Privacy Policy
Last updated: 13 September 2026
1. Who we are
F(x) ("F(x)", "we", "us") is operated by:
Ignas Paškauskas
Įsruties g. 19, Vilnius, Lithuania
Email: [email protected]
F(x) provides automated pre-acquisition analysis of online businesses. This policy explains what personal data we handle, why, and for how long.
2. Scope
This policy covers the F(x) web application at fxscan.app, the F(x) Stripe app, and any connectors used to grant F(x) read-only access to third-party services during a due-diligence review.
3. Our role under the GDPR
Our role depends on the data:
- Buyer account data — we are the controller. We decide why and how this data is processed.
- Data analysed during a scan (a target business's Stripe account, code repository, database, or website) — we act as a processor on behalf of the buyer who commissioned the scan. The business being analysed, or its owner, remains the controller of its own customer data.
Where a seller grants F(x) read-only access to their systems, they do so knowingly and voluntarily as part of a due-diligence process, and may withdraw that access at any time.
4. What we collect
From buyers (account holders)
- Email address and authentication details (we use Supabase Auth; passwords are hashed and we never see them in plain text)
- If signing in with Google: your email address and basic profile information
- Scan history: the URLs and businesses you have scanned, and the reports generated
During a scan
- The public content of the website being scanned (pages, scripts, HTTP headers, publicly reachable files)
- Where access is granted by the seller: read-only access to services such as Stripe, GitHub, Supabase, or Google Analytics, limited to the permissions the seller selects
Website analytics (only if you accept cookies — see section 5)
- We use PostHog, hosted in the EU, on our own website (fxscan.app) to count visits and see which pages and buttons people use. It records approximate location, device type, pages viewed, where on a page you click, and a replay of clicks and scrolling. Anything typed into a form is hidden in the replay.
- Pages that show scans, reports, your dashboard, your account, checkout, or a seller's access request are never recorded, and no analytics data is sent from them.
- This applies only to visitors to our own site. It is never applied to a website being scanned, and it is unrelated to the Google Analytics data a seller may grant us to read during a scan.
Report count (no cookie)
- When a report finishes, we send PostHog a single event containing only the scan's internal identifier. It contains no email address, no scanned website, and no findings, and it is not linked to a visitor. It lets us count reports generated.
We do not collect
- Payment card numbers. Payments, where applicable, are processed by Stripe; we never receive or store card details.
- Advertising or marketing identifiers, and we do not use error-tracking services such as Sentry.
5. Cookies
Essential cookies. If you have an account, we set a cookie to keep you signed in. Without it the site cannot tell one signed-in person from another, so it is set regardless of the choice below and cannot be turned off.
Analytics cookies. PostHog sets cookies to count visitors and pages. These are not set unless you press Accept on the banner shown on your first visit. Press Decline and no analytics cookies are set and no visitor data is sent to PostHog — the site works exactly the same either way.
Changing your mind. Your choice is stored in your browser, not in your account. Clearing your browser's site data for fxscan.app removes it and the banner appears again.
Not used. We set no advertising or cross-site tracking cookies, and no third-party cookies beyond the PostHog ones described above.
6. How we handle sensitive data found during a scan
This is the most important part of this policy, so we state it plainly.
Credentials granted by a seller. Read-only credentials (for example a Stripe restricted API key, or an OAuth token) are used only for the duration of the scan. They are revoked and deleted immediately once the scan completes, including where a scan fails partway through. We do not retain them.
Payment and subscription data. From services such as Stripe we derive only aggregate metrics — for example the proportion of revenue on promotional pricing, retention and churn rates, and revenue concentration. We do not retrieve, store, or include in reports the personal data of the analysed business's customers, such as names or email addresses.
Secrets found during a website scan. Where a scan finds an exposed credential (for example an API key left in a website's code), we record only its type, where it was found, and a truncated fingerprint sufficient to identify it. We do not store the credential's full value.
Database exposure findings. Where a scan finds a database table readable without authentication, we record the table name, the number of rows, and the column names. We do not retrieve or store the contents of those rows.
Evidence retention. Technical evidence supporting a finding is stored in a private, encrypted store and is automatically deleted 30 days after the scan.
7. Reports
A completed report is delivered to the buyer who commissioned it. Reports contain findings and aggregate metrics, and are redacted so that they do not contain credential values or personal data belonging to the analysed business's customers.
Once a report has been delivered, the buyer holds their own copy. We can delete our copy on request, but we cannot recall or delete a copy already in the buyer's possession. Please bear this in mind when commissioning a scan.
8. Legal bases for processing
- Performance of a contract — to create and maintain your account, run scans you request, and deliver reports.
- Legitimate interests — to keep the service secure, prevent abuse, and maintain the integrity of our systems.
- Consent — where a seller grants read-only access to their systems, that access is based on their explicit, revocable consent.
9. Retention
| Data | Retention |
|---|---|
| Access credentials granted for a scan | Deleted immediately on scan completion |
| Technical evidence supporting findings | Automatically deleted 30 days after the scan, by a scheduled job that runs several times a day |
| Analytics cookies (our own website) | Set only if you accept them; your choice is remembered in your browser until you clear it. Session replays are kept by PostHog for 30 days |
| Reports and derived aggregate metrics | Retained while your account is active; deleted on account deletion |
| Account data (email, authentication) | Retained while your account is active; deleted within 30 days of account deletion |
10. Where your data is processed
F(x) processes and stores data within the European Union. Our infrastructure providers act as processors on our behalf:
- Supabase — database and authentication
- Railway — application hosting
- Cloudflare R2 — encrypted storage of scan evidence
- Stripe — payment processing, where applicable
- PostHog (EU Cloud) — analytics for our own website
Some of these providers are established outside the EU. Where any transfer outside the European Economic Area occurs, it is carried out under appropriate safeguards, including the European Commission's Standard Contractual Clauses.
We do not sell personal data, and we do not share it with third parties for marketing purposes.
11. Security
We apply the following measures:
- All data encrypted in transit (TLS) and at rest
- Access credentials never stored in plain text
- Row-level access controls so that each account can access only its own data
- Evidence storage is private, with no public access, and access is logged
- Data minimisation by design: we collect the least data needed to produce a finding, and discard it on a fixed schedule
No system is perfectly secure, but we aim to hold as little sensitive data as possible, for as short a time as possible.
12. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent at any time.
To exercise any of these rights, contact [email protected]. We will respond within one month.
If you believe we have handled your data improperly, you may lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) at vdai.lrv.lt, or with the supervisory authority in your country of residence.
13. Sellers granting access
If you are a seller who has been asked to grant F(x) read-only access:
- Access is read-only. F(x) cannot modify, delete, or move anything in your accounts, and cannot initiate payments.
- You choose which services to grant, and may decline any of them.
- You may revoke access at any time from within the service concerned.
- Access credentials are deleted as soon as the scan finishes.
- The resulting report goes to the buyer who commissioned it. If you would like to know what was reported about your business, contact [email protected].
14. Children
F(x) is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
15. Changes to this policy
We may update this policy as the service develops. The "last updated" date at the top will change, and material changes will be communicated to account holders by email.
16. Contact
Questions about this policy or about your data:
[email protected]
Ignas Paškauskas, Įsruties g. 19, Vilnius, Lithuania