Privacy Policy
Unlimited Coverage Cybersecurity LLC ("Scanon," "we," "us," or "our") operates the Scanon.ai website and related services (collectively, the "Service"), which use automated tools, including machine learning, to detect and redact personally identifiable information ("PII") in photos and videos submitted by users.
This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices and rights you have. By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Because the Service is purpose-built to process content that frequently contains the personal information of both you and third parties (for example, faces, license plates, identification documents, addresses, and screens visible in uploaded media), this Policy is more detailed than a typical website policy. We encourage you to read it carefully.
1. Quick Summary
We provide this summary for convenience only; the full Policy below controls.
- What we process: Account information you provide, the photos and videos you upload, the redacted output we generate, and basic usage data about how you interact with the Service.
- Why we process it: To detect and redact PII in your media, deliver the redacted output to you, secure the Service, comply with law, and improve our detection models in limited, privacy-protective ways described in Section 8.
- How long we keep uploads: Uploaded media and redacted outputs are retained only as long as needed to process and deliver your results, and are automatically deleted on the schedule described in Section 9 unless you have a paid plan that includes longer retention you have configured.
- Do we train AI on your content? We do not use the contents of your uploaded photos or videos to train third-party generative AI models. We use uploaded media to improve our own redaction models only as described in Section 8, and you can opt out.
- Do we sell or share your data? We do not "sell" personal information or "share" it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.
- Your rights: Depending on where you live, you have rights to access, correct, delete, port, opt out of certain processing, and appeal our decisions. See Sections 14 and 15.
2. Definitions
- Account means a unique account created for you to access the Service.
- Affiliate means an entity that controls, is controlled by, or is under common control with us.
- Biometric Identifier means a retina or iris scan, fingerprint, voiceprint, scan of hand or face geometry, or other unique biological characteristic used to identify an individual.
- Content means photos, videos, images, and other media you upload, submit, or otherwise provide to the Service.
- Cookies are small data files placed on your device by a website.
- Data Controller, for purposes of the GDPR and UK GDPR, refers to Scanon as the entity that determines the purposes and means of processing your Personal Data.
- GDPR means the EU General Data Protection Regulation, and UK GDPR means the equivalent in the United Kingdom.
- Personal Data or Personal Information means information that identifies, relates to, describes, references, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual.
- Redacted Output means the modified version of your Content that we return to you after redaction.
- Service Provider or Processor means any natural or legal person that processes data on our behalf.
- Usage Data means data collected automatically through your use of the Service.
- You means the individual using the Service, or the organization on whose behalf an individual uses the Service.
3. Who We Are and How to Contact Us
The data controller for the Service is:
Unlimited Coverage Cybersecurity LLC
8 The Green, STE B
Dover, DE 19901
United States
Email: info@scanon.ai
For privacy-specific questions, requests to exercise your rights, or to reach our privacy team, please email info@scanon.ai with "Privacy Request" in the subject line.
4. Information We Collect
4.1 Information You Provide Directly
- Account information: name, email address, password (stored only in hashed form), and, for paid accounts, billing contact information.
- Content you upload: photos, videos, and any associated metadata. Content may contain Personal Data about you and about other individuals, including, in some cases, faces, license plates, identification documents, addresses, financial information visible on-screen, children's images, and other sensitive information.
- Communications: information you provide when you contact support, submit feedback, respond to surveys, or otherwise communicate with us.
4.2 Information Collected Automatically
When you use the Service we automatically collect:
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language preferences, and time zone.
- Usage data: pages and features accessed, actions taken (such as files uploaded, redaction settings selected, files downloaded), timestamps, referring URLs, and error logs.
- Cookies and similar technologies: as described in Section 12.
4.3 Information from Third Parties
If you sign in using a third-party identity provider (such as Google), we receive basic profile information from that provider as authorized by your settings with them. If you pay for the Service, our payment processor provides us with transaction confirmations and limited billing metadata, but we do not receive or store your full payment card number.
4.4 Sensitive and Biometric Information
The redaction process may involve scanning your Content to detect categories of information that some jurisdictions classify as sensitive, including faces (which can constitute Biometric Identifiers), government-issued identification numbers, financial information, and information that could reveal racial or ethnic origin, religious beliefs, health, or other protected characteristics.
We use this information solely to detect and redact it, and we apply heightened safeguards described in Sections 8 and 10. We do not use facial geometry or other biometric features to identify specific individuals, to build databases of identified persons, or to authenticate users.
5. Legal Bases for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
- Performance of a contract — to provide the redaction Service you have requested, manage your Account, and deliver Redacted Output.
- Legitimate interests — to secure and improve the Service, prevent fraud and abuse, and operate our business, where those interests are not overridden by your rights.
- Consent — for optional uses such as marketing communications, certain cookies, and any processing of biometric or other special-category data where consent is the applicable basis. You may withdraw consent at any time.
- Legal obligation — to comply with applicable laws, including tax, accounting, and law-enforcement obligations.
Where we process special categories of Personal Data (including biometric data within Content), we do so on the basis of your explicit consent or another legal basis permitted under Article 9 GDPR.
6. How We Use Information
We use information for the following purposes:
- To deliver the redaction Service — receiving your Content, running detection and redaction processes, generating Redacted Output, and making the output available to you.
- To manage your Account — registration, authentication, billing, customer support, and related administration.
- To secure the Service — detecting and preventing fraud, abuse, unauthorized access, malware, and other harmful activity.
- To improve the Service — analyzing aggregate usage trends, debugging, monitoring performance, and, on a limited basis described in Section 8, improving our redaction models.
- To communicate with you — sending transactional messages (such as receipts, security alerts, and service notices) and, with your consent where required, marketing communications.
- To comply with law and enforce our agreements — responding to legal process, enforcing our Terms, and protecting our rights, property, and safety, and that of our users and the public.
- For business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the protections in Section 11.
We do not use your Content for advertising, profiling, or any purpose unrelated to providing and improving the Service.
7. Content from Third Parties Who Are Not Our Users
Your Content often contains Personal Data about individuals who are not Scanon users (for example, bystanders in a photo, drivers in dashcam footage, or people on a video call). Those individuals have not interacted with us directly.
To address this:
- We act as a Processor with respect to such third-party Personal Data, processing it under your instructions and for the purpose of redacting it.
- You represent and warrant that you have the legal right and any necessary permissions, notices, or consents to upload the Content and to instruct us to process it.
- We minimize our processing of third-party Personal Data to what is necessary to detect and redact it, retain it only as described in Section 9, and apply the security measures in Section 10.
- If a non-user contacts us about Personal Data appearing in Content uploaded to the Service, we will generally refer them to you as the controller, and may notify you, except where prohibited by law.
8. Automated Processing and Model Improvement
8.1 How Redaction Works
The Service uses automated decision-making, including machine learning models, to detect categories of PII in your Content (such as faces, license plates, text containing identifiers, and similar items) and to apply redactions. Automated detection is not perfect; you are responsible for reviewing the Redacted Output before relying on it for any purpose.
You can request human review of automated decisions that produce legal or similarly significant effects on you by contacting info@scanon.ai.
8.2 Use of Content to Improve Our Models
By default, we do not use the contents of your uploaded photos or videos to train or fine-tune our redaction models. We may use:
- Aggregated and de-identified metrics (for example, detection counts, error rates, processing times) to monitor model performance; and
- Specific files only with your opt-in consent — for example, if you flag a redaction error and choose to submit the file for model improvement, we will use it only for that purpose and apply additional safeguards (such as further minimization and access restrictions).
We do not sell your Content, share it with third parties for their own AI training, or use it to train generative AI models that produce content for other users.
9. Data Retention
We retain different categories of information for different periods:
- Uploaded Content and Redacted Output: Stored only as long as needed to process your request and make the output available for download. Unless you have configured a longer retention period as part of a paid plan, uploaded Content and Redacted Output are automatically deleted within 24 hours of processing, and in any event no later than 7 days.
- Account information: Retained for as long as your Account is active, and for a limited period after closure to comply with legal, tax, and audit obligations (typically up to 7 years for billing records).
- Usage data and logs: Retained for up to 24 months in identifiable form, after which they are aggregated or deleted.
- Support communications: Retained for up to 3 years after the matter is closed.
- Records required by law (for example, tax invoices, fraud-prevention records, and litigation holds): Retained for the period required by applicable law.
You may request deletion of your Account and associated data at any time as described in Section 14. Some information may remain in backups for a limited period before being overwritten in the ordinary course.
10. How We Protect Your Information
We implement administrative, technical, and physical safeguards designed to protect your information, including:
- Encryption in transit using TLS for all data transmitted between your device and the Service.
- Encryption at rest for stored Content and database records.
- Access controls that limit access to Personal Data and Content to personnel and Service Providers with a legitimate need, under contractual confidentiality obligations and with multi-factor authentication.
- Logging and monitoring of access to systems that handle Content.
- Segregation of Content from other systems to limit exposure.
- Vendor due diligence for Service Providers that process Personal Data on our behalf.
- Incident response procedures for detecting, investigating, and responding to security incidents, including notification to affected individuals and regulators where required by law.
No method of transmission or storage is 100% secure. While we use commercially reasonable measures, we cannot guarantee absolute security. You are responsible for keeping your Account credentials confidential and for promptly notifying us at info@scanon.ai if you suspect unauthorized access.
11. How We Share Information
We do not sell your Personal Information. We share information only as described below:
- Service Providers (Processors). We share information with third parties that perform services on our behalf, such as cloud hosting, content delivery, payment processing, email delivery, customer support, analytics, and fraud prevention. These providers are bound by contractual obligations to use the information only for the services they provide to us and to protect it appropriately. Current categories of Service Providers include, without limitation:
- Cloud infrastructure and storage (hosting and processing of Content and Service operations).
- Vercel — hosting and analytics for the website.
- Stripe — payment processing. We do not store full payment card numbers.
- Brevo — transactional and marketing email delivery.
- Customer support and ticketing tools.
- Affiliates. With entities under common control with us, subject to this Policy.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, dissolution, or sale of assets, subject to standard confidentiality protections and, where required, notice to you.
- Legal and safety. To comply with applicable law, valid legal process, or governmental requests; to enforce our Terms; to protect the rights, property, or safety of Scanon, our users, or others; and to detect, prevent, or address fraud, security, or technical issues.
- With your direction or consent. When you direct us to share information with a third party (for example, by integrating the Service with another tool you use).
We may share aggregated or de-identified information that cannot reasonably be used to identify you for any business purpose.
12. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Provide essential functionality (for example, keeping you signed in).
- Remember preferences (such as language and display settings).
- Measure performance using first-party and limited third-party analytics.
You can manage cookies through your browser settings and, where available, through our in-product cookie banner. Disabling certain cookies may affect functionality.
We honor Global Privacy Control (GPC) signals from your browser as a valid opt-out of "sale" or "sharing" of Personal Information under applicable U.S. state laws.
13. International Data Transfers
We are based in the United States, and we process Personal Data in the United States and in other countries where we or our Service Providers maintain facilities. If you are located outside the United States, your information will be transferred to and processed in countries that may have data protection laws different from your country.
For transfers of Personal Data from the EEA, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented as appropriate. You may request a copy of the relevant safeguards by contacting info@scanon.ai.
14. Your Privacy Rights
Subject to applicable law and verification of your identity, you have the following rights with respect to your Personal Data:
- Access — request confirmation of, and a copy of, the Personal Data we hold about you.
- Correction — request that we correct inaccurate or incomplete information.
- Deletion — request that we delete Personal Data, subject to legal exceptions.
- Portability — receive certain Personal Data in a portable, machine-readable format.
- Restriction or objection — restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
- Withdraw consent — where processing is based on consent, withdraw consent at any time without affecting prior lawful processing.
- Opt out of automated decisions that produce legal or similarly significant effects, and request human review.
- Lodge a complaint with a supervisory authority. EEA residents may contact their national data protection authority; UK residents may contact the Information Commissioner's Office.
To exercise these rights, email info@scanon.ai. We will respond within the timeframe required by applicable law (generally 30 days for GDPR, 45 days for U.S. state laws). We may need to verify your identity before fulfilling your request.
We will not discriminate against you for exercising your privacy rights.
15. U.S. State Privacy Rights
The following sections describe additional rights that may apply to residents of certain U.S. states.
15.1 California (CCPA / CPRA)
If you are a California resident, you have the rights described in Section 14, plus the following:
- Right to know the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it.
- Right to delete Personal Information we have collected from you, subject to exceptions.
- Right to correct inaccurate Personal Information.
- Right to opt out of "sale" or "sharing" of Personal Information. We do not sell Personal Information and do not share it for cross-context behavioral advertising.
- Right to limit use of sensitive Personal Information. We use sensitive Personal Information only for the purposes permitted under the CPRA (including providing the Service you requested) and do not use it to infer characteristics about you.
- Right to non-discrimination for exercising your rights.
Categories of Personal Information we have collected in the prior 12 months, by CCPA category:
- Identifiers (such as name, email, IP address).
- Customer records (billing information).
- Internet or other electronic network activity (usage data, device data).
- Geolocation data (approximate, derived from IP).
- Audio, electronic, visual, or similar information (your uploaded Content).
- Inferences drawn from the above (limited to Service operation and security).
- Sensitive Personal Information (account credentials; and within Content, items such as government IDs, precise geolocation, and biometric information when present).
You may exercise these rights by emailing info@scanon.ai. You may also designate an authorized agent to make a request on your behalf, subject to verification. If we deny your request, you may appeal by replying to our response.
15.2 Other U.S. States
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Hampshire, New Jersey, Kentucky, Rhode Island, Maryland, Minnesota, and other states with comprehensive privacy laws have rights similar to those described in Section 14, including the right to access, correct, delete, port their data, opt out of targeted advertising, "sales," and certain profiling, and appeal denials of their requests.
To exercise these rights, contact info@scanon.ai. If we deny your request, you may appeal by replying to our response within 60 days. If your appeal is denied, you may contact your state attorney general.
15.3 Biometric Information (Illinois, Texas, Washington, and Similar Laws)
If you are an Illinois resident, the Illinois Biometric Information Privacy Act (BIPA) may apply to certain processing performed by the Service. To the extent the Service processes Biometric Identifiers (such as scans of face geometry to detect faces for redaction):
- We do so for the limited purpose of detecting and redacting that information from your Content.
- We do not sell, lease, trade, or otherwise profit from Biometric Identifiers or Biometric Information.
- We retain Biometric Identifiers only as long as needed to perform the redaction and in no event longer than the retention periods in Section 9 (and not beyond the maximum periods required by applicable biometric privacy laws).
- We protect Biometric Identifiers using the safeguards described in Section 10 and in a manner that is the same as or more protective than the manner in which we protect other confidential and sensitive information.
By using the Service to redact Content that contains Biometric Identifiers, you provide your written consent to this processing and represent that you have obtained any required consents from third parties whose biometric information appears in your Content.
Similar protections apply where required by Texas's CUBI, Washington's biometric privacy statute, and other comparable laws.
16. Children's Privacy
The Service is not directed to children under 13 (or under 16 in the EEA and the UK), and we do not knowingly collect Personal Data from children. If you are a parent or guardian and believe your child has provided us with Personal Data, please contact info@scanon.ai and we will take steps to delete it.
Because uploaded Content may contain images of children, you represent that you have the legal authority and any required consents to upload such Content and have it processed by the Service.
17. "Do Not Track" and Global Privacy Control
Most browsers offer a "Do Not Track" (DNT) setting, but there is no industry consensus on how to respond. Our Service does not currently respond to DNT signals. We do, however, treat Global Privacy Control (GPC) signals as a valid opt-out of "sale" or "sharing" of Personal Information under U.S. state privacy laws.
18. Links to Other Websites
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party site you visit.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this Policy and, where the changes are material, provide additional notice (such as by email or an in-product banner) before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
20. Contact Us
For questions, requests, or concerns about this Privacy Policy or our privacy practices, please contact:
Unlimited Coverage Cybersecurity LLC
8 The Green, STE B
Dover, DE 19901
United States
Email: info@scanon.ai
EEA and UK residents may also contact their local supervisory authority.
