Privacy policy
Last updated August 27, 2026
ZeroDayTracker (“we”) provides a watchtower for the SaaS tools you tell us you use. This policy explains what we collect and why.
What we collect
Account email, organization name, the vendor names you add to your stack, billing identifiers from Stripe, and how you use the product (pages, sign-in). We do not scan your network, ingest SSO logs, or collect the contents of the SaaS tools you name.
How we use it
To authenticate you, match public vulnerability feeds against your stack, send digest email if you subscribe, and process payment. We do not sell personal information.
Processors
We use Supabase (database and auth), Stripe (payments, on the PopMeUp Stripe account), Google Cloud / App Engine (hosting), and Resend (transactional email). Public vulnerability data comes from CISA and NIST.
Retention
We keep account and stack data while your account is open. You can request deletion by emailing privacy@zerodaytracker.ai.
Contact
privacy@zerodaytracker.ai