Privacy
The short version
EverThread runs observation-only security scans against the URL you register, against the hostnames you allowlist. We email you when a finding opens, regresses, or stays unresolved past 24 hours. That's it.
What we collect
- The URL and allowlist hostnames you register.
- The email address(es) you nominate to receive alerts. Whop collects your billing email; we never see your card number.
- Scan output: HTTP status, headers, TLS chain, presence of well-known files, and the structure of public pages. We do not store page bodies beyond what the scanner needs to fingerprint findings.
- An HMAC-signed session cookie on
security.everthread.liveso the dashboard knows which tenant is logged in. We do not set cookies oneverthread.live.
What we don't do
- We don't sell scan data, ever.
- We don't aggregate findings across customers.
- We don't run third-party analytics or ad pixels on this site.
- We don't attempt to bypass authentication or exploit vulnerabilities.
When you cancel
After your paid period ends, your sites and findings become read-only for 30 days. After 30 days, your company's data is purged from our encrypted audit chain and JSONL stores.
Contact
Email privacy@everthread.live for data requests.