Your information
Privacy Notice
Preview draft · Last updated September 22, 2026
This notice explains how the current Purposeful Security review site handles information. It does not describe future accounts, saved assessments, evidence gathering, or consulting services.
Security Checkup answers
Your environment selections, answers, and exclusion explanations are processed in the current browser tab to generate your action plan. The checkup does not send these entries to our server or save them in cookies, local storage, or session storage. No account or evidence upload is required.
Refreshing, closing, or leaving the checkup may clear your progress. We do not hold a server-side copy of your answers to retrieve later. Do not enter names, passwords, customer information, or confidential technical details.
Reports you download or print
JSON reports are generated in your browser. Printing or saving a PDF uses your browser’s print tools. These reports can include your environment choices, answers, exclusion explanations, and recommended actions.
You control where you save or share a report. Protect it as potentially sensitive information. Downloads, cloud-synced folders, backups, and printers may retain copies under their own settings. Deleting a report from one location does not necessarily remove those copies.
Website requests and hosting
The review site is hosted on Cloudflare. Loading pages and using site features sends normal web requests through its infrastructure. Technical information can include your IP address, requested URL, request time, and browser information. This processing supports delivery and protection of the site and is separate from your checkup answers.
Cloudflare may process traffic and security information under its service terms and privacy practices. We have not yet confirmed all account-level logging, analytics, and retention settings for launch; this notice does not promise that visits are anonymous or that technical records are immediately deleted.
Cloudflare Privacy Policy ↗Vulnerability searches and threat headlines
Unlike checkup answers, vulnerability search keywords and filters are sent to our server in a request URL. The server sends relevant search parameters to NIST’s National Vulnerability Database to obtain results. Those requests may be present in service logs or caches. Search only for public product names or vulnerability identifiers, not confidential information.
Threat headlines are retrieved by the server from external news feeds. Opening an article or another external link takes you to a separate provider with its own privacy practices.
Cookies, analytics, and retention
The current application code does not add advertising trackers or store checkup answers in browser storage. Hosting-level features are separate and remain part of our pre-launch review. We are not making a site-wide “no cookies” or “no data collection” claim.
Checkup progress is temporary browser state; downloaded reports remain wherever you save them until you remove them. Hosting and third-party technical records follow the applicable service settings and policies. Their retention periods must be confirmed before the production notice is finalized.
Privacy questions and updates
A dedicated privacy email address is not yet active. We will add a verified, monitored contact and confirm the site operator’s details before public launch. Please do not send private information to a guessed email address.
This notice will be reviewed before introducing accounts, saved results, contact forms, analytics changes, or automated evidence collection. Changes will be reflected in the date at the top of this page.