Privacy Statement
What we collect through the Atomic App Scanner, why we collect it, and the rights you have over it.
Last updated: 22 July 2026
Atomic Security (“we”, “us”) is a sole proprietorship (eenmanszaak) registered in the Netherlands, and the data controller for personal data processed through the Atomic App Scanner service (“Atomic Scanner”, the “Service”). This statement explains what we collect, why, and how to exercise your rights under the General Data Protection Regulation (GDPR / AVG).
Who we are
- Atomic Security — Keizersgracht 520H, 1017 EK Amsterdam, Netherlands
- KVK: 96494190
- BTW-id: NL005213092B78
- Contact: [email protected]
What we collect
Account data. When you sign up we store your email address and a one-way hash of your password (argon2id — we never store the password itself), together with the workspace and role your account belongs to. We use this to authenticate you and operate your account.
Applications you upload. To run a scan you upload an Android application package (APK). We store the file and the results it produces so you can review them. Each file is analysed in an isolated, network-isolated sandbox and is used only to generate your report — never shared, sold, or used to train anything.
Scan results. The findings we produce from your uploads, retained under your account so you can revisit and export them.
Billing data. If you buy a scan or a subscription, our payment processor (Stripe) handles your card details — we never see or store your full card number. We keep a record of your purchases, plan, and credit balance to run billing.
Session data. We set a strictly-necessary, HTTP-only session cookie and a CSRF cookie to keep you signed in and protect our forms. These are not used for tracking or advertising.
Technical data. The Service runs on servers in Germany (EEA) and is delivered through Cloudflare’s content-delivery and edge-protection network. To route and protect each request, Cloudflare processes standard request data on our behalf — including your IP address, browser user-agent, and the time of each request.
For basic, privacy-respecting traffic measurement we use Cloudflare Web Analytics — a cookieless tool that reports aggregate metrics (such as page views, referrers, and country) without cookies, cross-site tracking, or device fingerprinting. We do not use advertising, profiling, or ad-tech analytics, and we set no tracking cookies. Because we place only strictly necessary cookies, there is no cookie-consent banner.
Why we’re allowed to (legal basis)
- Providing the Service — to perform our agreement with you (Art. 6(1)(b) GDPR): running scans, managing your account, and billing.
- Securing the Service — our legitimate interest in a functioning, protected platform (Art. 6(1)(f) GDPR).
- Legal obligations — keeping invoices and tax records where the law requires it (Art. 6(1)(c) GDPR).
Who we share it with
We do not sell your data or share it for marketing. We rely on the following processors:
- Hetzner Online GmbH — cloud hosting in Germany (EEA) for our application servers and database (accounts, scan results, and billing records), under a data-processing agreement.
- Cloudflare, Inc. — content delivery, edge protection, and object storage (R2) for uploaded applications and scan artifacts, under a data-processing agreement.
- Stripe, Inc. — payment processing, under its own controller/processor terms.
- Resend (Plus Five Five, Inc.) — transactional email delivery (account verification, password reset, and scan notifications), under a data-processing agreement.
Our application servers and database are located in the EEA (Germany). Some processors — notably Stripe, Resend, and Cloudflare’s global edge network — may involve transfer to servers outside the EEA (for example, the United States), covered by appropriate safeguards such as the EU Standard Contractual Clauses. We may also disclose data where we are legally required to.
How long we keep it
We keep your account, the applications you upload, and their scan results for as long as your account is active. You can delete uploads and results at any time, and we remove your data a reasonable period after you close your account, unless a longer period is required by law. Invoices and other billing records are kept for as long as tax law requires. Technical logs held by Cloudflare are retained only for short operational and security periods.
Your rights
Under the GDPR you can ask us to give you access to, correct, delete, restrict, or hand over your personal data, and you can object to processing based on legitimate interest. To do any of these, email [email protected].
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Changes to this statement
We may update this statement as our practices or the law change. The date at the top shows when it was last revised.