__Privacy Policy__
AuditAid
Effective Date: June 19, 2026
Last Updated: June 20, 2026
This Privacy Policy applies to auditaid.io and all associated web applications and services operated by AuditAid. AuditAid is not a law firm. This document does not constitute legal advice. You should consult qualified legal counsel for advice specific to your jurisdiction.
1. Introduction
AuditAid ("we," "us," or "our") provides an AI-powered smart contract security auditing platform accessible at auditaid.io (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard information about you when you visit our website or use our Service.
We are committed to data minimization. We collect only what is necessary to provide the Service and comply with applicable law, including the EU General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable privacy regulations.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration data: name and email address (OAuth sign-in only; we do not collect passwords)
- Billing and payment information (processed by our third-party payment provider; we do not store raw card data)
- Smart contract code and related materials you submit for auditing
- Communications you send to us via support channels
2.2 Information Collected Automatically
When you visit our website, we automatically collect limited technical data necessary to operate the Service:
- Session authentication tokens (strictly necessary)
- CSRF protection tokens (strictly necessary)
- Load balancing cookies (strictly necessary)
- User preference cookies, such as cookie consent status (strictly necessary)
With your consent, we also collect:
- Analytics data via Google Analytics 4 and Microsoft Clarity, including anonymized page views, session duration, referral sources, browser type, approximate geographic region, and aggregated interaction/heatmap data (analytics cookies, require opt-in for EU/UK users)
2.3 Information We Do NOT Collect
We do not collect:
- Advertising or marketing tracking cookies
- Social media tracking pixels
- Biometric data or sensitive personal information as defined under CPRA
- Data from minors under the age of 16
3. Cookies and Tracking Technologies
3.1 Strictly Necessary Cookies
Strictly necessary cookies are required for the Service to function and cannot be disabled. They do not require your consent under GDPR or CCPA. These include:
- Session cookies for authentication
- Security tokens to prevent cross-site request forgery
- Cookie consent preference storage
3.2 Analytics Cookies (Google Analytics 4)
We use Google Analytics 4 to understand how visitors interact with our website. Google Analytics sets cookies that collect anonymized usage data transmitted to Google's servers.
Legal basis (GDPR): Consent (Article 6(1)(a)). We do not activate Google Analytics until you have affirmatively accepted analytics cookies via our cookie consent banner.
CCPA/CPRA: Google Analytics data may constitute a "sharing" of personal information under California law. You may opt out at any time via our cookie preference center or by using the Google Analytics Opt-Out Browser Add-on available at tools.google.com/dlpage/gaoptout.
We have enabled IP anonymization within Google Analytics 4. We do not use Google Analytics data for advertising or retargeting purposes. We also use Microsoft Clarity (a Microsoft product) for aggregated session analytics and heatmaps to understand usability; like Google Analytics, it loads only after you accept analytics cookies and is governed by the same consent and opt-out controls.
3.3 Cookie Consent Banner
On your first visit, a cookie consent banner will:
- Clearly distinguish strictly necessary cookies (always active) from analytics cookies (opt-in for EU/EEA/UK users, opt-out for all others)
- Allow you to accept or decline analytics cookies before they are set
- Provide a persistent link to your cookie preferences in the website footer
You may change your cookie preferences at any time by clicking "Cookie Preferences" in the website footer. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
4. How We Use Your Information
We use the information we collect for the following purposes:
- To create and manage your account and authenticate your identity
- To provide, maintain, and improve the AuditAid auditing Service
- To process transactions and send related billing communications
- To respond to your support requests and communications
- To monitor Service security, detect fraud, and prevent abuse
- To analyze aggregate usage patterns and improve user experience (analytics, with consent)
- To comply with applicable legal obligations
We do not sell your personal information. We do not use your submitted smart contract code to train AI models. Audit results and submitted code are treated as confidential.
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing personal data are:
- Contract performance (Article 6(1)(b)): processing necessary to provide the Service you have requested
- Legal obligation (Article 6(1)(c)): processing required to comply with applicable laws
- Legitimate interests (Article 6(1)(f)): security monitoring, fraud prevention, and service improvement — where these interests are not overridden by your rights
- Consent (Article 6(1)(a)): analytics cookies, email marketing (if applicable)
6. Data Sharing and Disclosure
6.1 Service Providers (Sub-processors)
We share personal data with trusted third-party service providers acting as data processors on our behalf, including:
- Cloud hosting and infrastructure providers (e.g., Vercel, Railway)
- Payment processors (e.g., Stripe)
- Analytics providers (Google Analytics 4 and Microsoft Clarity, only with your consent)
- AI model inference providers used within the auditing pipeline
All service providers are contractually bound to process data only on our instructions, implement appropriate security measures, and comply with applicable data protection laws. We maintain a current list of sub-processors available upon request.
6.2 Legal Disclosures
We may disclose your information when required by applicable law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data may be transferred as part of that transaction. We will notify you via email or prominent notice on our website of any such change in ownership and any choices you may have regarding your personal data.
6.4 No Sale of Personal Data
AuditAid does not sell or rent personal information to third parties for their own marketing or commercial purposes. We do not share your submitted smart contract code with any third party except as strictly necessary to provide the Service (e.g., AI inference providers bound by confidentiality obligations). Separately, if you explicitly opt in to publish a completed audit report to our public "Showcase," the report content you select (never including proof-of-concept exploit code) becomes publicly accessible and may be indexed by search engines until you unpublish it; this publication is entirely at your discretion and off by default.
7. Data Retention
We retain personal data for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy, or as required by law.
- Account data: retained for the duration of your account and for up to 3 years after account closure for legal and compliance purposes
- Submitted smart contract code and audit results: retained for the duration of your subscription; you may request earlier deletion. Reports you explicitly publish to the Showcase are retained until you unpublish them (exempt from the standard post-delivery deletion)
- Analytics data: retained per Google Analytics' default retention period (up to 14 months), subject to your consent
- Billing records: retained for 7 years as required for tax and accounting compliance
8. Data Security
We implement industry-standard technical and organizational security measures to protect your personal data, including:
- Envelope encryption for sensitive data at rest using AES-256
- PostgreSQL Row Level Security (RLS) to enforce per-user data isolation
- TLS/HTTPS encryption for all data in transit
- Access controls limiting employee access to personal data on a need-to-know basis
- Regular security assessments of our infrastructure
No method of transmission or storage is 100% secure. If we discover a data breach that affects your rights and freedoms, we will notify you and applicable regulators as required by law (within 72 hours under GDPR).
9. International Data Transfers
AuditAid operates globally. If you are located in the European Economic Area, United Kingdom, or Switzerland, your personal data may be transferred to countries outside your jurisdiction, including the United States.
Where we transfer data outside the EEA/UK, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission, or other transfer mechanisms recognized under applicable law.
10. Your Privacy Rights
10.1 Rights Under GDPR (EEA/UK/Swiss Users)
You have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate or incomplete data
- Erasure: request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
- Restriction: request that we restrict processing of your data in certain circumstances
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent: where processing is based on consent, withdraw it at any time
- Lodge a complaint: with your local data protection authority (e.g., your national DPA or the UK ICO)
10.2 Rights Under CCPA/CPRA (California Residents)
California residents have the right to:
- Know what personal information we collect, use, disclose, or sell
- Delete personal information we hold about you, subject to certain exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
- Limit use of sensitive personal information
- Non-discrimination for exercising your privacy rights
10.3 Exercising Your Rights
To exercise any of these rights, contact us at __legal@auditaid.io__. We will respond to verifiable requests within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before fulfilling your request.
11. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we learn that we have inadvertently collected such data, we will delete it promptly. If you believe we have collected information from a child under 16, please contact us immediately.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a prominent notice on our website and, where required by law, by sending an email notification to registered users. The updated policy will be effective as of the date indicated at the top of this document.
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms, to the extent permitted by applicable law.
13. Contact Information
For privacy-related inquiries, requests, or complaints, please contact:
__AuditAid__
Privacy Contact: legal@auditaid.io
Website: https://auditaid.io
For EU/EEA/UK users who are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.