Legal

Privacy Policy

How The AEye handles your data. Last updated July 2026.

Who we are

The AEye (“we”, “us”) operates theaeye.co and related services — a defensive Attack Surface Management and authorized recon platform. Contact: privacy@theaeye.co or support@theaeye.co.

What we collect

Account data you provide (name, email, company, country); authentication data (password hashes, optional 2FA secrets); domain ownership claims and verification tokens; scan inputs and results for domains you authorize; tool inputs you paste (URLs, headers, IPs, hashes); usage and entitlement counters; support messages you send; basic technical logs (IP for rate limiting, timestamps, error diagnostics). We do not sell personal data.

How we use data

To create and secure your account; run authorized scans and diagnostic tools; enforce plan limits; send service email (verification, scan alerts you enable, support replies); improve reliability and security; comply with law. Scan targets and findings are used only to provide the service to you.

Legal bases (where applicable)

Contract performance (providing the service you signed up for); legitimate interests (security, fraud prevention, product improvement); consent where required (optional marketing — we do not spam); legal obligation when required.

Processors & subprocessors

We use infrastructure and email providers to operate the product (for example: cloud hosting, managed Postgres, transactional email). They process data only on our instructions under contractual safeguards. Payment processors (when enabled) receive billing data needed to charge your plan.

International transfers

Servers and processors may be located outside your country. We take reasonable steps to protect data in transit (HTTPS) and at rest with our providers’ standard controls.

Retention

Account and scan data while your account is active. After deletion or prolonged inactivity we delete or anonymize personal data within a reasonable period, unless law requires longer retention (security logs, billing records).

Security

Passwords are hashed; sessions use httpOnly cookies; email verification is required for the portal; rate limits and authorized-domain rules reduce abuse. No method is 100% secure — report issues to security@theaeye.co.

Your rights

Depending on your region you may request access, correction, export, or deletion of personal data, or object to certain processing. Email privacy@theaeye.co. We may need to verify your identity before acting.

Children

The service is not directed to children under 16. Do not create an account if you are under the age required in your jurisdiction.

Changes

We may update this policy. Material changes will be reflected by the “Last updated” date on this page. Continued use after changes constitutes acceptance where permitted by law.

Contact

privacy@theaeye.co · support@theaeye.co · https://theaeye.co/contact

See also Terms of Service and Security.