Privacy Policy
Last updated September 29, 2026
[YOUR BUSINESS NAME] ("we") makes PhantomLynk, a Windows app and website that help you find and fix privacy and security problems on your PC. We collect as little as we can. This policy explains what we collect, why, and your choices.
What stays on your PC
The scan runs entirely on your computer. File paths, program and extension names, network details, browser settings, Wi-Fi names and the files found by the cleanup tool never leave your PC. Your undo history and full scan details are stored only on your PC, in your Windows user profile.
What we collect
- Account: your email address, optional name, a one-way hash of your password (we can't read your password), two-step verification settings, and whether you opted into product news.
- Signed-in PCs: the computer name, Windows version, app version, and when each PC last connected. This lets you see and sign out your PCs.
- Scan summaries: your score, category scores, and for each check its ID, title, status (pass or fail) and severity. This powers your score history and syncing between PCs.
- Synced preferences: checks you chose to ignore, your scan schedule and notification choices.
- Breach monitoring (Pro): the email addresses you ask us to monitor, and the list of public breaches they appear in.
- Billing (Pro): handled by Stripe. We store your Stripe customer ID and subscription status. We never see or store your card number.
- Security log: sign-ins and account changes, with only the first half of your IP address (for example 203.0.x.x).
- Server logs: our host keeps standard web server logs, including IP addresses, for security and troubleshooting, for a limited time.
Services we use
- Stripe processes payments (stripe.com/privacy).
- Have I Been Pwned checks monitored email addresses against known breaches. We send it only the email address being checked.
- Password checker: the app turns your password into a SHA-1 hash on your PC and sends only the first 5 characters of that hash to the Pwned Passwords service (a method called k-anonymity). Neither we nor that service ever receive your password or its full hash.
- Winget (Microsoft's Windows Package Manager) runs on your PC to check for app updates.
- Our website loads fonts from Google Fonts and a QR-code script from Cloudflare's CDN. Both can see your IP address when they serve those files.
What we don't do
We don't sell or rent personal data. We don't use advertising or third-party tracking cookies. We use one essential cookie to keep you signed in.
How long we keep data
We keep account data until you delete your account. Each PC keeps up to its 200 most recent scan summaries. When you delete your account, we permanently erase your data from our database right away. Backups roll over within 30 days.
Your rights
From your account page you can download all your data, correct your name, and permanently delete your account. Depending on where you live (for example under the GDPR or CCPA), you may also have the right to object to or restrict processing, or to complain to a data protection authority. To use any of these rights, email support@phantomlynk.com.
Security
Passwords are hashed with bcrypt. Connections use HTTPS. App sign-ins use revocable per-PC tokens, and optional two-step verification protects your account.
Children
PhantomLynk is not directed at children under 13 (or under 16 in the EEA), and we don't knowingly collect their data.
Changes and contact
If we make meaningful changes, we'll email you before they take effect. Questions: support@phantomlynk.com.