/ Legal
Privacy Policy
Last updated: 14 June 2026
This Privacy Policy explains how we collect, use, and protect personal data when you use Brutor. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
01Data controller
The controller responsible for your personal data is:
Operator

You can contact us about privacy matters via our contact page.
02Data we collect
- Account data — name, email, and authentication identifiers, handled by our authentication provider.
- Billing data — subscription and payment status. Card details are processed by our payment provider; we do not store full card numbers.
- Scan data — the domains you submit and the results we generate from scanning them.
- Technical & usage data — IP address, device/browser information, and logs needed to operate and secure the Service.
03How we use your data
- to provide the Service and run the scans you request;
- to manage your account, subscription, and payments;
- to secure the Service and prevent abuse;
- to communicate with you about your account and important updates;
- to comply with legal obligations.
We do not sell your personal data, and we do not use your scan data to train, fine-tune, or otherwise update the weights of AI models.
04Legal bases
Where the GDPR applies, we rely on: performance of a contract (to provide the Service); our legitimate interests (to secure and improve the Service and prevent abuse); your consent (where requested); and compliance with legal obligations. Under the FADP we process data in good faith and proportionately for the purposes described here.
05Service providers (sub-processors)
We share data only with providers who help us run the Service, under appropriate contractual safeguards. Current categories include:
- authentication and subscription management;
- payment processing;
- cloud database and application hosting;
- a dedicated scanning server located in the EU;
- an AI provider used to analyze and explain findings.
We do not sell your personal data. A current list of named sub-processors is available on request.
06International transfers
Some providers may process data outside Switzerland or the EU/EEA. Where this occurs, we rely on recognized safeguards such as adequacy decisions or the EU Standard Contractual Clauses (with the Swiss addendum where relevant).
07Retention
We keep account and billing data for as long as your account is active and as required by law. Raw scan artifacts (logs and evidence) are retained for a limited period for debugging and then deleted; findings and report summaries are retained while your account is active.
08Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, and request portability. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local EU supervisory authority.
09Cookies
We use essential cookies required for authentication and to keep you signed in. We do not use these for advertising.
10Data security
Security is core to what we do. By design, Brutor never accesses your source code or internal systems. We use encryption in transit and apply appropriate technical and organizational measures to protect personal data.
11Children
The Service is not directed to children and is intended for users aged 18 and over.
12Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email.