Privacy Policy
1. Who we are
Infervo (“Infervo”, “we”, “us”) provides a martech stack-detection product: you submit a company’s website URL and Infervo reports the marketing, analytics, CRM, advertising, ecommerce, and payments technology that site uses. This policy explains what personal data we process, why, and with whom we share it. It covers infervo.app.
2. What we collect
Account information
When you sign in with Google we receive your name, email address, and profile picture. We do not receive or store your Google password.
Scans you run
- The website URLs you submit and the scan reports we generate from them (detected vendors, the public signals that triggered each detection, and email-infrastructure records read from public DNS).
- To produce a report, our servers fetch and render the public third-party website at the URL you submit, and query public DNS for that domain. The signals we capture are those a normal web browser sees (scripts, network requests, cookies set by the page) plus public DNS records.
We do not connect to your own databases, we do not store database connection credentials, and we do not ingest files you upload — Infervo no longer offers those features.
Technical & usage information
Essential session cookies (see Section 5) and basic operational logs (such as timestamps and request metadata) used to run and secure the service.
3. How we use your information
- To provide the service: authenticate you, run the scans you request, and generate and store reports.
- To operate, secure, debug, and improve the service.
- To communicate with you about your account or the preview.
We do not sell your personal data, and we do not use it for advertising.
4. Sub-processors & the sites we scan
Infervo runs on the third-party infrastructure providers below. Note that when you scan a URL, our servers fetch and render that third-party website directly; the operator of the scanned site may log that request (e.g. our IP and user agent) as they would any visit. Only scan sites you are authorised to scan.
| Provider | Used for | Data shared |
|---|---|---|
| Sign-in (Google OAuth) | Your name, email, profile picture | |
| DigitalOcean | Cloud hosting & infrastructure | All data, encrypted at rest |
| Google Public DNS & Cloudflare DNS (DNS-over-HTTPS) | Resolving the scanned domain’s email-infrastructure records (MX/SPF/DKIM/DMARC) to attribute its ESP/CRM | The domain name you scan |
| OpenRouter (optional AI summary) | Generating an on-demand AI narrative of a scan’s detected stack — only when you click “Generate AI summary” on a report | The scanned domain and the list of detected vendor names for that scan. No personal data, no page content, and nothing about you. |
The AI summary is optional and off by default— the scan itself is fully deterministic (signatures + DNS, no AI). A summary is generated only when you explicitly request one on a report, and it sends just that scan’s detected vendor names (above) to OpenRouter to produce a short narrative.
5. Cookies & analytics
Essential cookies — set by our authentication layer to keep you signed in. They are HttpOnly, Secure, and SameSite-scoped.
6. Data retention & deletion
We retain your account data, projects, and scan reports while your account is active. You can request deletion of your account and associated data by emailing hello@infervo.app; we will action it within a reasonable period. (During preview, self-service deletion tooling is still being built.)
7. Your rights
Depending on where you live (e.g. the EU/EEA/UK under GDPR, or California under the CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict the processing of your personal data, and to object to certain processing. To exercise any of these, email hello@infervo.app.
8. Security
We do not connect to your databases or store connection credentials. Scans run server-side, scan reports are isolated per tenant, traffic is served over HTTPS/TLS, and we authenticate via Google (no passwords stored). More detail is on our Security page.
9. International transfers
The providers in Section 4 may process data in the United States and other countries. By using Infervo you understand your data may be transferred to and processed in those countries.
10. Children
Infervo is not directed to children and is not intended for anyone under 16.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above and, where appropriate, communicated to you.
12. Contact
Questions about this policy or your data: hello@infervo.app.