Privacy policy
Last updated: September 1, 2026
This Privacy Policy explains how Rowly ("we", "us") collects, uses, and shares information when you use rowly.me and related services.
1. Information we collect
- Account data: email address, name (if provided), authentication identifiers, and workspace membership details.
- Billing data: handled by our payment processor (Paddle). We store subscription status and related billing identifiers needed to manage your plan. We do not store full card numbers.
- Scan and project data: project names, scan reports, security scores, and settings you save to your dashboard.
- Usage and technical data: approximate location (e.g. country from edge headers), device/browser information, and logs needed to operate and secure the Service.
2. Scans and credentials
Rowly never asks for or accepts database credentials. Scans run against a domain you provide: we read your site's public homepage and JavaScript, and, if a Supabase or Firebase project is discovered, probe its public API using only that project's own public key - never a password or service-role key. We also check for publicly-reachable hosting platforms (Vercel, Netlify, AWS, and others) using the same passive, credential-free approach. To generate comprehensive security scores, we may submit the domain name (and only the domain name, without credentials or payload data) to reputable third-party security databases and scanning tools, such as Mozilla HTTP Observatory, Qualys SSL Labs, Google Safe Browsing, and Certificate Transparency logs.
3. How we use information
- Provide, secure, and improve the Service
- Authenticate users and manage organizations
- Process subscriptions and send transactional emails
- Send optional security alerts or digests you enable
- Comply with law and prevent abuse
- Create aggregated, anonymized security analytics and industry benchmarks to improve our scanning algorithms and publish generalized security insights (no individual project or user identifiable data is ever disclosed)
4. Cookies and local storage
We use essential cookies and browser local storage strictly necessary to authenticate your account, maintain active login sessions, store workspace settings, and prevent fraudulent activity. These are always on and cannot be declined, since the Service does not work without them.
We also use analytics cookies and tools (Google Analytics and PostHog) to understand how Rowly is used and improve it, but only if you accept the cookie banner shown on your first visit. If you decline, or don't respond, these stay off: no analytics cookies are set, and PostHog runs in a memory-only mode that never writes an identifying cookie to your device. Declining does not limit access to the scanner or any other part of the Service. You can change your choice at any time using the "Cookie preferences" link in the footer. We do not use third-party tracking cookies for cross-site advertising.
Separately, our hosting provider (Vercel) runs a cookieless traffic analytics tool on every page - it does not read or write any cookie or local storage on your device, so it is not part of the choice above. It records page views against a rotating, non-persistent identifier rather than anything stored on your device.
5. Sharing
We share necessary data with trusted third-party service providers (sub-processors) that assist us in operating the Service, including cloud hosting and cookieless traffic analytics (Vercel), database management (Supabase), authentication, transactional email delivery, payment processing (Paddle), and, only if you accept the cookie banner, analytics (Google Analytics, PostHog). All service providers are bound by strict confidentiality and data protection obligations. We do not sell your personal information.
6. Retention
We retain account and project data while your account is active and as needed for legitimate business, security, and legal purposes. You may request account deletion subject to our product controls and legal obligations.
7. Security
We use industry-standard safeguards appropriate to a security product, including encrypted transport and access controls. No method of transmission or storage is 100% secure.
8. International data transfers and user rights
Your information may be transferred to, stored, and processed on servers located outside of your home jurisdiction (including the United States and European Union). Regardless of your location, you have the right to access, update, export, or request the deletion of your personal account data. To exercise any of these rights, please contact us at support@rowly.me.
9. Changes
We may update this policy periodically. The "Last updated" date at the top will change when we do.
10. Contact
Privacy questions: support@rowly.me.