codes, whether a response looked like data, record counts, and a small sample of redacted field or collection names (names only, never values). We deliberately do not read row bodies, documents, files, or user records. Findings and this evidence are stored as your scan report so you can review and re-check them.
Billing
Payments are processed by Stripe. We store your plan, subscription status, and Stripe customer/subscription identifiers. We never see or store full card numbers — Stripe handles card data directly.
3. Google API Services — Limited Use
DenyFirst's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: information obtained through Google OAuth (the list of Google Cloud projects your account can access) is used solely to verify that you own the project you asked us to scan. It is not used for any other purpose, is not sold or transferred except as needed to provide this feature, is not used for advertising, and is not used to train generalized machine-learning models.
4. How we use information
- To authenticate you and operate your account.
- To verify ownership of a backend before scanning it — the core safety control of the product.
- To run the scans you request and return findings, evidence, and fixes.
- To process payments and manage your subscription.
- To send service communications and respond to support requests.
- To detect and prevent abuse (for example, one account attempting to scan many backends it does not own).
5. Sharing and sub-processors
We do not sell personal data. We share data only with the service providers that run DenyFirst, each acting on our instructions:
- Fly.io — application hosting and the disposable sandboxes that execute scans.
- Stripe — payment processing.
- Resend — transactional email delivery.
- Managed PostgreSQL — the control-plane database.
We may also disclose information where required by law, or to protect the rights, safety, and security of our users and our service.
6. Retention
We keep account and scan data for as long as your account is active, and for a limited period afterward to meet legal, tax, and dispute-resolution obligations. Provider OAuth tokens are used only during the ownership check and are not persisted. You can ask us to delete your account and its associated data at any time.
7. Security
Scans run in isolated, disposable sandboxes and are read-only by default; any escalation (such as creating a throwaway test record) happens only when you explicitly enable it, and is cleaned up afterward. Authorization grants are integrity-protected so that a database compromise cannot mint or widen the right to scan a backend. We restrict internal access to production data on a need-to-know basis. No system is perfectly secure, but minimizing what we collect is our first line of defense.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email hello@denyfirst.com and we will respond within a reasonable period. You can also close your account, which removes your access and begins deletion of associated data subject to the retention above.
9. International transfers
We operate from the United States and use providers that may process data in the United States and the European Union. Where required, we rely on appropriate safeguards for cross-border transfers.
10. Children
DenyFirst is a tool for developers and businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
We may update this policy as the product evolves. When we make material changes we will update the effective date above and, where appropriate, notify you by email.