Privacy Policy
Last updated: September 25, 2026.
Intavant, LLC ("Intavant," "Clearnode," "we," "us," or "our") provides the clearnode.app public website and the Clearnode monitoring service. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information about website visitors, prospective customers, account users, and people whose information may appear on websites our customers ask us to scan. It is a notice of our practices, not a waiver of your legal rights. Our Terms of Service govern use of the website and service.
The short version
- We use account, contact, usage, and customer-supplied site information to operate Clearnode, provide support, secure and maintain it, bill through Stripe, and meet legal duties.
- Scans of public sites may capture URLs, page content, screenshots, findings, logs, and personal information visible on those sites. Customers choose and authorize the sites and remain responsible for their content and notices.
- We do not sell personal information or customer data, and we do not provide customer data to AI services for training. An acquisition of Intavant as an ongoing business may include customer records, subject to this Policy.
- We use US hosting and processing. Stripe processes payment methods; we do not receive full card numbers or bank-account credentials.
- We generally purge customer-specific index data within 30 days after cancellation, but some scan or index data may be kept longer, potentially indefinitely, for indexing. Billing records and security logs are kept at least seven years. Do not rely on us to retain or restore your data after cancellation.
- The app does not use analytics or advertising trackers. The public website may use analytics tools, with consent controls where required. Marketing email requires separate consent; account, security, billing, and legal notices do not.
- Ask about access, correction, or deletion at [email protected]. Some records must or may be retained for legal, security, or indexing reasons as explained below.
1. Scope and our roles
This Policy applies to information collected through the public website, account registration, the monitoring service, communications with us, and our authorized service providers. It does not govern the independent privacy practices of customer websites, Stripe, or other third parties. Intavant decides how account, billing, website-visitor, and support information is used. For personal information contained in sites a customer submits for scanning, the customer decides which sites to monitor and is generally responsible for the site's privacy notices and lawful basis for that processing; Intavant processes the information to provide and operate the service as described here and in our Terms. If you appear on a customer-monitored site, contact that site's operator first about its privacy practices; we will assist with a request concerning information we hold where appropriate.
The paid service is not offered to customers located in the European Economic Area or United Kingdom at launch. We nevertheless aim to describe our practices transparently and honor rights that apply under relevant law. If processing for a customer requires a separate data-processing agreement, the customer must contact [email protected] before submitting that data.
2. Information we collect
Information you provide. We collect names, email addresses, organization and account details, support and contact-form messages, preferences, and information you voluntarily provide in normal use of the service. We collect the sites and domains you submit, settings, reports you generate, and communications about your account. Please do not submit sensitive personal information unless necessary and authorized.
Site and scan information. Monitoring publicly accessible sites can collect site names, domains, URLs, page content, page structure, screenshots, accessibility and site-health findings, uptime observations, scan logs, and related metadata. Public pages can contain personal information about visitors, employees, or other people even when a customer does not intend that. We collect only through the customer-authorized monitoring workflow and use this information for the purposes below.
Information collected automatically. We collect account and site activity logs, timestamps, IP addresses, basic browser and device information, security and diagnostic events, and information needed to operate sessions and measure service usage. On the public website, we may collect page-view and referral information through analytics technologies as described under Cookies. We do not use analytics or advertising trackers inside the Clearnode application.
Billing information. Stripe collects payment-method information and processes charges. We receive or exchange names, email addresses, billing and subscription details, invoices, payment status, transaction identifiers, and related information needed to administer purchases and resolve billing issues. We do not store or have access to full payment-card numbers or bank-account credentials.
3. How and why we use information
We use information to create and administer accounts; perform requested scans and monitoring; generate findings, reports, and support responses; measure plan usage and bill through Stripe; communicate about transactions, service changes, security, and legal matters; maintain, troubleshoot, protect, and improve our platform; prevent fraud, malware, and abuse; comply with law and enforce our Terms; and produce aggregate analytical, administrative, and reporting information. We use customer site data only to provide support, process and store requested site information, understand service usage, maintain and manage the platform, and create aggregate analysis and reports. We do not use it for unrelated advertising or sell it.
Where a law requires a legal basis, these activities rest on performance of a contract or steps requested before one; our legitimate interests in operating, securing, supporting, and improving the service where those interests are not overridden by individual rights; compliance with legal obligations; or consent where required, such as for optional marketing or nonessential cookies. You may withdraw consent without affecting processing already lawful before withdrawal. We do not use automated decisions that produce legal or similarly significant effects about individuals solely from personal information.
4. When we disclose information
We disclose information only as needed for the purposes in this Policy, under appropriate access limits, or as law permits or requires. Our US-based providers include Stripe for payments and subscriptions, Laravel Cloud and AWS for application and data infrastructure, and Cloudflare for delivery and security. Providers that deliver transactional communications or help us support and maintain the service may receive the limited information needed for those functions. We require providers to handle information for authorized purposes and apply appropriate safeguards. Stripe may handle payment information under its own privacy notice and legal obligations.
We may disclose information to comply with lawful process; protect users, the public, our rights, or the security of the service; investigate suspected fraud, malware, or unlawful content; or enforce our Terms. Professional advisers under duties of confidentiality may receive limited information when necessary for legal, accounting, or dispute-related work. We do not disclose personal information to unrelated third parties for their independent marketing. We may share aggregate or de-identified information that does not reasonably identify a person or customer for analysis, administration, reporting, and product management.
5. No sale of information; business transfers
We do not and will not sell personal information or customer data to third parties for money or other valuable consideration, or share it for cross-context behavioral advertising. We do not permit analytics tools to use information from our sites for their own targeted advertising. If Intavant is involved in a merger, acquisition, reorganization, or sale of the ongoing business or substantially all relevant business assets, account and customer records may transfer with that business, subject to confidentiality and this Policy. We will not separately sell customer lists or personal information detached from the business. If a successor proposes materially different practices, it must provide any notice or choice required by applicable law before applying them to previously collected information.
6. Cookies and analytics
The website and service use necessary cookies or similar storage for sessions, preferences, security, fraud prevention, and operation. Cloudflare Turnstile or similar security technology may process browser and device signals to distinguish legitimate activity from abuse. The public website may use third-party analytics or tracking tools to understand normal site usage, page performance, and traffic sources; the application itself does not use analytics or advertising trackers. We will identify and obtain consent for nonessential technologies where applicable law requires it, and offer a way to change that choice. You can also manage cookies through your browser, though blocking necessary technologies may impair the site. We do not use analytics data for targeted advertising or sell it. If our tracking practices materially change, we will update this Policy and any required choices before the change.
7. AI tools and email
We do not provide customer data or personal information to AI services for training or use customer scans to train AI models. Our personnel may use AI tools to help provide support, develop products, or analyze aggregate information only without disclosing customer content, account-specific scan data, or personal information to those tools. We may send account, billing, platform, security, and legal notices when needed to provide the service or comply with law. We send promotional or marketing email only after separate, explicit consent; accepting this Policy or our Terms is not marketing consent. Marketing messages will provide an unsubscribe method, and withdrawal does not stop necessary transactional or legal notices.
8. Retention and deletion
We keep information for the purposes described here and as needed to satisfy legal, accounting, security, and dispute obligations. Customer-specific index data is generally purged within 30 days after cancellation. Some scan data or scan-derived indexing records may be retained for indexing purposes beyond that period, potentially indefinitely. We may minimize, aggregate, or de-identify retained data where reasonably practical, but you should not assume that all scan information is erased automatically at cancellation. We do not guarantee that any customer data will remain available or recoverable after cancellation and may delete it sooner. Residual copies may remain temporarily in backups and be removed through their normal rotation or restoration controls.
Billing records and security logs are kept for at least seven years and may be kept longer if required for taxes, litigation, fraud prevention, security, or other lawful purposes. Other account, support, and website information is kept while reasonably needed for the relevant relationship or purpose, then deleted or de-identified unless an exception applies. If you request deletion, we will evaluate and honor it to the extent required by law and consistent with these stated retention purposes. We may need to verify your identity and retain limited records to document the request or comply with law.
9. Security and location
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, and alteration, including access controls and monitoring appropriate to the information involved. No service can guarantee perfect security. Please use strong credentials and tell us promptly about suspected account compromise at [email protected]. We will investigate and provide legally required notice of a security incident.
Customer account and scan data is hosted and processed in the United States. We do not authorize processors outside the United States to handle that data. Public internet traffic may transit networks outside our control, and a person visiting our public website from another country may cause browser and connection data to be transmitted to our US systems. If our hosting or processor locations materially change, we will update this Policy and make any legally required disclosures or arrangements first.
10. Your choices and privacy rights
Subject to applicable law and verification, you may ask to access, correct, obtain a copy of, or delete your personal information; object to or limit certain uses; withdraw consent; and appeal a denied request where law provides that right. We do not discriminate against you for exercising a legal privacy right. Email [email protected] with your request. We may ask for information reasonably necessary to verify identity or authority and will respond within the time required by applicable law. You may also unsubscribe from marketing through the message link and control optional cookies through available site controls. We do not sell information, so we have no sale-based opt-out to process.
If the request concerns personal information on a customer-controlled website or in that customer's scan, please contact the website operator first. We will direct requests to the relevant customer or assist it as appropriate, subject to our legal obligations. Deletion may be limited by another person's rights, lawful retention obligations, security needs, or the indexing retention described above; we will explain a denial when law requires it. Where applicable, you may complain to the privacy regulator or supervisory authority with jurisdiction over you.
11. Children and third-party sites
Accounts are for people at least 18. We do not knowingly invite children to register or provide their personal information directly to us. Public customer sites we scan might incidentally display information about minors; the customer is responsible for that site's content and permissions. If you believe a minor created an account or we hold information collected directly from a minor improperly, contact [email protected]. Links to third-party sites and payment pages are governed by those parties' privacy notices, not this Policy.
12. Changes to this Policy
We may update this Policy as our practices, providers, service, or legal obligations change. We will post the revised text with a new last-updated date and provide additional notice or seek consent for material changes where law requires it. We will not apply a materially new use to previously collected personal information without any notice or choice required by law. Please review this page periodically.
13. Contact
Intavant, LLC is responsible for this Policy. Send privacy, access, correction, or deletion requests to [email protected]. Send legal notices to [email protected].