Privacy Policy
Last updated: 10 June 2026
1. Data Controller
The data controller for the purposes of the GDPR is debuger.net. For any privacy-related requests, contact us at privacy@debuger.net.
2. Data We Collect
- Account data: email address and name provided at registration.
- Authentication data: hashed password; JWT session token stored in your browser's localStorage.
- Technical logs: IP address, HTTP method, path, timestamp — retained for security and abuse prevention.
- Monitoring data: Core Web Vitals, Lighthouse scores and performance metrics of the websites you configure in your projects. This data belongs to you.
- Payment data: billing name and card details processed exclusively by Stripe. We store only the Stripe customer ID and subscription status — never raw card numbers.
- RUM data: anonymised page-load metrics collected via our Real User Monitoring script from end-users of your monitored sites. No personally identifiable data is stored.
- Accessibility scanner data: when you request a free accessibility report we collect your email address, optionally your company name, the URL you asked us to analyse, and — as proof of consent required by the GDPR — the IP address, timestamp and exact wording of the consent you accepted. We also store the scan results (WCAG violations found on the public page you submitted). This tool is offered to an Italian-speaking audience: the binding notice for it is the Italian informativa privacy, which the consent checkbox links to.
3. Legal Basis
- Contract (Art. 6.1.b GDPR): processing your email, password and payment information is necessary to provide the service you subscribed to.
- Legitimate interest (Art. 6.1.f GDPR): IP address logging and security monitoring are necessary to detect abuse, prevent unauthorised access and maintain service integrity.
- Pre-contractual request (Art. 6.1.b GDPR): processing the email address you submit to the free accessibility scanner is necessary to produce and deliver the report you asked for.
- Consent (Art. 6.1.a GDPR): marketing emails are sent only if you tick the separate, optional marketing box. This consent is never bundled with the report request and can be withdrawn at any time via the unsubscribe link or by emailing us — withdrawal does not affect the lawfulness of processing carried out beforehand.
4. Data Retention
Your account data is retained for the duration of your active account. Upon account deletion, all personal data is permanently removed within 30 days. Anonymised aggregate metrics may be retained longer for statistical purposes.
Accessibility scanner leads and their reports are retained for 24 months from the last scan, after which they are deleted. If you withdraw marketing consent we keep only the record of the withdrawal, as required to prove we stopped contacting you.
5. Your Rights (GDPR)
Under the GDPR you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate data via the Settings page.
- Erasure: delete your account and all associated data at any time via Settings → Delete account.
- Portability: export your monitoring results as CSV from the monitor detail page.
- Objection: object to processing based on legitimate interest.
To exercise any right, email privacy@debuger.net. We will respond within 30 days.
6. Cookies & Local Storage
We use only essential cookies and localStorage — no tracking or analytics from third parties:
- debuger_token (localStorage) — your JWT authentication token. Required to stay logged in.
- theme (localStorage) — your light/dark mode preference. Optional.
- cookie_consent (localStorage) — records whether you have acknowledged this banner.
No advertising cookies, cross-site trackers or analytics pixels are used.
7. Third-Party Processors
- Stripe— payment processing. Data may be transferred outside the EU under Stripe's Standard Contractual Clauses. Stripe Privacy Policy.
- Resend — transactional email delivery (account verification, alerts).
- Hetzner — cloud hosting in Helsinki, Finland (EU). Data is stored exclusively within the European Economic Area.
- Anthropic — used to turn technical accessibility violations into plain-language explanations and fix suggestions. We send only the public HTML fragments of the page being analysed; we never send your email address or any other personal data. Anthropic Privacy Policy.
8. Data Transfers
All data is hosted in the EU (Hetzner Helsinki). Payment data is handled by Stripe under appropriate safeguards (Standard Contractual Clauses). Accessibility scan content processed by Anthropic may be transferred outside the EU under Standard Contractual Clauses; this transfer never includes personal data.
9. Contact
For privacy enquiries: privacy@debuger.net