ReSafe Ltd. ("ReSafe", "we", "us" or "our") builds security products that protect people from online threats. Protecting you means looking at signals that are, by their nature, personal, so we hold ourselves to a simple rule: our business model is the price you pay for the product. Any data we hold is not for sale.
This Privacy Policy describes how we collect, use, store, share, and protect information in connection with the resafe.io website, the ReSafe mobile applications, the ReSafe browser protection, and every related feature and service (together, the "Services"). It applies to visitors, registered users, and anyone who contacts us. It forms part of, and should be read together with, our Terms of Service.
By using the Services you confirm that you have read this Privacy Policy and understand it. If you do not agree with it, please do not use the Services.
ReSafe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements, which are published at https://developers.google.com/terms/api-services-user-data-policy. Where this Privacy Policy describes marketing, advertising, research, or statistical uses of the information we collect, those uses do not extend to information received from Google APIs.
1. General
"Personal Information" means any information relating to an identified or identifiable natural person. Depending on which features you use, ReSafe may collect the following:
- Account and contact details you give us, such as your name, email address, phone number, country, and the password you set or the third-party identity provider you sign in with.
- Billing details required to take payment. Full card numbers are handled by our payment processors; we retain only limited data such as the card brand, the last four digits, and the expiry date.
- Technical and installation details, such as your IP address, device and browser type, operating system, language, installation time, and the version of the Services you run.
- The advertising identifier your device provides, on Apple devices where you have allowed tracking when we asked. We use it to show you our own advertising on other platforms and to measure that advertising, which means sharing it with the advertising and attribution providers described under Transferring Information to Third Parties below. If you decline the prompt the identifier is never collected, and if you later withdraw permission in your device settings we clear the one we hold the next time the app opens. Your protection works the same either way.
- The names of the sites your device looks up, where you have turned on site blocking, so that we can refuse the ones we know to be dangerous. Site blocking below describes what is resolved, what is recorded when a site is blocked, and what is never named.
- The addresses of the pages you visit, where you have installed our browser extension, so that we can warn you about malicious or deceptive sites. Browser Protection below describes what is sent, what is kept, and what never leaves your browser.
- Answers you provide in our onboarding questionnaire, and the identifiers you ask us to monitor, such as email addresses or phone numbers belonging to you.
- Records of your interaction with us, including support tickets, survey responses, and the alerts you were shown and acted on.
- Diagnostic details when the Services crash or stop responding, such as the error and its stack trace, the device and application version, and the identifier of the account the report belongs to. On a small sample of sessions in which the app has crashed this includes a recording of the screens involved, in which all text, images, and graphics are masked. The logs attached to a report have their content removed, and addresses carrying a one-time token are redacted, before it is sent.
- A recording of your app sessions — the screens you saw and where you tapped — so that we can see where the app is confusing or broken. Every part of a screen that shows your personal information is masked before the recording leaves your device: your name, your email address, your phone number, the identifiers you asked us to monitor, the information a breach exposed, and your payment details are covered over rather than recorded. What remains is the layout, our own wording, and where you tapped.
- A recording of your visits to our website, for the same reason, if you have accepted analytics cookies. The website is masked more narrowly than the app: what is covered over rather than recorded is anything you type into a form, your payment details, your passwords, and the information a breach exposed. The rest of the page is recorded as it was drawn, which is our own wording and any of your own details a page shows back to you, such as your name, your email address, or your phone number. What the recording holds beyond that is the layout of the page, the address of each page you saw, where you moved and clicked, and how far you scrolled. The pages reached from a link we email you, which carry a one-time code in their address, are not recorded at all.
- Where your visit came from, where performance cookies are allowed: the campaign and creative named in the link that brought you to our website, the identifier an advertising network appended to that link, the site you arrived from, and the page you arrived on. We keep the first of these visits and the most recent one, and we record them on your account when you create it, so that we can tell which of our advertising produced a customer. They name an advertisement, never you.
To the extent you have chosen to enable our SMS filtering feature as part of the Services, we will also receive information contained in some of the text messages you receive from numbers not included in your contact list (including message content), as of your enabling of such feature and thereafter during your use thereof. Most such messages are judged on your device and are never sent to us. What reaches us is a message carrying a web address your device could not judge on its own: your device's operating system sends us that message and its sender, so that we can check the address and answer whether the message is junk. That request carries no account, no device identifier, and nothing else about you.
Where you provide us with Personal Information relating to a third party — for example when you ask us to monitor an identifier that is not your own — you acknowledge and agree that you have received and obtained all approvals necessary for us to process that information as described in this Privacy Policy.
Providing Personal Information is voluntary. You are not required by law to provide it, but some information is necessary to deliver the Services, and without it parts of the Services will not work.
2. Site blocking
ReSafe refuses the dangerous sites your apps look up, by answering the questions they already ask. Every app on a phone finds a website by looking its name up in the Domain Name System, and turning on site blocking installs a configuration that sends those lookups to us over an encrypted connection instead of to your network's own resolver. That is what lets us stop a phishing site in any app rather than only in a browser, and it is also why this section is here: the lookups are yours, and you should know exactly what we do with them.
The configuration is issued to your account, so the lookups arriving from your device are attributable to it rather than anonymous. We say that plainly because the protection history we show you depends on it.
Looking a name up
We receive the name of the site being looked up and nothing else. There is no page address, no path, no query string, no page you came from, and no content of any kind: a lookup carries a name, and a name is all there is to send. We put that name to a filtering resolver, read back whether it is a site to refuse, and answer your device. We also compare it against the sites we have judged dangerous ourselves — the fraudulent shops described under A site we check below, and the sites named by the published lists of phishing addresses we license — which is a comparison made in memory, against a list we hold, so the name goes nowhere further to make it.
Answering means asking the Domain Name System, so the name reaches the resolvers we forward to, exactly as it would reach whichever resolver your device used before. Those providers are described under Transferring Information to Third Parties below. Nothing about you goes with the name: they receive a lookup from us, not from you, and not your account, your device, or your address.
A site we do not block
A name we do not refuse is counted and, with the one exception described under A site we check below, never named. We keep a running count of how many lookups we answered for your device each day, so that your dashboard can tell you how much was checked, and the name itself is not written to our records, not written to our logs, and not sent anywhere. It is not used to build a profile of you, it is not used for advertising, and it is not sold. We are able to say this because the code cannot do otherwise, rather than because we have undertaken not to look.
A site we block
When we refuse a site, we record that we refused it. The record holds the site, the time, and nothing more — no page, no path, and nothing about what you were doing. The site is stored as the website itself rather than as the particular name that was refused, so a tracker spread across many subdomains is one entry and not fifty, and a site refused repeatedly in one day is one entry and not one per attempt.
These records are stored against your account, because they are your protection history: they are what the app shows you on your activity timeline and what the counts on your dashboard are counting. We may also send you a notification when a site is blocked, and we keep a record of having sent it. How long we keep these records, how long we keep the daily counts described above, what happens to both when your account is deleted, and how to ask us to erase them sooner are set out under Retaining Your Information below.
A site we check
One kind of name we do not refuse is sent on for a check: a site that looks like a shop nobody knows. A name that is not on the list of widely used sites, and is newly registered, or resembles a well-known brand, or is shaped like a shop, is passed from the resolver to our own servers together with the reference that identifies your device’s configuration, so that we can look at the site before the next person reaches it — and tell you if it turns out to be a fake shop, since by then you have already been there. That is the only kind of name that leaves the resolver without having been refused, and a name that does not fit the description is counted and never named, exactly as above.
Checking a site means our servers fetch its front page, read its registration date from the public registry, and ask an artificial-intelligence provider whether the page is a fraudulent shop; the providers are described under Transferring Information to Third Parties below, and what they receive is the site and nothing about you. We keep the result — the site, the verdict, its reasons, the page’s title and an extract of its text — as a record about the site, not about you, for as long as the verdict stands. A site judged fake is refused for every device from then on; a site the check could not settle is marked suspicious and is not refused; a site judged fine is remembered as fine so it is not checked again for a while.
We also keep, against your account, that your device resolved the site while it was being checked. This exists for one reason: if the site is then blocked, or marked suspicious, we can tell you — a notification that names no site, and a row on your activity timeline that does, with the reasons. If the site is judged fine, that record is deleted at once. Otherwise it is deleted thirty days after your device last resolved the site, or when you delete your account, as Retaining Your Information below sets out. It is never used to build a profile of you, never used for advertising, and never sold.
Turning it off
Site blocking is yours to switch off, and only yours: iOS reserves that choice to you, so it is made on the same device settings screen where you chose ReSafe as your DNS provider rather than anywhere in our app. Switching it off stops your lookups reaching us at once. What we have already recorded is kept, and expires or is deleted exactly as Retaining Your Information below sets out.
3. Browser Protection
The ReSafe browser extension warns you about malicious and deceptive websites. Doing that means looking at where you are going, so this section sets out exactly what leaves your browser, what we keep, and what we never receive at all. It applies only where you have installed the extension and connected it to your account.
Where this Privacy Policy describes marketing, advertising, sales promotion, loyalty, research, or statistical uses of the information we collect, those uses do not extend to anything described in this section; and where it lists advertising, attribution, and search-engine providers among the third parties who may receive information, nothing described in this section is transferred to them. Nothing described in this section is ever used or transferred for advertising, attribution, creditworthiness, or lending, and nothing described in this section is ever sold; that is true of the addresses the extension asks us to check, the records of a rule matching, the daily counts of pages inspected, what the one-time checkup reports, the session token the extension holds for a connected browser, and the identifier and device name we store for it, and of anything else this section describes. Everything this section describes as reaching us, we use to protect you while you browse, to show you your own protection history, and to show you which of your browsers are connected so that you can disconnect one; and we transfer it only where that is needed to provide that protection, for security or fraud prevention, to comply with the law, or in a merger or sale of assets in which the recipient is bound to protect it at least as well.
Checking a page before it loads
When you navigate to a page, the extension sends us the full address of that page, including its path and any query string, together with the address of the page you came from where your browser reports one. We use them to decide whether to warn you and for nothing else. The check is answered from the address itself, in memory: we do not store it, and we do not write it to our logs. That full address is not added to a profile of you, it is not used for advertising, and it is not shared with anyone.
The same check runs in four other places: when you ask us to check a link you have right-clicked; when a site asks your browser for permission to send you desktop notifications, in which case we send the address of the page making that request; and twice during the checkup described below, once over your open tabs and once over those of them that already hold that permission. The two checkup sweeps send origins alone rather than full addresses.
A site we check
One kind of site is looked at further, and it is the same kind ReSafe checks for a phone: a site that looks like a shop nobody knows. Where the site is not on the list of widely used sites, and is newly registered, or resembles a well-known brand, or is shaped like a shop, the check of the address starts a check of the site itself — our servers fetch its front page, read its registration date from the public registry, and ask an artificial-intelligence provider whether the page is a fraudulent shop. Only the website's own name is used for this. The path and the query string are read to answer your check and are discarded with it, and they are never part of what is looked at here.
What a check of that kind leaves behind is a record about the site — the site, the verdict, its reasons, the page’s title and an extract of its text — and no record about you. We do not keep that your browser was the one that reached it, and we do not keep the address you were on. A site judged fake is blocked from then on, for your browser and for every device on the service; a site the check could not settle is marked suspicious and is not blocked; a site judged fine is remembered as fine so it is not checked again for a while. Nothing described in this paragraph is used to build a profile of you, used for advertising, or sold.
Checking a site of that kind takes about twenty seconds, which is longer than a page takes to load, so the page is not held: it loads, and your browser asks us the same question again once or twice over the following minute to see whether an answer has arrived. If the answer is that the site is a fake shop, the extension takes you off the page and shows you our warning instead. Those repeat questions send the same address as the first and are treated exactly the same way: read to answer you, and not kept. Your browser stops asking as soon as an answer arrives, if you navigate away, or after a minute, whichever comes first.
Where ReSafe runs its own filtered DNS service, the same question is put to that service at the same moment, so that the sites blocked on your computer are the sites blocked on your phone. Our own servers ask it as part of the check described above, and where your account is set up with the service your browser asks it directly as well. Whichever of the two asks, the site’s host name is all that is sent — never the path, never the query string, and never the page you came from. Answering it means looking that host name up in the Domain Name System, so the host name reaches the DNS provider our service forwards lookups to; that provider is described under Transferring Information to Third Parties below. A host name looked up for one of the checks in this section is not stored and is not written to our logs, it is not added to a profile of you, and it is not used for advertising. That is a statement about these checks and not about the service in general: where your device resolves through the service itself, Site blocking above is what describes it, and a site the service blocks for your device is recorded as that section sets out. This lookup is part of the checks described above and follows them: where a check is not made, no host name is looked up either, so the sites the extension stays out of, described next, are excluded from it — and the notification-permission check, which runs whatever site you are on, sends the host name of that site like any other.
We also check the address against lists of dangerous sites that Google publishes. We hold our own copy of those lists and check against it in memory, so for almost every page nothing about where you went is sent anywhere. That copy is downloaded from our own servers rather than from Google, and in the first seconds after one of our servers starts, before its copy has finished loading, the short fingerprint fragment described next is put to those same servers of ours instead of being checked in place; it never becomes an address, and it does not go to anyone outside ReSafe. The lists hold one-way fingerprints rather than addresses, and when a page you visit produces a fingerprint that begins like one on a list, we send that short opening fragment to Google to ask which full fingerprints it stands for. We do not send the address, and the fragment is not one: it begins the same way for an enormous number of unrelated pages, which is why the question has to be asked at all. Google receives the fragment from us rather than from you, and nothing about you, your device, or your account goes with it. So that the same question is not asked twice, our servers keep the answer in a record they share, stored under the fragment it answers and held until the expiry Google gives us for it and never longer than a day, after which it is deleted. That record is not stored against your account and nothing in it says which browser, or which person, the fragment came from, and neither the fragment nor the address is written to our logs, added to a profile of you, or used for advertising.
Sites the extension stays out of
The extension ships with a list of sites it does not inspect, which includes webmail, banks, search engines, and our own site. It does not read those pages, and it does not check them as you go to them: no address of a page on one of them is sent to us, and neither is the address you came from when you arrive from one. A link you right-click on one of them is not checked either: the extension tells you it stays out of that site instead of asking us about it. From your ReSafe account settings you can tell the extension to stop checking any other site as you browse it, and you can disconnect the extension there to stop it checking anything.
One of the checks described here runs whatever site you are on, and neither list covers it. A file you download that matches one of our rules is recorded whatever site it came from, which sends us the address it was served from; that one runs only where you have given the extension permission to see your downloads, and it runs on every plan. The check on a site asking your browser for permission to send you desktop notifications is covered by both lists: on a site the extension stays out of, and on any site you exclude yourself, the prompt goes straight through to your browser without being checked and nothing about it is sent to us. That check belongs to a paid plan and does not run without one. Both are described in full above and below.
Where you sign in
Where your plan includes it, the extension also notices when you sign in to a site with a password and the sign-in succeeds — the page you land on afterwards no longer asks for a password — and sends us the name of that site, so it can appear in the list of your accounts in the app, with the date and the name of the browser it was seen from. It sends the site name only: never your username, your password, or anything else you typed, and never the address of the page. It does this only on sites the extension checks, so a sign-in on the webmail, banks and other sites it stays out of, or on a site you have excluded yourself, is never recorded. We keep the site name with your account for as long as your account exists, exactly as we keep an account found from your mailbox, and you can hide it in the app. You can turn this off from the extension’s options page at any time, and disconnecting the browser stops it too.
What we record when a warning fires
When one of our rules matches and we warn you, block the page, or send a hijacked search to your own search engine instead, we record that it matched. A rule that only feeds the decision, and says nothing to you, leaves no record behind. The record holds the identifier of the rule, what it detected, how serious it is, which of our protections recorded it, when it happened, and the site it happened on. The site is stored as an origin alone: we reduce the address to its origin before storing it, so the path and the query string are discarded and never reach our database. Alongside it we keep a daily count of how many pages the extension inspected, which carries no addresses at all. A download is reported by this same route and in this same shape: when you have given the extension permission to see your downloads and one of our rules matches a file you have downloaded, the record carries the address the file was served from, reduced to its origin like any other. Nothing is sent when a download finishes and no rule matches it.
These records are stored against your account and against the browser they came from, so that you can see your own protection history and tell one connected browser from another. They are not anonymous, and nothing in this Privacy Policy describes them as anonymous.
When we block a site and you choose to continue to it anyway, we record that the block was overruled. What we keep is a count of how often each kind of block is overruled on each day, so that we can tell a warning people trust from one they do not. That count is not stored against your account and is not tied to you: it is a total across everyone who met the same kind of block, and nothing in it identifies which browser or which person any of it came from.
The one-time checkup
When you first connect the extension it runs a one-time checkup of your browser and reports what it finds as counts. It checks the origins of up to twenty open tabs, sending each origin rather than the full address of any tab, and reports how many were flagged. It reports how many of those same open sites you have permitted to send you desktop notifications and how many of those we treat as risky. It does not read the list of extensions you have installed.
Identifying your browser
Connecting the extension creates a session for it. The extension holds a token for that session on your device, and we store an identifier for the installation together with a device name such as "Chrome on Windows", so that your dashboard can show you which browsers are protected and let you disconnect one of them. Disconnecting the extension ends that session.
We record that a browser was connected or disconnected, and the version of the extension that connected, so that we can tell how many people complete the setup and whether a release of the extension is failing to. We also record, each time the extension reports a batch of rule matches to us, how many of them we recorded and how many we refused, how many of the recorded ones warned you and how many sent your browser somewhere else, which kinds of threat our rules identified — named from our own list of rules, never read off a page — and how serious the worst of them was, so that we can tell whether the extension is protecting people rather than only how many install it. What these records hold is your account and the facts just described — never the sites you visit, never an address or a host name, never the text a rule matched or the element it matched on, and nothing about what you did in the browser afterwards. They are handled for us by the analytics provider described under Transferring Information to Third Parties below.
What never leaves your browser
The extension reads pages in order to recognize the shapes that phishing takes. None of what it reads is transmitted to us:
- No page content. The text of a page, its markup, and its structure stay in your browser. When a rule matches, what travels is the identifier of that rule — never the text it matched or the element it matched on.
- No values you type. The rules that examine forms ask structural questions, such as whether a password field is present or whether the form would submit over an insecure connection. Nothing reads the contents of a field, so no password, card number, or anything else you enter is ever sent to us or seen by us.
- Nothing describing whether you are at your computer — no idle state, and no window or tab counts beyond the one-time checkup described above.
The extension also holds things on your device that it never sends us: the rules it has downloaded, the list of sites you have told it to skip, the sites you have chosen to continue to despite a warning, a short-lived note of the address each tab was last sent to, a short-lived record of what it concluded about a file you downloaded, and your own settings.
When the extension itself fails, it reports that failure to us so that we can fix it. What is sent is the error, its stack trace, and the version of the extension. The address of any page you were visiting is removed before the report is sent, as is the address of a site we blocked, and no identifier of your account is attached — so a report tells us that something broke and in which part of the extension, and not who you are or where you were. Reports are handled for us by the error-reporting provider described under Transferring Information to Third Parties below.
4. Your Rights Regarding Your Personal Information
Your rights
Subject to the exemptions available under applicable law, you may at any time:
- Access the Personal Information we hold about you and receive a copy of it.
- Have inaccurate or incomplete Personal Information rectified.
- Have your Personal Information erased. While your subscription is active you can delete your account, and everything held against it, from inside the app — open Profile and choose Delete account. Without one, the app opens on the screen that asks you to subscribe and that control is out of reach, so write to support@resafe.io instead and we will delete the account, and everything held against it, for you. Retaining Your Information below names the one record a deletion leaves behind, and why it has to.
- Restrict or object to our processing of your Personal Information.
- Receive your Personal Information in a structured, commonly used, machine-readable format and have it transmitted to another controller.
- Withdraw a consent you have given us, at any time, and ask us to stop the processing that relied on it.
- Lodge a complaint with your local supervisory authority.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and it may mean we can no longer provide some or all of the Services to you.
Fees
You do not have to pay a fee to exercise these rights. We may charge a reasonable fee, including administration costs, if your request is manifestly unfounded, repetitive, or excessive, and we may instead refuse to act on such a request. We may ask you for information that confirms your identity before we act, so that Personal Information is not disclosed to someone who has no right to it.
How to contact us
Send requests, questions, and complaints about this Privacy Policy to our Data Protection Officer at support@resafe.io. We respond within the period required by applicable law, and will tell you if we need longer because the request is complex.
5. Database and Use of Information
What we use information for
Information collected through the Services is stored in our database and used for the following purposes:
- Providing the Services, and enabling you to use them efficiently and securely.
- Detecting, investigating, and warning you about threats, and improving the accuracy of that detection.
- Improving, enriching, modifying, and removing features of the Services.
- Producing anonymized and aggregated research, statistics, and threat intelligence, which do not identify you.
- Verifying your identity, preventing fraud and abuse, and enforcing our Terms of Service.
- Collecting fees and administering your subscription.
- Responding to your support requests and telling you about changes to the Services.
- Offering you additional products and services, subject to your choices described below.
- Complying with legal, regulatory, accounting, and reporting obligations.
Legitimate interest
We rely on our legitimate business interest to use Personal Information in order to send you content and offers we believe are relevant to you. You may object to this at any time by writing to support@resafe.io. Objecting may affect our ability to provide you with parts of the Services.
Information we need
Some of the information you are asked to provide is necessary in order for us to provide the Services. If you refuse to provide it, you may not be able to receive the Services or particular features of them.
Information from other sources
We may receive information about you from business partners, resellers, professional advisers, identity and payment providers, security researchers, and public or commercially available threat-intelligence sources. That includes records of data breaches you appear in, which reach us through the provider described under Transferring Information to Third Parties below. We combine that information with information we hold in order to deliver and improve the Services.
6. Storing Information and Mailings
ReSafe may store the information described in this Privacy Policy, and use it, for the following purposes:
- Marketing, advertising, and sales promotion, including by email, message, or any other medium.
- Encouraging loyalty, and conducting research and surveys about the Services.
- Investigating complaints internally and improving how we handle them.
- Operational, marketing, and statistical purposes.
- Providing the Services and any additional services you ask for.
Information is stored on servers operated by us and by our hosting and infrastructure providers, and may be processed in countries other than the one you live in. Where Personal Information is transferred out of the European Economic Area or the United Kingdom, we put in place an appropriate transfer mechanism, such as the European Commission standard contractual clauses.
7. Transferring Information to Third Parties
ReSafe does not sell your Personal Information. We transfer it to third parties only in the following circumstances:
- When you have permitted the transfer.
- To the advertising platforms that brought you to us, in the hashed form described under Use of Cookies, so that we can measure our own advertising.
- To authorized service providers who process information on our behalf and under our instructions, including hosting, payment, communications, analytics, crash and error reporting, customer support, breach monitoring, DNS resolution and filtering.
- When you have breached our Terms of Service or acted unlawfully in connection with the Services.
- To enforce our Terms of Service or this Privacy Policy.
- In response to a subpoena, court order, or lawful request by a governmental or regulatory authority.
- To establish or exercise our legal rights, or to defend against legal claims, or as otherwise required by law.
- Where we investigate suspected illegal activity, fraud, or other wrongdoing.
- Where necessary to protect the rights, property, or safety of ReSafe, our users, or others.
- To collect unpaid fees, including through collection agencies or attorneys.
- In connection with a merger, acquisition, reorganization, sale of assets, insolvency, or liquidation, in which case the recipient will be bound by this Privacy Policy or a policy that protects you at least as well.
Service providers are permitted to use Personal Information only for the purpose for which we disclosed it, and are bound by written agreements that require them to keep it confidential and secure.
Checking a suspected fake shop
Where a site is checked as Site blocking describes, its name is looked up in the public registration-data service of the registry responsible for that name (RDAP), which answers with the date the site was registered, and its name and the text of its front page are sent to Google, whose Gemini model on Google Cloud judges whether the page is a fraudulent shop. Both requests are made by our servers about the site: neither receives your account, your device, your address, or anything about you, and the registry receives what anybody looking the name up would send it.
Google acts as our processor under the Google Cloud data-processing terms, which permit it to use what we send only to answer our request and not to train its models, and we send it nothing that identifies a person. The site’s own page may of course contain whatever its operator put there; we send the page as it is served to the public, and never anything you typed into it.
Breach monitoring
Telling you whether your information has appeared in a data breach requires us to check it against a provider that maintains records of data breaches that have already occurred. Where you ask us to monitor an identifier — an email address or a phone number — we transfer that identifier to such a provider for that purpose alone. While your subscription is not active we transfer the email address on your account in the same way, so that we can show you what a scan finds, and we do so only after that address has been confirmed; that check is separate from monitoring and ends when your subscription becomes active.
We transfer the identifier and nothing further. The request is made by our servers, so your device, your IP address, and the remainder of your account are not disclosed to the provider. Apart from the check described above, we transfer an identifier only after you have asked us to monitor it and, where we ask you to demonstrate that you control it, only after that demonstration has succeeded.
The provider returns the breaches in which the identifier appears, the date of each, and the categories of information each exposed. Where it returns the exposed information itself, such as a password, we retain that information so that we may show you what to change. Information of that kind is the most sensitive we hold: it is not logged, it is never sent anywhere but back to you, it does not reach our analytics — the screen that shows it to you is masked in the session recordings described under Information We Collect above, and no analytics event carries it — and it is not used for any purpose other than presenting your own result to you.
Such a provider acts as our processor under a written data-processing agreement, may use what we transfer only in order to answer our query and not for its own purposes, and undertakes in its own terms not to retain a history of the queries we submit. We will identify the provider we use upon your written request to support@resafe.io.
Removing an identifier from monitoring, which you may do at any time within the app, ends every subsequent check against it. Removal does not erase the identifier from the breach itself: that information was published outside our control and outside the provider’s, and neither of us is able to withdraw it.
8. Third Parties
The Services contain links to, and integrations with, websites and applications that we do not operate. Those services run under their own privacy policies and may independently collect Personal Information from you.
We recommend that you read the privacy policy of any third party before you use it. Unless we say otherwise, such third parties are neither controlled nor owned by ReSafe, and we are not responsible for their practices.
The categories of third party who may receive information in connection with the Services are:
- Hosting, storage, and infrastructure providers.
- Payment processors and billing providers.
- Email, SMS, and push-notification providers, to whom we transfer the contact details needed to send you messages — your email address and, where you have verified one with us, your phone number — along with your name, your time zone, and the state of your subscription.
- Breach monitoring providers, to whom we transfer the identifiers you ask us to monitor — and, while your subscription is not active, the confirmed email address on your account — for the sole purpose of checking them against records of known data breaches, and who process them on our behalf under written agreement.
- Logo and icon providers, to whom we send the web address of a service and nothing about you.
- Link-shortening services, which receive a shortened web address found in a text message and nothing about you.
- Google’s Web Risk service, which receives the short opening fragment of a one-way fingerprint of a web address found in a text message — and only when that fragment matches a list of dangerous sites we hold a copy of — so that we can ask which full fingerprints it stands for. The fragment begins the same way for an enormous number of unrelated addresses, it is sent from our servers rather than your phone, and neither the address, the message, nor anything about you goes with it.
- Domain Name System resolvers, to whom the name of a site being looked up is sent so that the lookup can be answered and dangerous sites refused, and who receive the lookup from us rather than from you.
- Publishers of dangerous-site lists, who receive a short fragment of a one-way fingerprint — never an address — so that a page which begins like a listed one can be confirmed, and who receive it from us rather than from you.
- Analytics, product-measurement, and performance-monitoring providers.
- Advertising, attribution, and search-engine providers.
- Identity providers you choose to sign in with.
- Partners, resellers, and sub-contractors who help us deliver the Services.
- Professional advisers, such as auditors, insurers, and lawyers.
9. Retaining Your Information
How long we keep information
We retain Personal Information only for as long as necessary to fulfil the purposes it was collected for, including satisfying any legal, accounting, or reporting requirement. In deciding the retention period we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it, and whether we can achieve those purposes by other means.
Scanned message content
To the extent you have chosen to enable our SMS filtering feature as part of the Services, we will retain the content of the text messages your device sent us to check, as of your enabling of such feature and thereafter during your use thereof, and use such for the sole purpose of improving our Services. Such information is retained for ninety days, then deleted, and is not linked to your account.
Site blocking records
A name your device looks up that we do not refuse is not retained at all, so no retention period applies to it — with the one exception Site blocking describes under A site we check: the record that your device resolved a site while it was being checked, which we delete the moment the site is judged fine and otherwise thirty days after your device last resolved it, and the check’s own record of the site, which is kept for as long as its result stands and is not linked to you. The record of a site we blocked is your protection history and is what the app shows you on your activity timeline; we delete it ninety days after it is written, together with our record of any notification we sent about it. The daily counts of lookups we answered carry no site name, and are kept for the life of your account so that your dashboard can go on counting them.
The addresses the extension asks us to check are not retained at all, so no retention period applies to them. The record of a rule matching is your protection history and is what your dashboard shows you; we delete it ninety days after it is written. The daily counts of pages inspected carry no address, and are kept for the life of your account so that your dashboard can go on counting them.
Whatever has not already expired is deleted when your account is deleted, and you may ask us to erase it sooner under Your Rights Regarding Your Personal Information above.
Account information
We retain information associated with your account while the account is active and for as long as necessary to provide you with the Services. When you delete your account we erase the records we hold about you, rather than deactivating them or keeping an anonymized copy. One record is kept, and only if you bought a subscription inside our iOS app: the identifier the App Store uses for that subscription, the account identifier that claimed it, and the date it was claimed. We keep it because the subscription carries on billing at the App Store after our records of you are gone, and this is what stops it being handed to the next person who asks to restore a purchase. It holds no name, no address and no contact details, and the account identifier in it refers to an account that no longer exists. The financial record of any payment stays with our payment processor, which keeps it for as long as tax and accounting law requires. Copies of deleted records persist in routine backups until those age out on our normal rotation, during which they are not restored to live use or used for any other purpose.
Marketing communications
Information used for marketing is retained until you ask us to stop sending you marketing messages, after which we keep the minimum record needed to honour that request.
Complaints and fault reports
Following a complaint or a fault report, we retain the details of the report for as long as necessary to protect ReSafe's legal rights.
10. Your Choices About Collection, Use, and Mailings
Declining to provide information
You may decline to provide information to us. Because some information is necessary to deliver the Services, that may mean you are unable to use the Services or particular features of them.
Mailings
ReSafe may send you emails and messages about the Services, including updates, improvements, and offers, as well as transactional communications such as security alerts, service announcements, receipts, and surveys. Transactional and security communications are part of the Services and are not marketing.
Opting out
You can opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email, by replying STOP to a marketing text message, or by writing to support@resafe.io. If your information has already been shared with a third party for that purpose, you may need to send your opt-out request to that third party as well.
11. Use of Cookies
Why we use cookies
ReSafe uses cookies and similar technologies to collect information about your device and your activity on our website, in order to operate, improve, and personalize your experience.
Types of cookies we use
- Necessary cookies: essential for the Services to function, including signing you in, keeping your session secure, and recognizing the same browser when you reconnect our browser extension, so that one browser is not counted as several devices. No consent is required for these. They hold a session token or a random identifier for the browser itself, and they do not record your name, your contact details, or the pages you visit.
- Performance cookies: track how the Services are used, which pages are accessed, how long visits last, and which elements are interacted with, under a random identifier rather than your name. Third parties may assist us with this. They also remember which advertisement or link brought you to our website — the campaign and creative named in the link, the site you came from, and the page you arrived on — so that we can tell which of our advertising works.
- Functionality cookies: remember your settings, such as text size, language, and timezone. The information is anonymous and cannot track your activity elsewhere.
- Targeting and advertising cookies: set by the advertising platform that brought you here, and used to tell that platform when a visit leads to a sign-up or a purchase, in a form that lets it recognise the click, so that it can measure our advertising and show it to people like you. We may also let that platform know when a visit leads to a sign-up, a checkout or a purchase using hashed identifiers, so that it is counted even where those cookies were not set. We do not use them to show you other companies' advertising.
- Analytics cookies: collect usage and navigation data so that we can decide which features to add or change. They cannot identify you personally.
How we ask
Necessary cookies need no consent. For every other kind, how we proceed depends on where you are. Where the law of your location requires your consent first — in the European Economic Area, the United Kingdom and Switzerland — none of them is set until you accept them on the banner we show, and they stay off if you reject them. Elsewhere they are set when you arrive, the banner tells you so, and you can turn them off there or at any time afterwards from the Cookie preferences control in the footer of every page. Either way, you may withdraw at any time, and withdrawing deletes the cookies we and the advertising platform set. If your browser sends the Global Privacy Control signal, we treat it as a refusal of the targeting and advertising cookies unless you have accepted them here yourself.
Turning cookies off
You can set your browser to refuse cookies or to alert you when cookies are being sent. If you disable cookies, some parts of the Services may not function properly.
Third-party cookies
Third-party websites reached through the Services, and third-party content embedded in our pages, may store their own cookies. ReSafe has no control over those cookies, and you should check the relevant third party's cookie policy.
12. Data Security
The measures we take, and their limits
ReSafe implements technical and organizational security measures — including encryption in transit and at rest, access controls, and least-privilege internal access — to help prevent unauthorized persons from gaining access to your Personal Information. However, no system can be completely secure, and we do not warrant that the Services will be entirely immune to breaches of security.
In the event of a breach affecting the security of your data, we will act in accordance with applicable law and will contact you where we are required to do so.
Inspections and liability
We inspect and upgrade our security arrangements periodically. Subject to applicable law, ReSafe will not be liable for direct or indirect damage caused to you by the exposure of your information through unauthorized access, where we have taken the measures described above.
You are responsible for keeping your account credentials confidential and for any activity that takes place under your account. Tell us immediately if you believe your account has been compromised.
13. Children's Privacy
The Services are not directed at children under the age of 16, and we do not knowingly collect Personal Information from them. If you believe a child has provided us with Personal Information, contact support@resafe.io and we will delete it.
14. Changes to This Privacy Policy
ReSafe may update this Privacy Policy from time to time. Where a change is substantial we will notify you on the website homepage, within the Services, or by email. Other changes take effect when the updated policy is published, and the date at the top of this page tells you when it was last revised.
You are responsible for reviewing the current version. Continuing to use the Services after a change has been made will be considered your consent to the amended Privacy Policy.
15. Contacting Us
ReSafe Ltd. is the controller of the Personal Information described in this Privacy Policy. Send privacy questions, requests, and complaints to our Data Protection Officer, and any other question, at support@resafe.io.
