geneav

Privacy Policy

This policy explains what data geneav collects when you use the website and API, why we collect it, and the choices you have. We keep it short and specific.

Last updated: July 26, 2026

Information we collect

When you create an account we store your email address, a BCrypt hash of your password (never the password itself), and your plan. When you create an API key we store only a one-way hash of it plus a short prefix and the last four characters so you can recognise it — the full key is shown once, at creation, and cannot be recovered afterwards. We also record usage metrics (such as your monthly scan count) to enforce plan quotas.

If you arrive from a link or a campaign URL, we store where that visit came from — the referring website and any utm_* parameters in the address — against your account when you sign up. It tells us which articles and links are worth writing more of. It is recorded once, at signup, and is never used to build a profile of you or shared with anyone.

The documents you scan

Files you submit for scanning are streamed straight to the detection engine and are not written to disk or retained once the scan completes. We do not keep a copy of your file contents. For operational and diagnostic purposes our server logs record only the file extension and size alongside the verdict — not the file, and not its name, since filenames themselves often contain personal information.

Cookies & sessions

When you sign in we set a single HttpOnly, SameSite=Lax session cookie so the browser can prove who you are on later requests. It is not readable by JavaScript and is used only to keep you signed in. We do not use advertising or third-party tracking cookies.

Your browser also keeps the referral information described above in sessionStorage until you sign up or close the tab. It is not a cookie, it is never sent to anyone but us, and it is discarded with the tab.

Website analytics

We count page views using Umami, which we run ourselves on our own server — no analytics provider receives your data, because there is no analytics provider. It is cookieless and does not track you across websites: it records the page, the referring site, and coarse details like country, browser and device type, with no identifier that persists between visits. We also count a handful of actions in the same way — that a scan was run, that an account was created — never who did them.

This is why you have not been shown a cookie consent banner. There is nothing to consent to, and we would rather keep it that way than gain a little more detail.

Third-party services

geneav relies on a small number of providers to run the service:

  • ClamAV — the open-source engine that performs the malware detection. See our legal & attribution page for details.
  • Hostinger — sends transactional email such as signup acknowledgements and password-reset links. Your email address is shared with Hostinger for this purpose.
  • OpenAI — powers the optional chat assistant. Messages you send to the assistant are forwarded to OpenAI to generate a reply. Do not paste sensitive data into the chat.
  • Microsoft — paid plans are sold through the Azure Marketplace, where Microsoft is the merchant of record and processes your billing details; we receive subscription details (plan, status, purchaser email) but never your payment method. If you sign in with Microsoft, we receive your name, email address, and directory identifiers from Microsoft Entra ID.

Data retention

We keep your account data, API keys, and usage records for as long as your account is active. Password-reset links are short-lived and expire automatically. Scanned file contents are not retained at all. When you close your account we delete your account data; because the database is backed up nightly and those backups are kept for 14 days, a copy of your record can persist in a backup for up to that long before it ages out.

Your rights & choices

You can revoke any API key from your dashboard at any time, and you can request access to, correction of, or deletion of your account data by emailing us. We will respond to legitimate requests within a reasonable time.

Changes to this policy

We may update this policy as the service evolves. When we do, we'll revise the “last updated” date above. Material changes will be communicated through the website.

Contact

Questions about your privacy or this policy? Email admin@geneav.com.