Skarn privacy policy

This policy covers the details you give when you register for a free license, purchase a paid subscription, use the customer portal at account.getskarn.com, or email or call us. The Skarn scanner itself is not covered because it collects nothing: it runs on your own machines, reads the session logs already on disk, and makes no network call when it scans. By design, nothing you scan, and no finding it produces, ever reaches us.

Last updated 2026-09-29.

Who we are

Skarn Software OÜ, registry code 17585335, Narva mnt 5, 10117 Tallinn, Estonia, the maker of Skarn, is the controller of the data described here, except the team member records described in the next section, which we process for the customer. Contact us about privacy at hello@getskarn.com.

Team member data and processor role

When you hold a Team or Enterprise license, your administrators use the portal to invite your team members and assign them licenses and seats. For these team member records the customer is the controller, and Skarn acts as a data processor on the customer's instructions. For the registration, account and billing data of the person who opens the account and of the purchaser, Skarn is the controller.

If you are a team member and want a record about you corrected or erased, ask the administrator of your organization's Skarn account. A request that reaches us directly is passed to that administrator.

The scanner sends nothing

Skarn is a local scanner. When it runs, no session content, no findings, no file paths, no secrets, and no telemetry leave the machine; at scan time the binary makes no network call at all. The license is an Ed25519-signed file verified offline against a key embedded in the binary, so running Skarn is not a data transfer to us. This policy covers the website registration and purchase processes, the customer portal, the messages you send us, marketing email, and our website analytics.

What we collect when you register, purchase or contact us

To issue a Free License, the registration form at getskarn.com/free/ collects:

  • the company or team name you enter;
  • the work email address you enter;
  • the number of developers you enter;
  • the campaign parameters in the link that brought you to the form, if any;
  • the IP address the request arrives from, which the registration record keeps only as a keyed hash;
  • the Cloudflare Turnstile token your browser submits with the form, which we verify and do not store.

The page that the link in the confirmation email opens collects:

  • whether you ticked the optional marketing-consent box;
  • the version of the license terms you accepted.

To purchase a Pro or Team subscription, you buy from Paddle, our merchant of record. Paddle sells the license in its own name and independently manages payment, billing and tax compliance, so for billing and transaction data it is an independent controller under its own privacy policy. At checkout Paddle collects:

  • your full name and work email address;
  • your company name, registered business address, and VAT identification number;
  • your payment details (processed securely by Paddle; we never see or store your full credit card or bank details);
  • the IP address and country location to verify tax and VAT compliance.

Paddle then passes to us what we need to issue and manage the license: your name and work email address, a Paddle customer reference, the order, subscription, invoice and payment references and amounts, and limited card details such as the last four digits. A Team license above the checkout's seat limit or bought on a purchase order, and every Enterprise license, is contracted and invoiced by us directly; we then collect the details on the order and the invoice: the name and work email address of your representative, your company name and billing details, and any purchase order number.

When you email us or call our support number, we receive your email address or phone number and whatever you send, including any file you attach. Every call goes to voicemail, and we receive the recording and the caller's number by email. We record the people we talk to about a purchase, and the emails we exchange with them, in our customer relationship system.

We do not build a profile of you beyond the records this policy describes.

What the customer portal holds

A Team or Enterprise account on account.getskarn.com holds:

  • the organization name and, for each member, the work email address and role your administrators enter, the name the member enters when accepting the invitation, which the member or an administrator can change later, and the member's status;
  • invitations (the invited address, the role, and who sent the invitation) and seat assignments;
  • the domains your organization has verified, and the email addresses of people who asked to join through a verified domain;
  • order, contract, invoice and payment references and amounts;
  • an append-only audit log of licensing actions, which records who did what and when, the IP address of each portal sign-in and invitation acceptance, and the IP address and browser of each license download or token reveal;
  • for each active sign-in session, the IP address and browser identifier.

Your administrators can view and export your organization's audit log.

If you register for a free license, or ask to join, with an address on a domain an organization has verified, we route your request to that organization instead of issuing an individual license. Depending on the organization's settings, we send you an invitation automatically, which is the default, or queue your request for its administrators; either way the organization receives your email address. An Enterprise organization that has verified a domain can also see and export which addresses on that domain already hold a personal Skarn account, with the name on the account, its status and whether an invitation was sent, and can send those addresses an invitation to join.

Why we collect it, and the lawful basis

For Free Licenses, we use the company name, email address, and developer count to issue the license and to support it. The lawful basis is the performance of the license agreement you enter when you register (GDPR Article 6(1)(b)). Without the company name and email address we cannot issue the license.

For Paid Licenses, we use your purchase details, email, and company information to generate your commercial License Token, deliver the Software, provide customer support, and manage your billing. The lawful basis is the performance of our contract with you (GDPR Article 6(1)(b)) and compliance with our legal, accounting, and tax obligations (GDPR Article 6(1)(c)). You must provide these details to buy a license; without them we cannot issue it.

We use the request IP address and the Turnstile token to confirm the request is genuine and to prevent abuse of our endpoints, and we record portal sign-in sessions and the audit log to keep the portal secure and to give each customer a record of its licensing actions. The lawful basis is our legitimate interest in keeping our endpoints and the portal secure (GDPR Article 6(1)(f)).

We route requests from a verified domain to its organization, and show an Enterprise organization the personal accounts on its verified domain, so that the organization can manage the Skarn licenses used under its name. The lawful basis is that legitimate interest (GDPR Article 6(1)(f)).

When you email us or leave a voicemail, we use your details and what you send to answer you and to keep a record of our conversation. The lawful basis is taking steps at your request before entering into a contract (GDPR Article 6(1)(b)) or, where your message is not directed at a contract, our legitimate interest in answering enquiries and supporting our customers (GDPR Article 6(1)(f)).

For team member records, the customer as controller determines the lawful basis.

Marketing email is separate and optional

The page that the link in the confirmation email opens and the purchase form may carry an unticked checkbox that opts you into occasional email from Skarn: new detection coverage, releases, and security research. It is not a condition of license issuance. We record your choice only so we can honor it. The lawful basis for that email is your explicit consent in accordance with GDPR Article 6(1)(a) and Article 13 of the ePrivacy Directive 2002/58/EC. You can withdraw it at any time, independently of your license, using the unsubscribe link in every marketing email we send or by emailing hello@getskarn.com. Withdrawing consent does not affect the lawfulness of the email we sent before, and does not affect your license.

Website analytics without cookies

We measure use of getskarn.com with Matomo, an analytics platform we host ourselves on a server rented from Hetzner Online GmbH in Nuremberg, Germany; your visit data is not sent to any third-party analytics service. The measurement is cookieless, IP-anonymized audience measurement: it sets no cookies, uses no cross-site identifiers, is designed to store no name, email address, or account identifier, and the last two bytes of your IP address are discarded before anything is stored. If your browser sends the Do Not Track signal, no analytics beacon is sent at all.

We use these statistics for two purposes: to understand which pages and channels lead people to install Skarn and register licenses, and to detect errors on our own pages (the tracker reports JavaScript errors and content-security violations, with no page content attached). The lawful basis is our legitimate interest in measuring and improving our own website (GDPR Article 6(1)(f)).

Raw visitor logs are automatically deleted after 180 days, and backup copies age out within a further month. Aggregated statistics, such as monthly page-view counts, are retained; they contain no personal data.

How long we keep it

We do not retain your data longer than necessary for the purposes for which it was collected:

  • A free license registration you do not confirm expires after 30 minutes and is deleted by the next scheduled cleanup.
  • We keep your free license registration details (company name, email, developer count) for the active duration of your free license and for up to 2 years after the license expires or is deactivated, in order to facilitate renewals and handle related support inquiries.
  • We keep billing, invoice, and transactional data related to Paid Licenses for 7 years from the end of the financial year in which the transaction was recorded, or, for a multi-year contract, from the end of the contract, as Estonian accounting and tax law requires.
  • Our nightly cleanup clears the keyed hash of a registration's IP address once it is 30 days old, unless we need it longer to investigate a specific security incident. The same cleanup deletes rate-limit records, which can contain an IP address or an email address, once they are a day old, and portal sign-in sessions, with their IP address and browser identifier, once they expire 7 days after sign-in.
  • We keep the audit log for as long as we run the service, because it is the record of every license issued, revoked or reassigned; its entries include the IP addresses described above.
  • When an administrator removes a member, we delete the member's name and email address from the portal and end the member's sessions; the audit log, the licenses already issued to that member and our backups keep them. We keep the rest of an organization's portal records for the term of the subscription and delete them when the customer asks us to close the account, except the billing records and the audit log.
  • We keep email and voicemail correspondence with a customer until 24 months after the license ends, and other correspondence for up to 24 months after its last message, unless it forms part of the billing records.
  • We keep your marketing consent record until you withdraw your consent. Once you unsubscribe, we immediately cease sending you marketing emails, but we will retain a record of your opt-out for up to 5 years solely to ensure we respect your choice and to demonstrate our compliance with applicable anti-spam laws.
  • Deleted records remain in our backups until those expire: daily copies of selected licensing tables for 30 days, weekly copies of the whole licensing database for 13 months, and weekly copies of the whole audit log for 7 years from the day each copy is made.

Who receives it

These are the parties that receive the data described here and what each one does with it. Each one acts on our instructions as our processor, except Paddle, which sells in its own name as merchant of record and is an independent controller for billing data, and Cloudflare, which also uses the signals its Turnstile challenge collects, as a controller, to improve its bot detection:

  • Cloudflare, which hosts getskarn.com and the customer portal, runs our registration and processing endpoints, stores the licensing database and its daily backups, signs free licenses, and provides the Turnstile challenge on the registration form;
  • Amazon Web Services, which holds the key that signs paid licenses and stores our weekly backups, in Frankfurt, Germany: each signing request carries the contents of the license being signed, including the holder's email address and the organization name;
  • GitHub, whose hosted runners produce the weekly backup export of the licensing database before it is stored at Amazon Web Services;
  • SMTP2GO, which delivers the sign-in, confirmation, invitation, transaction, and license retrieval emails from its EU infrastructure;
  • Hetzner Online GmbH, on whose server in Nuremberg, Germany, we host our Matomo analytics and its backups;
  • Paddle, our merchant of record, which handles paid checkouts, VAT and tax calculation, payment processing, and financial record retention as an independent controller;
  • HubSpot, our customer relationship system, hosted in the EU (Germany), which holds the contact details of the people we talk to about a purchase and the emails we log with them;
  • Microsoft, whose Microsoft 365 service hosts our company email in the European Union and EFTA;
  • Zadarma, which runs our support telephone number: every call goes to voicemail, and the recording and the caller's number are emailed to us.

When we route a registration or join request to an organization that verified the email domain, or show an Enterprise organization the personal accounts on its verified domain, that organization receives the details described above and handles them under its own rules. The full list, with what each party receives and where it operates, is at getskarn.com/trust/subprocessors/.

For the personal data of a Team or Enterprise customer's members held in the license portal, we process on the customer's instructions under the data processing agreement.

We do not sell your data, and we do not share it for anyone else's advertising.

International data transfers

Some of our service providers process personal data outside the European Economic Area (EEA). These transfers rely on the Standard Contractual Clauses in their data processing terms or on an adequacy decision of the European Commission. You can ask for a copy of the clauses that apply to your data at hello@getskarn.com.

Your rights

Subject to applicable law, you can ask us to give you a copy of your data, correct it, erase it, restrict or object to our use of it, or provide it in a portable form; and you can withdraw marketing consent at any time. In particular, you have the right to object at any time to the processing of your personal data for direct marketing purposes under Article 21 of the GDPR. To exercise any of these rights, email hello@getskarn.com. Erased data leaves our backups when those expire, as described above. If you believe we have handled your data wrongly, you also have the right under Article 77 of the GDPR to lodge a complaint with a data-protection supervisory authority in the EU or EEA country where you live or work.

Changes to this policy

We update this page when the facts change.

See also the license terms, the free license registration and the third parties we use.