Privacy policy · Last updated 22 August 2026
Privacy, briefly.
A privacy policy from a security-education site should be readable, and it should be specific enough that you could check it. Here's ours.
SecureBySunday is a product of Northslate LLC, a Utah limited liability company, and that entity is the data controller for everything described below. "We" and "us" mean Northslate LLC throughout. Write to[email protected] about any of it — including the GDPR and CCPA rights set out further down.
What we collect
- Quiz answers stay in your browser's local storage. They are sent to us only if you submit your email to unlock your full breakdown — and then we store your email, your score, your stack, and your answers so we can send you your findings.
- Purchases are processed by Stripe. We receive your email and order details, never your card number.
- Counts, on our own server. We record that a page was viewed, that a quiz was started or finished, that a button was clicked, and how far down a page someone scrolled. A stored row is the event name, the path, an optional label, the date, and a random visit id — that's the whole record. It isn't tied to you, your email, or your quiz answers, and there's no profile behind it.
- About that visit id. It exists so we can tell four people taking the quiz apart from one person taking it four times — a distinction the counts above genuinely could not make, and one that changes what we conclude from them. It is sixteen random characters generated in your browser, it is stored in
sessionStorage rather than a cookie, and it is gone when you close the tab. It is not derived from your device, your IP, or anything about you, it is never attached to your email or your answers, and there is no column anywhere that could join it to them. Come back tomorrow and you are a new visitor to us, which is the point. - Scans get their own section below, because they are the one part of this site that reaches out and touches something.
- No third-party trackers. No Google Analytics, no advertising pixel, no session recorder. Your browser makes no third-party requests at all on this site — you can verify that in your network tab, which, frankly, is on brand. The one request that does leave our servers is the scan itself, described next, and your browser is not the thing making it.
Scans
The Exposure Scan is the one feature that makes a request to somewhere other than this site. You give us a URL; our server fetches it. Here is exactly what that means.
- What we fetch. The URL you give us, following redirects, plus a small fixed list of well-known paths that any web server is expected to answer for anybody, and the JavaScript files your own page links to. That's the whole list, it's the same list every time, and it's published in full on the methodology page.
- What we never do. We never log in, never query your database, never enumerate anything, and never send more than a handful of ordinary GET requests. Nothing we do to your app is anything a visitor couldn't do.
- What we store. The final URL after redirects, the hostname, the letter grade, the stack we detected, and for each finding: its type, the file name it was seen in, and how many distinct matches there were. Plus the date.
- What we never store. The value of a secret — ever. If the scan finds something shaped like an API key, what gets written down is "an AI-provider-shaped key, in /assets/index-abc123.js, 1 match". Not the key. Not the first few characters of the key. A prefix is enough to identify a key, and a database of key prefixes would itself be worth stealing.
- Ownership. Every scan requires you to confirm that you own the app or have written permission to check it, and that is enforced on our server, not just in the form. We don't scan other people's apps for you.
- The share page. If you share a result, the public page shows the grade and the hostname and the date. It never shows a single finding. Nobody can read your report from a link you shared.
- DNS. Before fetching, our server asks Cloudflare's public DNS resolver to resolve the hostname you gave us, over HTTPS. That's how we can refuse addresses that point at private networks before any connection is made. Cloudflare sees the hostname, the same as any DNS lookup anywhere; it does not see you.
- How long. Scan records are kept so a result link and a re-scan comparison keep working. Ask us to delete one and we will, the same as anything else — see Deletion below.
Cookies
Four, all strictly necessary, none used for tracking. sbs_access is set when you open your access link and is what keeps you signed in to the course.sbs_session is set when you sign in with an emailed code.sbs_claim is set for an hour after payment so the course opens straight away.sbs_lead remembers the address you gave the Exposure Check so checkout can fill it in for you. All four are HttpOnly and same-site. There are no advertising or analytics cookies, which is why there's no cookie banner to click away.
Who else touches your data
Four processors, each doing one job: Stripe (payments),Brevo (sending email), Supabase (the one-time sign-in codes), and Cloudflare (hosting and the database). Those four are the whole list.
What we do with it
- Send you the breakdown you asked for, and occasional course updates. Every email has an unsubscribe link that works the first time.
- Run the product: give you access to what you bought, and answer you when you write in.
- There are no advertising integrations on this site and no ad network receives anything from it — there's nothing here for one to receive.
- IP addresses are used transiently for abuse prevention (rate limiting) and are not stored with your records.
How long we keep it
Quiz and email records until you unsubscribe or ask for deletion. Purchase records for as long as tax and accounting rules require us to — that one we can't delete on request, and we'd rather say so than pretend otherwise. The event counts above carry only a per-visit id that expires when you close the tab and can't be traced back to you, so there is nothing in them we could find to delete even if you asked.
Deletion
Email [email protected] from the address in question and we'll delete everything we hold about you, usually within 72 hours. GDPR and CCPA rights are honored regardless of where you live.
If this policy changes
This page describes how SecureBySunday works today, and the date at the top says when it was last true. If the product changes in a way that changes this page, we'll update it and move that date. For a change that affects how we handle data you've already given us, we'll email you about it first rather than let you find out by re-reading a policy nobody re-reads. You can always take the unsubscribe or deletion routes above.