1. Introduction
Byte Optimizer LLC ("Byte Optimizer," "Company," "we," "our," or "us"), a Wyoming limited liability company, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you access or use:
- The Byte Optimizer website at byteoptimizer.com (the "Website");
- The Byte Optimizer client portal at portal.byteoptimizer.com (the "Portal");
- The OnScanner web vulnerability, security and privacy scanning platform at onscanner.com, covering unauthenticated and authenticated scans ("OnScanner");
- All professional cybersecurity services, including manual penetration testing and compliance consulting (the "Professional Services"); and
- Any other services, applications, or platforms operated by Byte Optimizer (collectively with the above, the "Services").
OnScanner product policy. OnScanner also has a product-level Privacy Policy published at onscanner.com/privacy-policy. Where the two documents address the OnScanner product, the product-level policy controls; this Policy continues to govern everything else, including the Website, the Portal, and the Professional Services.
By accessing or using any of the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Services.
This Privacy Policy should be read together with our Terms of Service. Capitalized terms not defined herein have the meanings given to them in the Terms of Service.
2. Information We Collect
2.1 Information You Provide to Us
- Account Information: When you create an Account on the Portal or OnScanner, we collect your name, email address, company name, job title, phone number, and login credentials.
- Payment Information: When you purchase Services, our third-party payment processor (Stripe) collects your payment card details, billing address, and related financial information. Byte Optimizer does not directly store full credit card numbers on our servers.
- Contact Form Submissions: When you use our contact form, subscribe to our newsletter, or otherwise communicate with us, we collect your name, email address, and the content of your message.
- Service Engagement Data: For Professional Services, we may collect information related to your engagement, including Statements of Work, authorization letters, system documentation, network diagrams, and other materials you provide for security assessments.
- Support Communications: Records of your interactions with our support team, including emails, chat logs, and any files shared during support sessions.
2.2 Information Collected Through the Services
- Scan Data (OnScanner): When you use OnScanner, we process information about the Targets you scan, including domain names, IP addresses, scan configurations, scan results, vulnerability findings, and remediation status. If you configure an authenticated scan, we also process the login credentials, session tokens, or API keys you supply so the scanner can access your Target; these are used solely to perform the scan you requested.
- Portal Usage Data: Information about your interactions with the Portal, including services ordered, project status, invoices, and communications with our team.
- Assessment Data (Professional Services): During penetration testing and security assessments, our testers may encounter and document sensitive information about your systems, including vulnerabilities, configurations, access credentials provided for testing, and network architecture. This data is treated as Confidential Information per our Terms of Service.
2.3 Information Collected Automatically
- Device & Browser Information: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage Data: Pages visited, time spent on pages, click patterns, referring URLs, and other interaction data.
- Log Data: Server logs that record requests made to our servers, including timestamps, HTTP methods, response codes, and user agent strings.
- Cookies & Similar Technologies: See Section 5 (Cookies & Tracking Technologies) for details.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing Services: To create and manage your Account, deliver the Services you have requested, process transactions, generate reports, and provide customer support.
- Security & Abuse Prevention: To verify Target authorization, detect and prevent unauthorized scanning activity, protect our infrastructure, investigate potential violations of our Terms of Service, and cooperate with law enforcement when required.
- Communication: To send you service-related communications (e.g., order confirmations, scan completion notifications, engagement updates), respond to your inquiries, and provide technical support.
- Marketing: To send you promotional communications about our Services, events, or industry updates, where you have opted in or where permitted by applicable law. You may opt out of marketing communications at any time (see Section 10).
- AI & Automated Reasoning: To power optional, opt-in AI features (AI Findings and AI compliance analysis) as described in Section 4.
- Improvement & Analytics: To analyze usage patterns, improve our Services, develop new features, and conduct internal research using aggregated and anonymized data.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
- Contractual Obligations: To fulfill our obligations under Statements of Work, service agreements, and these Terms.
4. AI & Automated Reasoning
OnScanner's optional AI features (AI Findings and AI compliance analysis) are off by default and opt-in per scan. The scan itself never uses an LLM: the scanning engines are deterministic, and if you do not enable an AI feature, no scan data is sent to any AI provider. This section explains how the AI features interact with your data when you turn them on.
4.1 What the AI Features Process
When you enable an AI feature for a scan, the following data may be processed:
- Scan findings, vulnerability descriptions, and severity context produced by OnScanner;
- Target metadata such as domain name, response headers, and detected technology fingerprints;
- Scan summary data (severity counts and key indicators) produced by OnScanner.
4.2 What Is Never Sent for AI Processing
The following data is excluded from AI / LLM processing under all circumstances:
- Payment card information and billing data;
- Login credentials supplied for authenticated scanning;
- Raw screenshots, video, or image-based renderings of your interfaces;
- Confidential Information disclosed during Professional Services engagements (penetration test artifacts, internal documents, source code, network diagrams).
4.3 Third-Party AI Providers
If you enable an AI feature for a scan, the data described in Section 4.1 is sent to a third-party AI provider (such as Anthropic, OpenAI, or Google) to generate the analysis. We use these providers under agreements that prohibit using your data to train their models, and we do not enable training on your data. If you do not enable an AI feature, no scan data is sent to any AI provider. The set of providers we use may change; this section will be updated if the nature of this processing materially changes.
4.4 No Training on Your Data Without Consent
Customer data including scan findings, Targets, Client Data, and Confidential Information is not used to train, fine-tune, or otherwise improve any model that would be deployed to other customers without your explicit, opt-in consent. Third-party AI providers process your data under no-training terms as described in Section 4.3. We may use aggregated, anonymized signals (for example, counts of finding categories or detection-rule outcomes) internally to improve detection logic, where such use cannot reasonably be linked back to you, your Account, or your Targets.
4.5 Outputs Are Advisory Only
AI outputs are advisory and may contain hallucinations, fabrications, or factual errors. You are responsible for independently verifying any AI-suggested finding, classification, or remediation before acting on it. Byte Optimizer is not liable for decisions or actions taken on the basis of AI output. See Section 7 of the Terms of Service (Disclaimers & Limitation of Liability) and Schedule A.4 of the Terms for additional caveats.
4.6 Opt-In & Opt-Out
AI features are off by default: you opt in per scan when you want them. To opt out of AI features entirely, simply leave them disabled, or email support@byteoptimizer.com from your Account email with the subject line "AI Opt-Out" to disable them for your Account. Opting out does not affect your underlying OnScanner Subscription.
4.7 Retention of AI Inputs & Outputs
Prompts sent for AI processing and the resulting outputs are retained on Byte Optimizer's systems for the same period as the underlying scan results (see Section 8 - Data Retention).
5. Cookies & Tracking Technologies
We use cookies and similar tracking technologies to collect information about your interactions with our Website and Services.
5.1 Types of Cookies We Use
| Category | Purpose | Examples |
|---|---|---|
| Essential | Required for the Website and Services to function (e.g., session management, authentication, CSRF protection) | Session cookies, CSRF tokens |
| Functional | Remember your preferences and settings (e.g., language, theme) | Preference cookies |
| Analytics | Help us understand how visitors use the Website so we can improve it | Google Analytics |
| Marketing | Used to deliver relevant advertisements and track campaign effectiveness | Meta, LinkedIn, Reddit, Google |
5.2 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to block or delete cookies. However, if you block essential cookies, some features of the Website and Services may not function properly.
For more information about cookies and how to manage them, visit allaboutcookies.org.
6. Data Sharing & Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
6.1 Service Providers
We share information with trusted third-party service providers who assist us in operating the Services, including:
- Payment Processing: Stripe processes payment transactions on our behalf. Their use of your information is governed by the Stripe Privacy Policy.
- Cloud Infrastructure: AWS, DigitalOcean, Cloudflare, Hetzner, etc. hosts our servers and data.
- Email Services: SendGrid, Mailgun, etc. delivers transactional and marketing emails.
- Analytics: Google Analytics, Plausible, Self-hosted analytics helps us understand Website usage.
All service providers are contractually obligated to use your information only for the purposes of providing services to Byte Optimizer and to maintain appropriate security measures.
AI providers (opt-in only). We share scan findings and Target metadata with a third-party AI provider (such as Anthropic, OpenAI, or Google) only when you opt in to an AI feature for a scan, under agreements that prohibit training on your data. If you do not enable an AI feature, no scan data is shared with any AI provider. See Section 4 for details.
6.2 Legal Compliance & Safety
We may disclose your information if we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request;
- Enforce our Terms of Service, including investigation of potential violations;
- Detect, prevent, or address fraud, security issues, or technical problems;
- Protect the rights, property, or safety of Byte Optimizer, our users, or the public.
6.3 Unauthorized Scanning & Abuse
Important: If we detect or reasonably suspect that our Services are being used to conduct unauthorized scanning, testing, or attacks against systems for which you do not have proper authorization, we may disclose your identity, Account information, and activity logs to:
- Law enforcement authorities;
- The owners or operators of the affected systems;
- Relevant regulatory bodies or CERTs (Computer Emergency Response Teams).
This disclosure may occur without prior notice to you and is necessary to prevent harm and comply with our legal obligations.
6.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Website of any change in ownership or use of your information.
6.5 With Your Consent
We may share your information for other purposes with your explicit consent.
7. Data Security
We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (TLS 1.3 preferred).
- Encryption at Rest: Sensitive data stored on our servers is encrypted using AES-256 encryption.
- Access Controls: Role-based access controls limit employee access to your data to only those who require it to perform their job functions.
- Infrastructure Security: Our systems are hosted in SOC 2 compliant data centers with physical security controls, intrusion detection systems, and regular security monitoring.
- Security Testing: We regularly assess the security of our own systems through internal testing and review.
- Employee Training: Our team receives regular training on data protection, security best practices, and incident response procedures.
While we strive to protect your information, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods include:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of your Account, plus 1 year after Account closure |
| Payment & Billing Records | 7 years for tax and legal compliance |
| OnScanner Scan Results | 12 months from scan date, or duration of Subscription plus 90 days |
| AI Prompts & Outputs | Same retention as the underlying scan |
| Penetration Test Reports | 3 years from delivery date |
| Support Communications | 2 years from resolution |
| Website Analytics Data | 26 months |
| Server Logs | 90 days |
Upon expiration of the retention period, your information will be securely deleted or anonymized. You may request earlier deletion of your data subject to the provisions in Section 10.
9. International Data Transfers
Byte Optimizer is based in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.
For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Your explicit consent where applicable; and/or
- Other legally recognized transfer mechanisms.
By using the Services, you consent to the transfer of your information to the United States and other countries where Byte Optimizer or its service providers operate.
10. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information. Byte Optimizer honors the following rights for all users, regardless of location, to the extent technically feasible and not in conflict with our legal obligations:
10.1 Rights for All Users
- Access: You may request a copy of the personal information we hold about you.
- Correction: You may request that we correct inaccurate or incomplete personal information.
- Deletion: You may request that we delete your personal information, subject to certain exceptions (e.g., legal obligations, dispute resolution, abuse prevention).
- Opt-Out of Marketing: You may opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at support@byteoptimizer.com.
- Opt-Out of AI Processing: AI features are off by default and opt-in per scan; you may also disable them for your Account entirely (see Section 4.6).
- Data Export: You may request a copy of your data in a commonly used, machine-readable format.
10.2 Additional Rights for EEA, UK & Swiss Residents (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws, including:
- Right to Restrict Processing: You may request that we restrict the processing of your personal information in certain circumstances.
- Right to Object: You may object to the processing of your personal information based on our legitimate interests.
- Right to Withdraw Consent: Where we process your data based on consent, you may withdraw that consent at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority.
Our legal bases for processing your personal data include: performance of a contract (providing the Services), legitimate interests (security, fraud prevention, service improvement), consent (marketing communications), and legal obligations.
10.3 Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting the information, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
To exercise your California privacy rights, contact us at support@byteoptimizer.com
.10.4 How to Exercise Your Rights
To exercise any of the above rights, please contact us at support@byteoptimizer.com. We will respond to your request within thirty (30) days (or within the timeframe required by applicable law). We may ask you to verify your identity before processing your request.
11. Children's Privacy
The Services are not intended for individuals under the age of eighteen (18). We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to promptly delete that information. If you believe that a child under 18 has provided us with personal information, please contact us at support@byteoptimizer.com.
12. Third-Party Links
The Website and Services may contain links to third-party websites, services, or applications that are not operated or controlled by Byte Optimizer. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through our Website. Byte Optimizer is not responsible for the privacy practices or content of third-party websites.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page;
- Post the revised policy on the Website; and
- For active Account holders, send an email notification at least thirty (30) days before the changes take effect.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy Inquiries: support@byteoptimizer.com
- Data Protection Officer: Shaid Hasan Shawon, reachable at shawon@byteoptimizer.com
- Mailing Address: Byte Optimizer LLC, 30 N Gould St, Sheridan, Wyoming 82801, US
- General Inquiries: info@byteoptimizer.com