Privacy Policy
Last updated 2 September 2026
This Privacy Policy explains how Crow Recon (“we”, “us”, or “Crow Recon”) handles personal information in connection with the Crow Recon website (crowrecon.com) and desktop application (together, the “Service”).
1. The desktop application
- No account, no telemetry. The app does not create an account, phone home, or send usage analytics to us.
- Your scan data stays local. Results, reports, monitoring history, and settings are
stored only on your computer (under
~/.crowrecon). We have no access to them. - Credentials stay local. Any credentials you enter for authenticated scope are stored only in your operating system’s keychain and are sent only to the target you are authorized to test — never to us.
- The app contacts third-party public data sources (for example certificate-transparency logs or the passive-source APIs you configure) only to perform the scan you request; those requests go directly from your machine to those services.
2. Information we collect
When you buy a license
Purchases are processed by Paddle as our Merchant of Record. Paddle collects your payment and billing details directly and shares with us only what we need to fulfil and support your order — typically your email address, the product and tier purchased, country, and an order/subscription identifier. We do not receive or store your full card number.
When we send your license key
We use Resend to email your license key to the address on your order. That email address is processed to deliver the key and any related support messages.
When you use the website
The website is hosted on Cloudflare. Standard server and security logs (such as IP address and request metadata) may be processed by our hosting and security providers to serve and protect the site. We do not use invasive advertising trackers.
When you contact us
If you email us, we keep your message and contact details to respond and for our records.
3. How we use information
- To deliver, activate, and support your license;
- To process purchases, renewals, and refunds (through Paddle);
- To operate, secure, and improve the website; and
- To comply with legal, tax, and accounting obligations.
We do not sell your personal information.
4. Service providers (sub-processors)
We share the limited information above with the following providers, each acting on our behalf under their own privacy terms:
- Paddle — payments, subscriptions, tax, and Merchant-of-Record services.
- Resend — delivery of the license-key and support emails.
- Cloudflare — website hosting/CDN, DNS, and email routing for our contact addresses.
- Google Cloud — the small service that turns a completed purchase into a signed license key and emails it.
5. Retention
We keep order and license records for as long as needed to support your license and to meet our legal, tax, and accounting obligations, then delete or anonymize them. Paddle retains transaction records under its own policy.
6. Your rights
Depending on where you live, you may have the right to access, correct, or delete the personal information we hold about you, or to object to certain processing. To make a request, email hello@crowrecon.com. For payment data held by Paddle, you can also contact Paddle directly. We will respond as required by applicable law.
7. Security
We use reasonable technical and organizational measures to protect the limited information we hold, including keeping secrets in managed secret storage and transmitting data over encrypted connections. No method of transmission or storage is perfectly secure.
8. Children
The Service is not directed to children and is intended for use by professionals and organizations. We do not knowingly collect information from children.
9. Changes
We may update this Policy from time to time; material changes will be posted here with a new “last updated” date.
10. Contact
Privacy questions: hello@crowrecon.com.