Privacy Policy
This policy explains what NexScan processes during browser environment checks, risk analysis and report generation, how the information is used and how its use is limited.
Information we process
Data required for detectionWhen a user opens a detection page, NexScan processes browser environment, network-path and runtime information to generate an authenticity report and explain anomalies.
Typical data includes browser identity, Client Hints, language, time zone, screen and hardware characteristics, Canvas / Audio / WebGL results, WebRTC exposure, IP geolocation intelligence, DNS results and historical drift records.
Google Analytics
Traffic analyticsGoogle Analytics loads automatically when a page is visited. It may use cookies and process page URLs, visit times, browser and device categories, referrers and coarse regions inferred from network addresses to aggregate traffic trends. NexScan does not intentionally send detection reports, fingerprint hashes or risk-rule results to Google Analytics.
Google Analytics is configured to anonymize IP addresses. Its retention period is controlled by the deployment owner in the corresponding Analytics property. Browser cookie controls, content blockers or Do Not Track-style tools can also be used to limit third-party analytics.
Retention and user rights
Deletion and processing restrictionsDetection sessions in this deployment are configured to be retained for no more than 30 days. On service startup, expired sessions and their associated raw signals, profiles and rule records are removed. If the operator changes this period, it should reassess data minimization and update this policy.
You may ask the operator to explain, correct or delete data associated with a detection session. Public history lookup is disabled, so detection records are not exposed on the internet through visitor identifiers.
How information is used
Purpose and boundariesThe information is used only for browser environment detection, risk scoring, anomaly explanations, security investigation, product debugging and service-quality improvements. It is not used for unauthorized cross-site tracking, advertising profiles or unrelated secondary purposes.
If a deployment stores detection records, its operator is responsible for database permissions, access controls, retention periods and internal audit policies, and for ensuring that use complies with applicable law.
Third-party services and dependencies
Supplementary intelligenceNexScan may call third-party IP intelligence or network analysis services to supplement ASN, geolocation, DNS resolver operator and proxy information. Returned data is used only for the current detection purpose and is not a final judgment about a user's identity or behavior.
Operators integrating additional external APIs should evaluate their reliability, cross-border data handling, quotas, terms and compliance requirements.
Data protection and expectations
Security and transparencyOperators should apply data-minimization principles, enable detection only where environment identification, risk assessment or security investigation is needed, and clearly explain the purpose to users.
NexScan provides technical detection and risk references. It does not automatically establish identity, justify account penalties or create a legal conclusion. Business decisions should combine configured thresholds, human review and compliance requirements.