Cenvian public trust
Privacy notice
This notice explains the information Cenvian currently processes to provide its V0.1 website checks, accounts, saved reports, and rechecks.
Last updated: August 11, 2026
Who is responsible
Cenvian is responsible for the service described in this notice. V0.1 provides public SEO checks, account authentication, website ownership verification, scans, reports, and rechecks. It does not include billing, browser rendering, continuous monitoring, or enterprise services.
Information Cenvian processes
The information depends on how you use the service:
- If you create an account, Cenvian stores the name and email you provide, authentication credentials managed by the account service, email verification and password-reset records, and sessions that can include IP address and user-agent facts.
- For saved websites, Cenvian stores organization membership, exact hostnames, ownership verification methods, verification digests, lifecycle times, and controlled verification-check facts.
- During a scan, Cenvian processes the submitted target and public response content. Persisted scan facts include the scan mode and status, discovered and sampled URLs, redirects, HTTP status and selected headers, content type, timing, robots and Sitemap facts, response byte counts and hashes when complete, parsed HTML facts and limited evidence, errors, and report facts. Full raw response bodies are not persisted in these scan facts.
- Short-term Redis state uses hashed identifiers derived from the trusted client IP for anonymous scan limits, the session user ID for signed-in scan limits, and the source IP and target email for verification and password-reset limits. Redis is also used for the recoverable queue and short-term coordination state.
Why Cenvian uses this information
Cenvian uses these facts to authenticate accounts, deliver verification and password-reset messages, confirm website ownership, run requested scans, produce and save reports, support stable-sample rechecks, enforce request limits, recover queued work, and protect the service and target websites. V0.1 has no billing or advertising feature.
Requests to websites
A requested scan sends identified HTTP GET requests to the submitted public website and, only when a current rule requires a status check, a limited external target. CenvianBot does not send your Cookie or Authorization data, does not log in, does not submit forms, and does not execute browser JavaScript in V0.1.
Current retention and backup boundaries
V0.1 retention cleanup is an explicit operator-run process measured against server time. Expired authentication verification records are deleted only after they have been expired for more than 7 days.
A terminal anonymous scan with no website scope is deleted after its finish time is more than 30 days old. A terminal scan with an account actor or website scope is deleted after its finish time is more than 90 days old. Terminal means completed, partial, failed, or cancelled; queued and running scans are not removed by this cleanup.
Database backup rotation keeps the latest 7 verified complete dump-and-manifest pairs. The rotation does not remove unknown files or incomplete or invalid pairs. A backup can contain account, authentication, scan, task, and report facts present in the database snapshot.
An operator can pause the manual retention command for a legal hold or an incident investigation. V0.1 does not include a separate hold database, approval system, or automated retention scheduler.
Account deletion
A signed-in user can delete the current account from the account view. If the user is the sole member of an organization, Cenvian first deletes that organization's scans and their task and report facts, then deletes the organization, its websites, verification facts, and memberships before deleting the user, accounts, and sessions.
For a shared organization, account deletion removes scans started by that user and the user's membership. Other members, the shared organization, its websites, and facts without that user as actor remain.
Password-reset records that identify the user are deleted in the same transaction. Custom email-verification records store a token digest that cannot be linked precisely to an account, so they remain until the expired-verification cleanup described above.
Privacy questions
For a question about this notice, the information used by Cenvian, or account deletion, email support@cenvian.com.