data processing agreement

what we store, and what we never touch.

A short agreement, in plain language, for what happens when you connect Stripe and your app database to Entitled. This describes the actual data flow, see the security page for the technical constraints that enforce it.

What is processed

Only what is needed to compare who paid against who has access:

What is not processed

Where it runs

Everything runs on one server in Frankfurt, Germany (DigitalOcean's fra1 region). The web app, the worker that reads your data, and the database all sit on that machine, inside the EU. Every read of your database comes from 161.35.64.36, so you can restrict access to that single address.

Site analytics

Visits to this site are counted with Umami, running on the same Frankfurt server. No third party receives them, so it is not a subprocessor. It sets no cookies. Before anything is recorded, report ids and the tokens in claim and unsubscribe links are removed from the address, and query strings are dropped. Events carry a name and at most the plan bought, never an email address, a customer id, or anything read from Stripe or your app.

Retention

Each run overwrites the previous read of Stripe and of your app; we don’t keep a history of every past read, only the latest one. An open disagreement is kept for as long as it stays open: a current disagreement is current information, however old it is. Once a finding is resolved, it and the log of events that led to it are deleted after the plan’s history window: there is nothing to delete on the free scan (a single run keeps no history to begin with), 7 days on the audit, and 365 days on Watch. A cleanup runs automatically once a day and removes anything past its window; you never need to trigger it yourself.

Deletion on disconnect

Deleting a report from its page deletes the sealed credentials, the snapshot, and every finding and its history at once, immediately, nothing held back for later. We never held payment methods to begin with, so there is nothing further to purge there.

Subprocessors

Stripe

Source of billing and subscription data, read via a restricted key you create and can revoke.

Resend

Transactional email: the claim link that gets you back to your report, and Watch alerts and weekly summaries.

Polar

Payment processing for the $49 audit and the $99/year Watch subscription. Polar is the merchant of record; we never see card details.

DigitalOcean

Hosting. Runs the web app, the worker that executes scans, and the database, on one server in Frankfurt (fra1), Germany. The worker holds the master decryption key; the web app does not.

Read the security pageRun a free scan