Qyvern

Privacy

Last updated 28 August 2026.

Who is responsible

The controller for the personal data described here is Zorez Group AB, org.nr 559452-7367, Stadsskogsgatan 46, 441 44 Alingsås, Sweden. Qyvern is the service operated by that company.

Privacy contact: hello@zorezgroup.com. Use the same address for access, deletion and any other request under this page.

Scan results are public by default

This is the most important thing to understand before you use Qyvern. When you submit a URL, the resulting report is public unless the scan is marked private. It is published at a shareable URL of the form /s/<slug>, it is listed on the public recent index, and a preview image of the score is generated for it. Anyone who has or finds the link can read the endpoint URL, the score, the findings and the simulated agent verdicts.

Submitting a URL is therefore an act of publishing information about that endpoint. Do not submit endpoints whose URL, existence or behaviour is confidential, and do not submit URLs that contain personal data, tokens or other secrets in the path or query string. Credentials embedded in a submitted URL are stripped before storage, but the rest of the URL is stored and shown as submitted.

What we collect, why, and on what legal basis

  • Submitted endpoint URLs and scan results. Stored so the scan can run and so the report can be shown and shared. Legal basis: performance of the service you requested (Article 6(1)(b)), or our legitimate interest in operating a public diagnostic index where you are not a party to a contract (Article 6(1)(f)).
  • Email address. Collected when you sign in with a magic link, and used to send that link and any service messages about your account. Legal basis: performance of the service (Article 6(1)(b)).
  • A quota key derived from your IP address. Anonymous scans are limited per network per day. We compute a one-way hash of your IP address (or of your user id when you are signed in) and store only that hash. We do not store the raw address in the application database. Legal basis: our legitimate interest in preventing abuse and keeping the free quota usable (Article 6(1)(f)).
  • Server and infrastructure logs. Our hosting and database providers keep standard request logs, which can include IP addresses, for security and debugging. Legal basis: legitimate interest in the security and availability of the service (Article 6(1)(f)).

We do not sell personal data, we do not use it for advertising, and we do not carry out profiling or automated decision-making that produces legal effects for you.

Cookies and browser storage

Qyvern sets no advertising or analytics cookies and runs no advertising trackers. We measure page visits with Plausible Analytics, which is cookieless, stores nothing on your device, and reports only aggregate counts such as pages viewed and referring sites. We do not use device or browser fingerprinting.

If you sign in, your browser keeps a sign-in session token in local storage so you stay signed in between visits. That storage is strictly necessary for the sign-in feature and is cleared when you sign out or clear site data. Anonymous scan quota is enforced from the hashed IP key described above, not from a cookie, so browsing the site without signing in stores nothing on your device.

Outbound requests to endpoints you submit

Running a scan means we make a small number of read-only HTTP requests from our infrastructure to the URL you submitted. Those requests carry our own network identity, not yours. Operators of the scanned endpoint will see them in their own logs. We never send payments and never attempt state-changing requests.

Sub-processors

These providers process data on our behalf:

  • Supabase — application database, authentication and magic-link email delivery. Data is held in an EU region.
  • Plausible Analytics, cookieless aggregate visit statistics. Plausible is an EU company and processes data in the EU.
  • Lovable — application hosting and deployment for the web front end and its server routes, served from an edge network with points of presence in and outside the EU. Request routing may terminate outside the EU even though stored data does not leave it.
  • The Qyvern scan engine — operated by us on our own infrastructure in the EU. It reads the endpoint you submitted and writes results back.

Stated plainly: the edge routing above is the one point where processing is not strictly EU-only, and we have not yet completed a documented transfer assessment for it. We will publish the outcome here when it is done rather than claim a result we do not have. We hold no certifications and make no compliance claims beyond what is written on this page.

We will update this list before adding a new sub-processor that handles personal data.

How long we keep things

  • Public scan results: kept indefinitely while the report remains published, because the public index is part of the service. Removed within 30 days of a deletion request.
  • Quota keys: 24 hours, then deleted by a scheduled job.
  • Account data, including your email address: kept while the account exists, and deleted within 30 days of your deletion request or of the account being closed.
  • Infrastructure logs: retained by our providers for up to 30 days, then rotated out.
  • Email delivery records for magic links: up to 30 days.

Your rights and how to use them

You have the right to access your data, to have it corrected, to have it deleted, to restrict or object to processing, and to receive it in a portable format. Write to hello@zorezgroup.com and say what you want. We answer within 30 days, and we tell you if a request genuinely needs longer, which the GDPR allows up to three months in complex cases.

We may need to confirm that a request comes from the account holder before acting on it. For a scan submitted anonymously, tell us the report URL and we will remove it; we cannot verify who submitted an anonymous scan, so we treat removal requests for a report from the operator of the scanned endpoint as valid.

If you think we have handled your data wrongly you can complain to Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy.se.

Security

Access to the production database is restricted, row-level security is enforced on user data, and traffic is encrypted in transit. No service is perfectly secure. If a breach affects your personal data and is likely to result in a risk to you, we notify you and IMY without undue delay, as the GDPR requires.

Children

Qyvern is a tool for people running API endpoints. It is not intended for children and we do not knowingly collect their data.

Changes

We update this page when the service changes in a way that affects your data, and we change the date at the top when we do. Material changes are announced on the site before they take effect.