Legal

Privacy Policy

How OmniCheck collects, uses, shares and protects personal data when you visit, scan or monitor a website.

Last updated: August 28, 2026

1. Scope and who controls your data

This Privacy Policy explains how 2create, the operator of OmniCheck ("OmniCheck", "we", "us" or "our"), handles personal data when you visit the service, submit a website, receive a report, create an account or configure monitoring.

For personal data used to operate OmniCheck accounts and the service, 2create acts as the data controller. For public website content fetched at your instruction, the parties' roles may depend on why you run the scan and your relationship with the website. You are responsible for having a lawful basis and any required permission before submitting a URL.

This policy does not govern a scanned website's own privacy practices. The operator of that website remains responsible for its content and notices.

2. Personal data we collect

We collect only the information reasonably needed to provide and protect OmniCheck:

  • Account data: your name, email address, password hash or Google account identifier, saved scan preferences and account status. We do not store your password in plain text or retain Google access tokens.
  • Scan and monitoring data: submitted URLs, scan settings, discovered pages, publicly returned page content and metadata, technical measurements, issues, scores, report files, scan history, monitoring frequency and alerts.
  • Guest and report-delivery data: a one-way hash linked to the browser session used to start a guest scan, plus an email address if you ask us to continue a scan or send the result.
  • Technical data: IP address, browser and device information, session identifiers, request and error logs, timestamps, security events and service usage needed to operate and troubleshoot the application.
  • Communications: information you include when contacting us, requesting support or exercising a privacy right.

Please do not submit passwords, authentication tokens, private documents, special-category personal data or other confidential information through a URL or support request.

3. How and why we use personal data

We use personal data for the following purposes and legal bases:

  • Provide the service and perform our contract: create and secure accounts, run requested scans, generate reports, remember settings, deliver results and operate scheduled monitoring.
  • Our legitimate interests: protect the service from misuse, diagnose failures, improve reliability and usability, understand aggregate service performance, enforce our terms and establish or defend legal claims.
  • Your consent: where we specifically ask for it for an optional use. You may withdraw consent at any time without affecting earlier lawful processing.
  • Legal obligations: keep records or disclose information when applicable law validly requires it.

We do not sell personal data. If you allow optional technologies, we use Google Analytics to understand visits and aggregate usage, and limited Meta event data to measure and improve advertising, including visits to selected public pages and successful scan starts. OmniCheck produces automated technical scores and findings, but it does not use them to make decisions that produce legal or similarly significant effects about individuals.

4. Data found during website scans

A scan may fetch public HTML, response headers, TLS observations, links, metadata, structured data, screenshots or rendered content from the submitted website and related pages. Security scans may compare high-confidence public software fingerprints with vulnerability intelligence; OmniCheck does not send customer page bodies or component inventories to that intelligence feed. Some public pages may incidentally contain names, contact details or other personal data.

The optional live threat-reputation check is separate from the retained security report. After showing a notice and receiving your explicit confirmation, OmniCheck sends the complete target URL, including its path and query string, to Google Web Risk. Opening the confirmation link alone does not send the URL to Google, and the provider verdict is not stored in report files or the scan summary.

Only submit sites you are authorised to test. Configure the smallest practical page limit, avoid private or authenticated areas and do not use OmniCheck to collect personal data. Scan reports may be accessible to anyone who has their unguessable report link, so treat report links as confidential and share them only with intended recipients.

If you believe a report contains your personal data or content unlawfully, contact us with the report URL and enough detail to identify the material. We will review valid requests and may restrict or remove access while doing so.

5. Cookies and similar technologies

OmniCheck uses strictly necessary cookies and server-side sessions to keep the service secure and functional. These support functions such as CSRF protection, sign-in, remembering a browser session and connecting a guest scan with the person who requested it.

With your permission, we use Google Analytics 4 on selected public OmniCheck pages to understand visitor numbers and how people use the site, including when a scanner is started. Google may receive the public OmniCheck page URL, event time, scanner category, approximate location derived from your IP address, and browser and device information. Google Analytics may set _ga cookies to distinguish visits. We disable Google Signals and advertising-personalisation signals, and we do not send the website URL you submit, private report URLs or report contents.

With your permission, we use the Meta Pixel in your browser together with the server-side Meta Conversions API for advertising measurement and optimisation. Meta may receive the selected public OmniCheck page URL, event time, IP address, browser user agent and Meta browser identifiers stored in the _fbp and _fbc cookies. A scan-start event also includes only the scanner category, such as accessibility or full-site check. Browser and server copies use the same event identifier so Meta can recognise them as one event. We do not send Meta the website URL you submit, your report URL or report contents.

Google Analytics and Meta events are not sent, and their browser scripts are not loaded, unless you choose “Allow optional”. You can reject optional technologies just as easily, and you can change or withdraw your choice at any time through “Cookie settings” in the site footer. Withdrawing consent stops future tracking, updates Google and Meta consent, and removes their browser cookies available to OmniCheck. Blocking necessary cookies may prevent sign-in, scan submission and other features from working.

6. When we share data

We disclose personal data only when needed for the purposes described above:

  • Service providers: hosting, storage, database, security, email delivery and technical support providers that process information under contract.
  • Google authentication: if you choose Google sign-in, Google confirms your account identifier, name and verified email address so we can create or access your OmniCheck account. We do not retain Google's access or refresh token.
  • Scan providers: submitted page URLs and related technical data may be sent to Google PageSpeed Insights or an infrastructure provider running Lighthouse so that we can produce performance measurements.
  • Optional threat-reputation provider: when you explicitly confirm a live threat check, the complete target URL is sent to Google Web Risk to check current Google threat-list status. OmniCheck does not cache or retain the provider verdict.
  • Web font delivery: the site loads fonts from Google Fonts, which means your browser connects to Google and shares standard request information such as your IP address and user agent.
  • Usage analytics: if you consent, limited visit and usage data from selected public pages is shared with Google Analytics so we can understand aggregate site traffic and behaviour.
  • Advertising measurement: if you consent, limited page-visit and scan-start event data is shared with Meta Platforms through the Meta Pixel and server-side Conversions API for advertising measurement and optimisation.
  • Legal and safety disclosures: authorities, advisers or affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse or handle a corporate transaction.

Some providers may process data outside the European Economic Area. Where required, we use an applicable adequacy decision, standard contractual clauses or another lawful transfer safeguard. You may contact us for more information about relevant safeguards.

7. How long we keep data

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the service, maintaining security, resolving disputes and meeting legal obligations.

  • Account information is generally kept while the account remains active and for a limited period afterwards where needed for legal, security or operational reasons.
  • Generated HTML, CSV, JSON and PDF report files, including detailed findings and bounded evidence, are normally removed after 30 days. Raw page responses and unrestricted provider payloads are not stored in reports.
  • Completed scan history is retained for up to 365 days so results and monitoring trends remain available. After that period, and after report files have been removed, we remove the submitted URL, account and monitoring links, request settings, identifiers, detailed summaries and failure details from the scan record. A non-identifying operational row containing the scan type, status and timing may remain for aggregate capacity analysis.
  • Application-security telemetry uses an eight-day rolling period. The private WordPress vulnerability-intelligence file is one rolling copy rather than a customer-data archive: it is replaced when refreshed, is not used after 48 hours without a successful refresh and is removed after seven stale days.
  • Guest-session identifiers expire with the underlying session lifecycle. Hashed scan-admission identifiers are removed with expired scan history. Operational logs and backups are kept on limited, rotating schedules appropriate to their purpose.
  • Information connected to a dispute, abuse investigation or legal obligation may be kept until that matter is resolved.

You may ask us to delete eligible account or report data. Some information may remain in backups until normal rotation completes or be retained where the law permits or requires it.

8. How we protect data

We use administrative, technical and organisational safeguards designed to protect personal data, including access controls, password hashing, transport encryption, network restrictions, audit logging, rate limits and service monitoring where appropriate.

No internet service can guarantee absolute security. Use a unique password, protect report links and notify us promptly if you suspect unauthorised access.

9. Your privacy rights

Depending on where you live and the circumstances, you may have the right to:

  • be informed about how your personal data is used;
  • request access to or a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests or to direct marketing; and
  • withdraw consent where processing relies on consent.

To exercise a right, email us using the details below. We may need to verify your identity and clarify the request. Rights can be subject to legal exceptions, including where information must be retained to protect another person's rights or comply with law.

You may also complain to your local data protection authority. In Bulgaria, the supervisory authority is the Commission for Personal Data Protection. We would appreciate the opportunity to address your concern first.

10. Children's privacy

OmniCheck is intended for adults and organisations, not children. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us so we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy when the service, our providers or the law changes. The current version will always be posted here with a revised "Last updated" date. We will provide additional notice when a change materially affects registered users or where law requires it.

Use of OmniCheck is also governed by our Terms of Service.

12. Contact us

For privacy questions, rights requests or concerns, email [email protected].

2create
Western Industrial Area, Neptun 8
9000 Varna, Bulgaria