Deep Security Recon Back to Recon

Deep Security Recon

Privacy Policy

This policy explains how Deep Security Recon and the Deep Security Recon Chrome extension collect, use, disclose, retain, and protect information.

Effective September 9, 2026
No sale of user dataWe do not sell personal information or browsing activity.
User-initiated analysisA hostname is submitted only when you choose to start an analysis.
Limited collectionThe extension does not read page text, forms, cookies, or complete browsing history.

1. Scope and service purpose

This policy applies to the Deep Security Recon website at recon.deepsecurity.io and the Deep Security Recon Chrome extension. The extension’s single purpose is to let a user select the hostname of the active public website and initiate authorized security, OSINT, infrastructure, mail-security, TLS, exposure, and threat-intelligence checks through Deep Security Recon.

The service is intended only for lawful research involving systems, organizations, domains, accounts, or other targets that the user owns, administers, or is authorized to assess.

2. Information the Chrome extension handles

Active website hostname

When you open the extension from Chrome’s toolbar, the extension reads the active tab URL to identify and display its hostname. It accepts only public HTTP or HTTPS websites. The extension does not read or transmit the page path, query string, page text, images, form entries, passwords, cookies, or other page contents. The hostname is sent to Deep Security Recon only after you click Analyze this website.

Account and authentication information

If you connect a Deep Security account, the extension handles your account identifier, name, email address, subscription plan, module entitlements, usage allowance, an opaque authorization token, and a cryptographic verifier. The token and verifier are stored in Chrome local storage on your device so the extension can maintain the connection. They are removed when you disconnect, when they become invalid, or when the extension is removed. The issued authorization token is time-limited.

Selections and technical information

The extension handles the module groups and premium modules you select. Requests to Deep Security Recon also contain ordinary connection information, including the extension identifier, date and time, source IP address, approximate country or region, browser or device category, and security-related request metadata.

3. Information handled by the Recon service

When a scan is started, the service may process the submitted domain, hostname, IP address, email address, username, phone number, VIN, or password hash prefix, depending on the feature you intentionally select. Reports may contain public registration, infrastructure, security, reputation, exposure, company, professional, or vehicle information returned by the selected sources.

For account administration and billing, we may handle account identity, email address, display name, plan, subscription status, allowances, usage totals, and transaction or subscription identifiers. Payment-card details are entered directly with the payment processor and are not stored by Deep Security Recon.

Privacy-conscious operational analytics may record country or region, browser family, device class, page-section interactions, and aggregate usage. Raw IP addresses, email addresses, submitted targets, and complete browser fingerprints are not stored in the analytics dataset.

4. How information is used

  • Provide the user-requested reconnaissance and security analysis.
  • Authenticate accounts and determine available plans, allowances, and premium modules.
  • Operate, maintain, secure, troubleshoot, and improve the requested functionality.
  • Prevent fraud, automated abuse, unauthorized activity, and misuse of the service.
  • Maintain security audit records and respond to support, legal, or regulatory requests.
  • Process subscriptions and maintain required business and transaction records.

We do not use browsing activity or other user data for personalized advertising, retargeting, data-broker services, creditworthiness, or lending decisions.

5. When information is disclosed

Submitted targets are disclosed only as needed to provide the modules you select, operate and secure the service, process payments, comply with law, or investigate fraud and abuse. Depending on the selected feature, providers may include:

  • Platform and account services: OpenAI ChatGPT Sites and Cloudflare.
  • Payments: Stripe.
  • DNS, registration, certificate, and infrastructure sources: Cloudflare DNS, RDAP.org, ARIN, crt.sh, WhoisXML API, DNSDumpster, Qualys SSL Labs, Shodan InternetDB, and the operators of the submitted public website.
  • Threat and exposure sources: VirusTotal, urlscan.io, Have I Been Pwned, Spamhaus, GreyNoise, AbuseIPDB, IPinfo, LevelBlue AlienVault OTX, and CISA.
  • Search and public-data sources: Google Search services, Google News, GitHub-hosted public datasets, Trestle, IPWhoIs, ipapi.co, NHTSA, and FuelEconomy.gov, when the corresponding module is selected.

Those providers process information under their own terms and privacy policies. We do not sell or transfer user data to advertising platforms, data brokers, or information resellers. We may disclose information when required by law or when reasonably necessary to protect users, the service, or others from malware, spam, phishing, fraud, abuse, or other security threats.

6. Retention

Submitted targets, account identity, exact source IP address, masked network prefix, country, timestamps, and related security-event information may be retained in an owner-restricted security audit log for up to 90 days. Password values are never retained. For the optional password-exposure check, only the first five characters of a SHA-1 hash are sent to the Pwned Passwords service using its k-anonymity protocol.

Account, usage, subscription, and transaction records are retained for as long as reasonably necessary to provide the service, administer the account, maintain security and financial records, resolve disputes, and meet legal obligations. Locally stored extension authorization data remains on the device until disconnection, invalidation, or extension removal.

7. Security

User data transmitted by the extension is sent over HTTPS. The extension limits network access to Deep Security Recon, uses a time-limited signed authorization token with a cryptographic verifier, and does not include remotely hosted executable code. Administrative audit data is restricted to authorized administrators. No method of storage or transmission is completely secure, but we use reasonable technical and organizational safeguards appropriate to the information handled.

8. Your choices and requests

  • You may use the extension without connecting a paid account, subject to the service’s current access requirements and allowances.
  • You control whether to start an analysis and which module groups to use.
  • You may disconnect the extension at any time to remove its locally stored authorization data.
  • You may uninstall the extension through Chrome to remove extension-local data.
  • You may contact us to request access, correction, or deletion of eligible personal information. Some records may be retained when required for security, fraud prevention, billing, dispute resolution, or legal compliance.

9. Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

We limit the collection, use, and transfer of user data to what is necessary to provide, maintain, secure, and improve the extension’s disclosed single purpose. Human access to user data is limited to user-authorized support, security or abuse investigation, legal compliance, or aggregated and anonymized internal operations.

10. Children’s privacy

The service is designed for security professionals and authorized adult users. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

11. Policy changes

We may update this policy when the extension, service, providers, or legal requirements change. The effective date at the top of this page will be updated when changes are published. Material changes to user-data practices will be disclosed as required before the new practices take effect.

12. Contact

For privacy questions or requests, contact Deep Security Inc. through the Deep Security contact page. Please include “Deep Security Recon Privacy” in your message and do not include passwords, authentication tokens, or sensitive scan evidence.