PushFix
Legal

Privacy Policy

What we collect, why we collect it, how long we keep it and how to get rid of it.

  • Free during early access
  • No credit card
  • Staging-first
  • Evidence for every finding

Last updated: 10 October 2026

This is a plain-language summary. It is not legal advice, and where your jurisdiction grants stronger rights than those described here, those rights prevail.

1. The short version

  • We collect the minimum needed to run your account and your audits.
  • We do not sell your data, and we do not use it to train AI models.
  • Audit targets are scanned as an anonymous visitor; we store the findings you asked for.
  • You can delete a project and its findings at any time.

2. What we collect

  • Account details: your email address, the organization name derived from it, session records, and a record of the date and the version of the Terms of Service you accepted. Access is passwordless, so we never store a password.
  • Audit data: the target URLs you submit, the answers you give during onboarding, and the pages, findings, occurrences and evidence the audit produces.
  • Usage and billing: which audits were run and when, so usage can be metered, plus subscription identifiers from Stripe.
  • Operational logs: request and error logs used to keep the service running and to investigate incidents.

3. How we use it

To run audits, produce reports, meter usage and bill for it, keep your account secure, answer support requests, and improve the product. We do not sell personal data and we do not use your findings to train models.

4. Audit targets and findings

When PushFix audits a target, it behaves like an ordinary anonymous visitor unless you provide a test account for the authenticated checks. Evidence such as screenshots and response excerpts may therefore contain content from the target. That content is stored only in your account, visible only to you, and deleted when the project is deleted.

A test account you add is used for one thing: signing in to your own application during an audit. Its password is encrypted before it is stored, with a key held outside the database, and it is never shown back to you or to anyone else. Remove the account on the project's Logins screen and the stored password goes with it.

5. Cookies and sessions

PushFix uses a single host-only session cookie to keep you signed in. It is marked HttpOnly, SameSite=Lax, and Secure where the site is served over HTTPS. There are no advertising or third-party tracking cookies.

6. Sub-processors

We rely on a small number of providers to operate: hosting for the application and database, object storage for evidence, an email provider for sign-in codes, and Stripe for payments. Each processes only the data needed for its role.

7. Retention

Account data is kept while your account is active. Audit data is kept until you delete the project or the account. Operational logs are kept for a short period for troubleshooting. Sign-in codes expire quickly and are stored only as a hash.

8. Your rights

You can access, correct, export or delete your data, and you can close your account. Deleting a project removes its audits, findings and evidence. To make a request, email us.

9. Security

Access to production data is restricted, transport is encrypted, and the access model is least-privilege. PushFix deliberately offers no endpoint for storing third-party credentials, because it does not keep a key-management service.

10. Children

PushFix is a tool for professionals and is not directed at anyone under 16.

11. Changes

We may update this policy. Material changes are reflected in the date at the top of this page.

12. Contact

Privacy questions and data requests go to hello@pushfix.com. See also our Terms of Service.