Legal

Privacy Policy

How OmniCheck collects, uses, shares and protects personal data when you visit, scan or monitor a website.

Last updated: August 3, 2026

1. Scope and who controls your data

This Privacy Policy explains how 2create, the operator of OmniCheck ("OmniCheck", "we", "us" or "our"), handles personal data when you visit the service, submit a website, receive a report, create an account or configure monitoring.

For personal data used to operate OmniCheck accounts and the service, 2create acts as the data controller. For public website content fetched at your instruction, the parties' roles may depend on why you run the scan and your relationship with the website. You are responsible for having a lawful basis and any required permission before submitting a URL.

This policy does not govern a scanned website's own privacy practices. The operator of that website remains responsible for its content and notices.

2. Personal data we collect

We collect only the information reasonably needed to provide and protect OmniCheck:

  • Account data: your name, email address, password hash, saved scan preferences and account status. We do not store your password in plain text.
  • Scan and monitoring data: submitted URLs, scan settings, discovered pages, publicly returned page content and metadata, technical measurements, issues, scores, report files, scan history, monitoring frequency and alerts.
  • Guest and report-delivery data: a one-way hash linked to the browser session used to start a guest scan, plus an email address if you ask us to continue a scan or send the result.
  • Technical data: IP address, browser and device information, session identifiers, request and error logs, timestamps, security events and service usage needed to operate and troubleshoot the application.
  • Communications: information you include when contacting us, requesting support or exercising a privacy right.

Please do not submit passwords, authentication tokens, private documents, special-category personal data or other confidential information through a URL or support request.

3. How and why we use personal data

We use personal data for the following purposes and legal bases:

  • Provide the service and perform our contract: create and secure accounts, run requested scans, generate reports, remember settings, deliver results and operate scheduled monitoring.
  • Our legitimate interests: protect the service from misuse, diagnose failures, improve reliability and usability, understand aggregate service performance, enforce our terms and establish or defend legal claims.
  • Your consent: where we specifically ask for it for an optional use. You may withdraw consent at any time without affecting earlier lawful processing.
  • Legal obligations: keep records or disclose information when applicable law validly requires it.

We do not sell personal data and do not use it for third-party behavioural advertising. OmniCheck produces automated technical scores and findings, but it does not use them to make decisions that produce legal or similarly significant effects about individuals.

4. Data found during website scans

A scan may fetch public HTML, headers, links, metadata, structured data, screenshots or rendered content from the submitted website and related pages. Some public pages may incidentally contain names, contact details or other personal data.

Only submit sites you are authorised to test. Configure the smallest practical page limit, avoid private or authenticated areas and do not use OmniCheck to collect personal data. Scan reports may be accessible to anyone who has their unguessable report link, so treat report links as confidential and share them only with intended recipients.

If you believe a report contains your personal data or content unlawfully, contact us with the report URL and enough detail to identify the material. We will review valid requests and may restrict or remove access while doing so.

5. Cookies and similar technologies

OmniCheck uses strictly necessary cookies and server-side sessions to keep the service secure and functional. These support functions such as CSRF protection, sign-in, remembering a browser session and connecting a guest scan with the person who requested it.

These technologies are not used for third-party behavioural advertising. At the date of this policy, OmniCheck does not set optional analytics or advertising cookies. Your browser settings can block cookies, but blocking necessary cookies may prevent sign-in, scan submission and other features from working.

6. When we share data

We disclose personal data only when needed for the purposes described above:

  • Service providers: hosting, storage, database, security, email delivery and technical support providers that process information under contract.
  • Scan providers: submitted page URLs and related technical data may be sent to Google PageSpeed Insights or an infrastructure provider running Lighthouse so that we can produce performance measurements.
  • Web font delivery: the site loads fonts from Google Fonts, which means your browser connects to Google and shares standard request information such as your IP address and user agent.
  • Legal and safety disclosures: authorities, advisers or affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse or handle a corporate transaction.

Some providers may process data outside the European Economic Area. Where required, we use an applicable adequacy decision, standard contractual clauses or another lawful transfer safeguard. You may contact us for more information about relevant safeguards.

7. How long we keep data

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the service, maintaining security, resolving disputes and meeting legal obligations.

  • Account information is generally kept while the account remains active and for a limited period afterwards where needed for legal, security or operational reasons.
  • Generated HTML, CSV and PDF report files are normally removed after 30 days. Scan records, summaries, JSON data and monitoring history may be retained longer so that results and trends remain available.
  • Guest-session identifiers expire with the underlying session lifecycle. Operational logs and backups are kept on limited, rotating schedules appropriate to their purpose.
  • Information connected to a dispute, abuse investigation or legal obligation may be kept until that matter is resolved.

You may ask us to delete eligible account or report data. Some information may remain in backups until normal rotation completes or be retained where the law permits or requires it.

8. How we protect data

We use administrative, technical and organisational safeguards designed to protect personal data, including access controls, password hashing, transport encryption, network restrictions, audit logging, rate limits and service monitoring where appropriate.

No internet service can guarantee absolute security. Use a unique password, protect report links and notify us promptly if you suspect unauthorised access.

9. Your privacy rights

Depending on where you live and the circumstances, you may have the right to:

  • be informed about how your personal data is used;
  • request access to or a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests or to direct marketing; and
  • withdraw consent where processing relies on consent.

To exercise a right, email us using the details below. We may need to verify your identity and clarify the request. Rights can be subject to legal exceptions, including where information must be retained to protect another person's rights or comply with law.

You may also complain to your local data protection authority. In Bulgaria, the supervisory authority is the Commission for Personal Data Protection. We would appreciate the opportunity to address your concern first.

10. Children's privacy

OmniCheck is intended for adults and organisations, not children. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us so we can investigate and delete it where appropriate.

11. Changes to this policy

We may update this policy when the service, our providers or the law changes. The current version will always be posted here with a revised "Last updated" date. We will provide additional notice when a change materially affects registered users or where law requires it.

Use of OmniCheck is also governed by our Terms of Service.

12. Contact us

For privacy questions, rights requests or concerns, email [email protected].

2create
Western Industrial Area, Neptun 8
9000 Varna, Bulgaria