Privacy

Effective June 2026

The short version

Uvy is an AI-native penetration testing service. We only ever test the applications and domains you have proven you control and authorized us to assess, our testing is scoped and does not attempt destructive actions, and we store the findings so you can fix and retest them. We don't sell your data, pool it across customers, or use it to train shared models.

What we collect on this website

When you create an account we collect your name and email. When you request or scope an engagement, we collect what you tell us about your application. We use analytics to understand usage and we don't run advertising trackers; the providers we use are listed under subprocessors.

Signing in with Google

If you choose “Sign in with Google”, Uvy uses Google OAuth with the openid, email, and profile scopes to receive your name, email address, and Google account identifier. We use this Google user data to create and set up your Uvy account and sign you in: this includes confirming your identity, creating your account and its workspace, linking any engagement you previously requested with the same email, and signing you in. We store your name and email on your account (we receive the Google account identifier but do not store it); we request online access only, so we do not retain Google access or refresh tokens after the sign-in exchange. We do not sell or transfer Google user data, we do not use it for advertising, and we do not use it to train AI or machine-learning models. Uvy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Signing in with GitHub works the same way and is used only to create and authenticate your account; you can also sign in with an email and password instead. You can disconnect a provider or delete your account at any time by emailing [email protected].

Domain ownership and authorization

Before Uvy tests a domain, you must prove you control it (a DNS record or a file we ask you to publish) and confirm you are authorized to have it tested. We do not scan, probe, or attack any target you have not verified and authorized. This is the core safeguard of the product.

What the product does when you run an assessment

When you launch an assessment, Uvy's agents send crafted requests to the target you verified, to discover and prove vulnerabilities the way an attacker would. Testing runs from isolated, dedicated infrastructure with controlled egress. We store the engagement's runs, the findings (such as affected URLs and parameters, proof-of-exploit evidence, severity, and remediation guidance), and the resulting reports, so you can review, fix, and retest. AI model providers receive only the minimum context each step requires, under terms that prohibit training on it.

Payments

If you purchase an engagement, payment is processed by Stripe. We do not store your card details, Stripe does. We retain the record of the purchase for invoicing and tax purposes.

Retention and deletion

Your findings, reports, and engagement history persist while you are a customer so you can track remediation over time. The dedicated infrastructure used to run an assessment is ephemeral and torn down after the engagement. You can request deletion of your account and assessment data at any time; we retain only what invoicing and law require.

Your rights

Wherever you are, you can ask us to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Depending on your location (for example under GDPR or CCPA/CPRA) you may have additional rights, including the right not to be discriminated against for exercising them; we don't sell or share your personal data for advertising. To make a request, email [email protected].

Where data is processed and security

Uvy is operated from the United States, and our providers may process data in the US and other countries; where required we rely on appropriate safeguards (such as standard contractual clauses) for international transfers. We protect data in transit and at rest and restrict access to it. If a breach affects your data, we will notify you and any regulator as the law requires, without undue delay.

Children

Uvy is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16; if you believe a child has given us data, contact us and we'll delete it.

Subprocessors

We rely on cloud infrastructure providers to host the platform and the isolated testing infrastructure, AI model providers to run inference, an analytics provider for usage measurement, Stripe for payments, and an email provider for transactional messages. Each is bound by data processing terms consistent with this policy. Our current named subprocessor list is published on our security page and updated as it changes.

Changes and contact

We may update this policy; material changes take effect when posted here. Questions, requests, or deletions: [email protected]. We respond to data requests within 30 days, or sooner where the law requires.