desenmascara.me
Privacy Policy
How we collect, use, and protect data at desenmascara.me.
Last updated: October 3, 2026
Data we process
- • Account data: email, username, authentication and access logs.
- • Service data: analyzed domains, timestamps, verdicts, and report metadata.
- • Security data: IP, user-agent, and language headers for abuse prevention and traceability.
Purposes and legal basis (GDPR)
- • Service delivery and account management (Art. 6(1)(b)).
- • Security, anti-abuse, and fraud prevention (Art. 6(1)(f)).
- • Legal obligations and compliance requirements (Art. 6(1)(c)).
- • Product updates and service communications when applicable (Art. 6(1)(a)/(f)).
Payments and processors
- • Payments are processed by Stripe as payment processor.
- • desenmascara.me does not store full payment card details.
- • Infrastructure and service providers are used under contractual safeguards.
AI assistants (MCP connector)
- • Our MCP server (https://desenmascara.me/mcp/v1) is read-only: it returns reports we have already published and never starts an analysis.
- • What we receive: the domain your assistant asks about, the request time, your IP address and the client name your assistant sends. We receive no account data, no conversation content and no prompts.
- • Your IP address is used only for the per-address rate limit (a counter that expires after 60 seconds) and appears in our web server logs, kept 14 days. The domain asked about is kept in our application logs for 30 days, without your IP address.
- • The free tier needs no account or key. Keyed access follows the account terms above.
Retention and rights
- • Data is retained only as long as required for operations, security, and legal obligations.
- • You may request access, correction, deletion, objection, restriction, or portability.
- • Contact: [email protected]