Privacy Policy

Last updated 2026-07-14

1. Who we are

402.report is operated by Jan Heye, a sole trader based in Germany ("we", "us"). We are the data controller for the personal data described below. You can reach us about anything in this policy — including to exercise your rights — at hello@402.report.

Postal address: Am Heerbusch 20, 44894 Bochum. We have not appointed a Data Protection Officer as we are not required to.

2. Our role

For your account, billing and our own site, we are the controller. When you route requests through our proxy, we act as a processor on your behalf for the data those requests carry: we forward it to the destination you chose and only observe the payment activity. You remain the controller for any personal data of your own end users that you send through us, and you are responsible for having a lawful basis to do so (see our Terms).

3. What we collect, why, and our legal basis

  • Account data (email address, authentication records) — to create and secure your account. Basis: performance of our contract with you (Art. 6(1)(b) GDPR).
  • Wallet & on-chain identifiers (the wallet addresses and transaction signatures your agent uses) — to attribute and display spend. Basis: contract. Note that blockchain transactions are inherently public and are not under our control.
  • Usage & forensics events (the destination domains and resources you call, amounts, outcomes, and the paying wallet decoded from the payment header) — to provide the observability and debugging features that are the service. Basis: contract.
  • Billing data (customer and subscription identifiers held at our payment providers; invoices) — to take payment and meet tax record-keeping duties. Basis: contract and legal obligation (Art. 6(1)(c)). We do not store your full card number; that is handled by Stripe and PayPal.
  • Notification targets (email addresses or webhook URLs you add for alerts) — to deliver the alerts you configure. Basis: contract; email channels require your confirmation (consent) before we send.
  • Waitlist email — to notify you about launch if you sign up. Basis: consent (Art. 6(1)(a)); you can withdraw it at any time.
  • Abuse reports & attribution (a reporter's email if given, the opaque client identifier we stamp on forwarded requests, and IP addresses) — to keep the service safe and respond to misuse. Basis: our legitimate interest in preventing abuse and securing the service (Art. 6(1)(f)).
  • Server & security logs (IP address, timestamps, minimal request metadata) — for security, diagnostics and abuse prevention. Basis: legitimate interest. We minimise what we log and do not log request bodies for this purpose.
  • Cookies — see section 4.

4. Cookies & analytics

We use only strictly necessary cookies to run the site and keep you signed in; these do not require consent. Any analytics are privacy-friendly, aggregate, and off unless you opt in — never for advertising, and we never sell your data. You can review or change your choices any time via Cookie settings in the footer.

5. Who we share it with

We do not sell your data. We share it only with service providers who process it on our instructions under a data processing agreement:

  • Supabase — database, authentication and app data storage (Ireland, EU).
  • Amazon Web Services (SES) — transactional email (Frankfurt, EU).
  • Fly.io — proxy compute (London, United Kingdom — covered by an EU adequacy decision).
  • Vercel — website and dashboard hosting and CDN (United States).
  • Stripe — card payment processing.
  • PayPal — payment processing.

We may also disclose data where required by law or a valid legal request.

6. International transfers

Most processing happens in the EU/EEA. Some providers (Vercel, Stripe and PayPal) may process data in the United States. Where data leaves the EEA, the transfer is protected by the EU Standard Contractual Clauses and/or the provider's certification under the EU–US Data Privacy Framework. You can request a copy of the relevant safeguards from us.

7. How long we keep it

We keep account, usage and forensics data for as long as your account is active. When you delete your account we delete the associated data, except where we must retain it to meet a legal obligation (for example, billing and tax records, which we keep for the statutory period). IP addresses captured for spam triage (waitlist sign-ups, abuse reports) are erased automatically after 90 days. Security logs and abuse records are kept only as long as needed for those purposes. Residual copies in short-lived encrypted backups are removed as those backups rotate.

8. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time (without affecting prior processing).

You can exercise the two most important ones yourself, instantly: download a full copy of your data or permanently delete your account — both are in your account settings in the app. For anything else, email us at hello@402.report and we will respond within one month. You also have the right to lodge a complaint with your local data protection supervisory authority.

9. Automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

10. Changes

We may update this policy; the "last updated" date above always reflects the current version. Material changes will be communicated through the service.