Effective September 18, 2026
Privacy Policy
This Privacy Policy describes the manner in which Ceron (“Ceron,” “we,” “us,” or “our”), as the operator of getceron.com and the Ceron Check service, collects, receives, uses, discloses, retains, and otherwise processes information relating to identifiable or reasonably identifiable persons. It applies to the public website, the free security checker, report-sharing features, AI-assisted report features, communications with us, and information handled in connection with a paid security engagement, except to the extent a separately executed agreement, statement of work, data-processing addendum, or other written instrument expressly governs the relevant processing.
Because the Site is primarily intended for organizational and professional use, certain information may be supplied by a business or by a person acting on behalf of an organization. This Policy applies to personal information contained in that material where applicable. It does not transform technical findings about a website into personal information merely because a URL, domain, response, or infrastructure identifier exists; the character of the information depends on the circumstances in which it is received and used.
1. Identity, scope, and contact
Ceron is the party responsible for the processing described in this Policy, subject to the allocation of responsibilities established in a customer’s written engagement documents. Questions, rights requests, and privacy-related correspondence may be directed to sales@useceron.com. If you contact us on behalf of another person or organization, you represent that you are authorized to do so; we may request information reasonably necessary to authenticate that authority and to prevent unauthorized disclosure.
2. Terminology used in this Policy
“Personal information” or “personal data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household, to the extent a privacy law gives the term that meaning. “Process” and “processing” include collection, access, consultation, use, disclosure, storage, alteration, combination, restriction, and deletion. “Providers” means vendors and infrastructure operators that process information for operational purposes on Ceron’s behalf or in connection with a feature you request. “Checker report” means the technical result generated from a public URL and the limited responses observed during the check.
3. Categories and sources of information
- Information supplied by you. This can include your name, email address, organization, role, messages, scheduling details, requested scope, and any other information you elect to include when corresponding with us or arranging an engagement. You are not required to provide information merely to browse the Site, but a requested feature may not function if its corresponding information is withheld.
- Checker submission and response data. When you submit a URL, we process the URL, its normalized form, redirect destinations, public response status, selected response headers, server-set cookie names and attributes after redaction, CORS observations, timing information, and the resulting findings. The checker is designed for public, unauthenticated responses. It does not intentionally authenticate to the target, execute the target’s JavaScript, or retrieve private application data.
- Report and AI feature data. If you request a share link, a redacted report and an identifier associated with that report are stored so the link can be served. If you request an AI summary or ask the report assistant a question, the relevant report context is transmitted to OpenRouter for generation of the response. The question itself is transmitted for chat. Ceron does not create a report record from chat messages, although the service provider or model provider may process submitted content under its own terms.
- Device, usage, and technical data. Hosting, security, and analytics systems may receive IP address, approximate location inferred from IP, device and browser characteristics, operating-system information, referring URL, pages requested, timestamps, error events, and ordinary request logs. Microsoft Clarity may collect interaction, session, and diagnostic information through cookies or comparable technologies.
- Information from other sources. We may receive information from scheduling providers, hosting and security providers, professional contacts, public sources, or a customer that supplies information about its personnel, systems, or authorized testing scope. We do not request that users submit secrets, authentication tokens, passwords, or unnecessary personal information to the checker.
4. Purposes and legal bases
We process information only for purposes reasonably connected with the operation of Ceron and the feature involved. Depending on the applicable jurisdiction and context, the legal basis may be performance of a requested service or contract, taking steps at your request before entering a contract, our legitimate interests, consent where required, compliance with a legal obligation, or another basis recognized by applicable law. Our legitimate interests include operating, securing, debugging, improving, and defending the Site; preventing abuse; communicating with business contacts; and establishing, exercising, or defending legal claims.
- to make the Site, checker, report-sharing, and report-assistance features available;
- to validate a submitted hostname, contact the public target URL, follow permitted redirects, and return observed evidence;
- to create and maintain requested share links, enforce expiry, and limit abusive or excessive chat use;
- to answer inquiries, schedule calls, evaluate a potential engagement, administer an engagement, and deliver agreed reports;
- to monitor availability, diagnose failures, measure product interactions, and improve reliability and security;
- to comply with subpoenas, court orders, lawful requests, tax or accounting requirements, and other legal duties; and
- to protect the rights, safety, property, and security of Ceron, its users, customers, providers, and third parties.
5. The free security checker
The checker performs a limited, read-only inspection of a public URL. It may make a small number of requests to follow redirects, inspect public response headers and server-set cookies, and observe responses to test origins. The submitted URL and technical response are processed in order to produce the result visible in your browser. Query strings can contain sensitive material, so you must remove credentials, signed URLs, tokens, personal identifiers, and other secrets before submitting a URL.
Ordinary checker results are displayed in the requesting browser and are not saved in Ceron’s application database by default. For completed checks, we keep a usage log containing only the submitted website’s origin (scheme and hostname) and the time of the check. This log does not contain URL paths, query strings, fragments, visitor IP addresses, or report contents. The target site, its CDN, DNS provider, hosting provider, network operator, and Ceron’s own infrastructure providers may retain ordinary request logs under their respective practices. A result is a point-in-time observation and may expose information that the target site itself makes publicly available. Submitting a URL does not give Ceron authority to test systems you do not control; you are responsible for having permission to initiate the request.
6. Sharing, summaries, and report chat
Report sharing is an optional action. When requested, we store a redacted representation of the report and make it retrievable through a link containing an opaque identifier. The report is scheduled to expire after 30 days, after which it is removed during routine cleanup. Anyone who obtains an active share link may be able to view the report, so you should distribute it only to intended recipients and should not place confidential material in a checker submission.
AI-assisted summaries and chat are also optional. To generate a response, Ceron sends the minimum relevant report context and, for chat, the question and recent conversation needed to answer it to OpenRouter. The response may be generated by a third-party model provider. Ceron does not use these features to make decisions about a person, does not treat the output as verified security advice, and does not intentionally submit secrets. OpenRouter and any downstream provider may apply separate terms, retention periods, and processing rules. You should review those terms before using the feature for confidential material.
To enforce the weekly chat allowance, Ceron may store a one-way hash derived from the requester’s IP address together with a time period, count, and update timestamp. This record is used for rate limiting and abuse prevention, is not intended to identify a person directly, and is removed during routine cleanup after the applicable short retention window.
7. Business inquiries, scheduling, and paid audits
If you email us, we process the address, message, attachments, and related correspondence so that we can respond and maintain a reliable record of the discussion. If you schedule through Calendly, Calendly processes the information necessary to create and administer the appointment under its own privacy notice. We may receive the scheduling details needed to prepare for the call.
A paid security audit can involve customer-provided asset inventories, test accounts, architecture information, logs, source material, findings, and other business or technical data. Before testing begins, the parties should agree in writing on scope, authorized access, methods, AI providers, permitted data, confidentiality, retention, deletion, and delivery. That written engagement controls customer data and may impose controller, processor, confidentiality, or security obligations that are more specific than this public Policy. Do not send customer secrets or production credentials through an unapproved channel.
8. Cookies, analytics, and similar technologies
The Site may use technologies that are necessary to deliver pages, maintain security, remember a requested state, or measure reliability. Microsoft Clarity is used to understand how the Site is used and may collect session interaction data through cookies or similar technologies. We do not intentionally use the checker as an advertising network or sell checker reports. Provider technologies may nevertheless create their own identifiers or logs.
Browser controls can restrict or delete cookies and comparable storage. Blocking a technology may affect a feature, security control, or measurement function. Where consent is required for a non-essential technology, the applicable consent mechanism or browser setting may be used to express a preference. We do not treat a browser signal as a universal opt-out unless applicable law requires that treatment.
9. Disclosures and recipients
We may disclose information to providers supporting hosting, security, analytics, scheduling, DNS resolution, database and storage operations, customer support, email, AI generation, professional advice, and legal compliance. A provider receives information only to the extent reasonably necessary for its function, although its independent retention and security practices may apply. We may also disclose information when required by law, to respond to a valid legal process, to prevent fraud or abuse, to protect rights and safety, or in connection with a financing, reorganization, merger, acquisition, sale of assets, or similar transaction.
We do not disclose information to make decisions based solely on automated processing that produce legal or similarly significant effects. The checker and AI assistant provide technical output and do not determine a person’s eligibility, employment, credit, insurance, housing, or access to essential services.
10. Retention and deletion criteria
Retention is determined by the purpose for which information was collected, the sensitivity and volume of the information, operational and security needs, contractual commitments, dispute and claim periods, and applicable legal requirements. The following periods describe the intended approach, not a guarantee that every provider’s independent backup or log will follow the same schedule:
- ordinary checker results: ordinarily remain in the requesting browser until the page is left or another check replaces them;
- shared redacted reports: up to 30 days, followed by deletion during routine cleanup;
- chat rate-limit records: a short operational period, with records older than 14 days removed during routine cleanup;
- contact and scheduling records: for as long as reasonably necessary to respond, administer the relationship, and document business communications;
- security and access logs: for a period appropriate to detect abuse, investigate incidents, maintain service integrity, and satisfy legal or contractual requirements; and
- paid-audit information: according to the applicable written engagement, confidentiality terms, deletion schedule, and legal hold requirements.
Deletion may be delayed when information is required to comply with law, resolve a dispute, investigate abuse, enforce an agreement, preserve evidence, or complete deletion from backup systems in the ordinary course.
11. Security and confidentiality
We use administrative, technical, and organizational measures intended to protect information against unauthorized access, alteration, disclosure, and destruction. No transmission, storage system, model provider, or internet-connected service can be guaranteed to be completely secure. Security safeguards for a paid engagement should be stated in the engagement documents, including access restrictions, approved personnel or providers, credential handling, incident escalation, and deletion responsibilities.
12. International processing
Ceron and its providers may process information in countries other than the country in which it was collected. Where a law requires a transfer mechanism, we intend to use a mechanism recognized for the relevant transfer, such as an adequacy decision, standard contractual clauses, or another permitted safeguard. Local rights and remedies may vary, and a provider’s own cross-border practices may apply to information sent to that provider.
13. Rights and how to exercise them
Depending on where you live and the role in which you interact with Ceron, you may have rights to know whether personal information is processed, access or obtain a copy, correct inaccuracies, request deletion, restrict or object to certain processing, receive portable information, withdraw consent where consent is the basis, and complain to a supervisory or privacy authority. Some rights are subject to exceptions, verification requirements, legal privileges, security needs, and other limits in applicable law.
To make a request, email sales@useceron.com with enough detail to identify the request and the relevant interaction. We may ask for additional information to verify identity or authority, and we may retain a minimal record of the request and its resolution. If a provider or customer controls the relevant information, we may direct you to that party or assist the responsible party as required by the applicable arrangement. We generally do not charge for a lawful request unless law permits a reasonable fee for repetitive, manifestly unfounded, or excessive requests.
14. Children
The Site is designed for professional and business users and is not directed to children. We do not knowingly request or intentionally collect personal information from a child in circumstances where parental consent is required. If you believe a child has provided information to us, contact us so that we can evaluate and delete it where appropriate.
15. Changes to this Policy
We may amend this Policy when our processing, providers, legal obligations, or Site features change. The revised version will display a new effective date. Where applicable law requires notice of a material change, we will provide notice by an appropriate channel before the change takes effect. Your continued use of the Site after the effective date constitutes use subject to the revised Policy only to the extent permitted by law.
This Policy is intended to describe practices, not to create rights or obligations beyond those imposed by applicable law or an executed agreement. For questions, requests, or concerns, contact sales@useceron.com.