cheatcode.chCHEATCODE.CH
Account
|
Online
Legal

Privacy Policy

Version 2026-06-10

Version of 23 August 2026. This policy is current and applies to your use of the service. Sections 1 and 4 reflect the review by legal counsel; other sections remain subject to review and may be updated, with any change published here with a new version date.

1. Introduction

This policy explains how Milan Takac, acting under the name cheatcode.ch, Zurich, Switzerland (“we”, “us”), is the controller responsible for processing personal data when you use our security-scanning service. For any privacy question, use our contact form or email info@cheatcode.ch.

2. Information we collect

Account: your verified email address. Scan data: the target URL you provide or the source code you upload as a ZIP archive (filename and contents), together with the publicly accessible resources we fetch (such as HTML, HTTP headers, and JavaScript), and the resulting scan metadata and findings. Technical: your source IP address, used for rate-limiting and abuse prevention. Payment: payment data is handled by a third-party payment processor; we receive confirmation and subscription details, not your full card data. Logs: subscription and email-engagement records (for example, which transactional emails were sent). Preferences: your chosen display language (stored in a cookie on your device and, so that emails arrive in your language, alongside your email).

3. How we use your information

We process your data to provide the service — running scans, delivering reports, and billing (performance of our contract with you); to prevent abuse, enforce rate limits, and improve accuracy (our legitimate interests); to send marketing email where you have consented; and to comply with legal obligations.

4. AI analysis and service providers

Your scan content is analysed using automated tooling and third-party artificial-intelligence models. When you start a scan, the content of your target is transmitted to our scanning infrastructure and to one or more third-party AI providers solely to identify potential security issues and generate your report. This covers the full submitted content — the uploaded ZIP archive or the publicly accessible resources fetched from the target URL — not only excerpts. The security analysis and the resulting report are produced fully or predominantly by automated technical tools and AI models; a human review takes place only where explicitly stated for the relevant offering. We do not use your submitted code or scan targets to train AI models, and we instruct our providers not to do so. We rely on the following categories of service providers (no names are published here): a third-party AI provider (analysis), a scanning-infrastructure host, a payment processor, an email provider, and a database host. Personal data is processed in Switzerland, Ireland, Germany, and the United States. Transfers within the EU/EEA rely on the adequate level of data protection recognised for those states. Transfers to the United States rely, depending on the provider, on the Swiss-U.S. Data Privacy Framework where the provider is certified under it, or otherwise on recognised standard data-protection clauses supplemented with the adaptations required under Swiss law and, where necessary, additional safeguards. A current list of the categories of providers we use is available on request. The automatically generated security report serves only as information and a basis for decision-making; any resulting assessment, remediation, or decision must be reviewed and made by you. Do not upload secrets, third-party personal data, or content you are not authorised to share; redact anything you do not want processed by an external AI provider.

5. Data retention

Your report is delivered by email. We apply the following concrete retention periods, enforced by automated deletion:

  • Paid scans (Check and Watch): scan content is purged shortly after the report email is delivered — we do not keep a copy of your scan data.
  • Uploaded ZIP archives: deleted automatically when the scan finishes, at the latest within 24 hours.
  • Results of free scans that are never unlocked: 7 days.
  • Technical failure logs: 30 days.
  • IP addresses used for rate-limiting and abuse prevention: 90 days.
  • The IP address recorded with your scan-authorization confirmation: 12 months.
  • Raw payment-event records: 90 days.
Email-address, subscription, and unsubscribe records are kept for as long as needed to provide the service, honour your unsubscribe choice, and meet statutory retention duties. Residual copies may persist in encrypted backups for a short period until they are overwritten.

6. Data security

We apply industry-standard protections, including encryption in transit and at rest and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

7. Analytics

We do not use third-party website-analytics or ad-tracking scripts. The only cookies we set are first-party and functional — your verified-email session and your language preference; we use no tracking cookies. The operational records described above (email, scans, purchases) are first-party data we collect only to run the service, as set out in sections 2 and 3.

8. Your rights

Subject to applicable law, you may request access to, correction or deletion of your personal data, restriction of or objection to processing, and data portability. You can unsubscribe from emails via the link in any email, and cancel Watch from your account. To exercise your rights, use our contact form or email info@cheatcode.ch.

9. Complaints

If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).

10. Changes to this policy

We may update this policy from time to time. Changes take effect when published, and we will provide notice of significant changes. The version is shown above.

Questions about your data? Contact us.