Privacy Policy
DeltaLayer is operated as a personal project from the Netherlands. This Privacy Policy explains how DeltaLayer collects, uses and protects personal data when you use deltalayer.eu.
If you have questions about this Privacy Policy or want to exercise your privacy rights, you can contact us at hello@deltalayer.eu.
1. What DeltaLayer does
DeltaLayer is a defensive, view-only domain stack checker. It helps users understand which publicly visible infrastructure and providers are connected to a domain, such as DNS, mail, hosting, CDN and related services.
DeltaLayer only uses publicly observable technical signals. It does not perform port scanning, exploitation, authenticated probing or intrusive security testing.
2. Data we collect
Depending on how you use DeltaLayer, we may process the following data.
Domain scan data
When you start a scan, we process the domain name you submit and the public technical signals discovered for that domain. This may include DNS records, nameservers, mail records, website response information, provider signals, IP/ASN information and related scan metadata.
Scan results are stored so we can generate and display a shareable report.
Technical data
We may process technical information such as IP address, request headers, timestamps, rate-limit counters, error logs and browser/runtime information. This is used to operate, secure and improve the service.
Early access or contact data
If you sign up for early access or contact us, we may process your name, email address, consent status, message content and source of signup.
Account data
If you use login or account features, we may process your email address, authentication status, session cookies and account-related data. Authentication may be handled through Supabase Auth.
3. How we use the data
We use the data to:
- run domain scans requested by users;
- store and display scan reports;
- detect visible providers and infrastructure patterns;
- prevent abuse and enforce rate limits;
- maintain security and reliability;
- respond to contact or early access requests;
- operate account and admin features;
- improve the quality of provider detection and product functionality.
4. Legal bases
We process personal data under the following legal bases:
- Performance of a service: to run scans, show reports and provide requested functionality.
- Legitimate interests: to secure the service, prevent abuse, maintain logs, improve detection quality and operate a reliable product.
- Consent: when you explicitly sign up for product updates or early access communication.
- Legal obligation: where we need to keep certain records to comply with applicable law.
5. Shareable scan reports
Scan reports may be accessible through a unique share link. Anyone with the link may be able to view the report.
Please do not submit domains or information if you are not comfortable with a report being generated from publicly visible signals. If you want a report removed, contact us at hello@deltalayer.eu.
6. Cookies and sessions
DeltaLayer may use essential cookies or similar technologies to provide login sessions, security and basic service functionality. These cookies are necessary for the service to work and are not used for advertising.
If analytics are added in the future, this policy will be updated to explain what is collected and whether consent is required.
7. Processors and service providers
We use third-party service providers to operate DeltaLayer. These may include:
- Supabase, for database, authentication and backend infrastructure;
- hosting and deployment providers;
- email providers, if we send transactional or product-update emails;
- infrastructure and monitoring providers;
- the private scanner worker used to process scan requests.
These providers may process data on our behalf only where needed to provide the service.
8. International transfers
DeltaLayer is operated from the Netherlands. Some service providers may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards such as EU Standard Contractual Clauses or other lawful transfer mechanisms where required.
9. Retention
We keep personal data only for as long as needed for the purposes described in this policy.
As a baseline:
- scan reports may be retained until they are deleted, expire or are no longer needed for the service;
- rate-limit and security data is kept for a limited period;
- early access signup data is kept until you unsubscribe or request deletion;
- account data is kept while your account exists;
- logs may be retained temporarily for security, debugging and abuse prevention.
Specific retention periods may be updated as DeltaLayer matures.
10. Your rights
If the GDPR applies to you, you may have the right to:
- access your personal data;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to processing;
- withdraw consent;
- request data portability;
- lodge a complaint with a supervisory authority.
In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.
To exercise your rights, contact us at hello@deltalayer.eu.
11. Security
We take reasonable technical and organizational measures to protect personal data. Sensitive server-side credentials, scanner tokens and database keys are not exposed to the browser.
No online service can be guaranteed to be completely secure.
12. Children
DeltaLayer is not intended for children under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page.