Privacy Policy
External Recon Labs LLC ("External Recon", "we") operates this platform from the Commonwealth of Pennsylvania, United States. This policy explains what we collect, why we collect it, how long we keep it, and how to have it removed. Questions or requests: support@externalreconlabs.com.
1. What we collect
- Your account email address and the verified email domain derived from it.
- Your acceptance of the Terms of Service, including version and timestamp.
- Any organization profile you choose to enter (legal name, authorized domains, brands).
- The domains and targets you submit for assessment.
- Scan results, findings, reports and any monitoring history generated for you.
- Per-scan audit records: initiating account, IP address, user agent, action taken and timestamp.
2. Why we collect it
To run and attribute scans, enforce free-tier limits and authorized-target rules, detect and investigate abuse, deliver paid reports and monitoring, and meet our legal obligations. We do not use your data to train advertising profiles.
3. Passive collection only
Findings are assembled from publicly available records and licensed third-party intelligence sources. We do not send intrusive, exploitative or high-volume traffic to your infrastructure as part of an assessment.
4. Retention
- One-time baseline audit reports are retained for 30 days from delivery, then deleted.
- Subscription customers' data is retained for the life of the subscription and removed 30 days after the plan ends or is cancelled.
- Abuse and audit records (scan attribution logs) are retained as long as necessary for abuse investigation, dispute resolution and legal compliance, independent of report retention.
5. Your rights
You may request access to, a copy of, correction of, or deletion of your personal data by emailing support@externalreconlabs.com. We respond within 30 days. Deleting your account removes your profile, organization profile and reports subject to the retention rules above.
6. Service providers and payment
We rely on a small number of processors acting on our behalf: cloud hosting and database providers, commercial and open intelligence data providers used to compile findings, and an email delivery provider used for account and report notifications. These providers process data only as needed to deliver the service.
Purchases are sold through Paddle.com, which acts as Merchant of Record for our orders. When you buy a report, add-on or monitoring subscription, Paddle collects and processes your billing details, payment method and tax location as an independent controller for payment, invoicing, fraud prevention and tax compliance, and shares the order reference and email address with us so we can deliver what you bought. We never receive or store your card details. We may also share data with professional advisers and with authorities where required by law.
7. Email
We send operational email tied to your activity: account and authentication messages, notice that a scan or monitoring run has completed, and replies to enhancement requests you submit. We do not send marketing campaigns or sell your address.
8. Cookies and analytics
We use only the cookies and local storage required to keep you signed in and preserve your in-progress inputs. We do not run advertising or cross-site tracking.
9. Sale of data
We do not sell or rent personal data to third parties.
10. Security
Access to reports is restricted to the owning account and platform operators. Administrative actions require multi-factor authentication. Report a security concern to support@externalreconlabs.com.
11. Changes
We version this policy. Material changes are published here with a new version identifier and, where required, notified by email.
Effective date: version 2026-08-02. See also our Terms of Service.