// LEGAL
Privacy Policy
Effective date: 17 June 2026 · Last updated: 3 July 2026
This Privacy Policy explains how NewNormal Security (“NewNormal Security,” “we,” “us,” or “our”) handles personal data in connection with our website, the NewScan scanner, and the optional, paid NewScan Pro upgrade (together, the “Services”). It should be read together with our Terms of Service.
Privacy by design. NewScan runs on your machine. We do not receive your targets, scan traffic, findings, or AI provider keys — those never leave your environment. We only process the limited data described below for licensing, the opt-in hosted NewScan Pro service, payments, and running our website.
1. The short version
- NewScan (local): no telemetry; we collect nothing from your scans.
- Licensing: your email (the license is registered to it) and a salted one-way device fingerprint — never your raw machine identifiers.
- NewScan Pro: inbound callbacks from your authorized targets, held briefly under a short time-to-live (TTL), then automatically deleted.
- Payments: card processing is handled by Stripe, our payment processor. We never see or store your full card details.
- We do not sell your personal data or use it for third-party advertising.
2. Information we collect
2.1 NewScan (the local scanner)
NewScan is self-hosted and runs under your control. It sends us no scan data and contains no analytics or telemetry. Your target traffic, captured findings, and any AI provider keys remain on your machine.
2.2 Account, licensing, and activation
When you buy or activate NewScan Pro, we process:
- your email address, to which the license is registered and to which we send license and service communications;
- a device fingerprint — a salted, one-way hash of stable machine attributes used to bind a license to your device(s) and enforce seat limits. We do not receive the underlying identifiers (MAC, machine UUID, etc.), only the hash; and
- license metadata: license ID, plan, seat count, issue/expiry dates, and device activation records (fingerprint, first/last seen).
2.3 NewScan Pro (the hosted OOB collaborator)
When you enable NewScan Pro, your authorized targets may send out-of-band callbacks (HTTP(S) and DNS) to our hosted listener. For each callback we transiently record only what is needed to confirm a finding: the request method, path, query, a sanitized subset of headers, a size-capped and truncated body, the source IP, timestamp, and the unguessable correlation token from the canary hostname. This data is associated to your scan session and is held only long enough for your scanner to retrieve it, after which it auto-expires (see Retention). We do not use it for any purpose other than returning it to your scan as evidence.
2.4 Website
Our website is largely static. Our hosting providers process standard server logs (IP address, user-agent, requested URL, timestamp) for security and reliability. If you email us, we receive the contents of your message and your contact details.
2.5 Payments
NewNormal Security is the seller of record; card payments are processed on our behalf by Stripe. Stripe collects and processes your payment-card information directly; we receive limited transaction metadata (e.g. order ID, plan, billing country, and the email you used) but never your full payment-card number. See Stripe’s Privacy Policy.
3. How we use information
- to provide, operate, secure, and support the Services;
- to issue and verify licenses and enforce seat/device limits;
- to receive and return out-of-band detection evidence for your authorized scans;
- to process orders, renewals, and refunds (card processing by Stripe);
- to communicate about your account, security, and material changes; and
- to comply with legal obligations and enforce our Terms.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing licensed Services), legitimate interests (securing and improving the Services, preventing abuse), consent (where requested, e.g. optional communications), and legal obligation (e.g. tax and accounting record-keeping).
5. Sharing and processors
We do not sell personal data. We share limited data with service providers who process it on our behalf under appropriate safeguards:
- Stripe — payment-card processing and billing;
- hosting/infrastructure providers — for the hosted NewScan Pro service and for our website and licensing functions; and
- authorities — where required by law or to protect rights, safety, and the integrity of the Services.
6. International transfers
We and our providers may process data in countries other than yours, including the United States. Where required, transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms.
7. Data retention
- NewScan Pro callbacks are minimized and short-lived: they expire automatically when the scan session’s TTL elapses (by default within hours) and are not retained long-term.
- License and order records are kept for the duration of your subscription and for as long as needed for legal, tax, and accounting purposes.
- Server logs are retained for a limited period for security and reliability.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. If you are in California, you have the right to know, delete, and to opt out of “sale” or “sharing” — we do not sell or share personal data as those terms are commonly defined. To exercise any right, contact us at privacy@newnormalsecurity.com. You may lodge a complaint with your local data protection authority.
9. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, offline-verifiable signed licenses (so secrets are not exchanged on a hot path), one-way hashing of device fingerprints, data minimization, and access controls. No method of transmission or storage is perfectly secure, and security testing is inherently sensitive — you are responsible for handling exported findings appropriately.
10. Cookies and tracking
Our website uses only essential cookies/local storage needed for basic functionality; we do not use third-party advertising or cross-site tracking cookies. Stripe’s checkout may set its own cookies necessary to process your payment, governed by Stripe’s policies.
11. Children
The Services are intended for professional use and are not directed to children. We do not knowingly collect personal data from anyone under 16.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by additional notice.
13. Contact
Privacy questions: privacy@newnormalsecurity.com. General support: support@newnormalsecurity.com.