This policy describes how Resku processes your personal data when you use the resku.fr website, the browser extension, or our related services.
1. Data controller
2. Data we collect
Each page is analyzed first inside your browser. To produce the score, the extension sends our API a limited set of signals : detailed below. We never transmit the full HTML of your pages, the text you type, or your session cookies.
- Waitlist: email address, chosen plan (Free, Pro or Team), sign-up date.
- Page analysis (extension): the URL and domain visited, the page title, and structural detection signals (presence of a password or bank-card field, favicon fingerprint, technical DOM characteristics, redirects). These are used solely to compute the security score.
- Server-side AI visual brand-impersonation detection (paid Pro subscription only): a screenshot of the visible area of the page may be sent to our API to compare it with known phishing kits. Not included in the Free plan. This feature only activates after you accept the privacy policy.
- Password-reuse protection: to alert you if you enter the password of a real site on a clone, the extension keeps a cryptographic fingerprint (irreversible hash) of your passwords, only in your browser. The password itself is never stored or transmitted.
- Installation identifier: an anonymous technical identifier is generated to authenticate your extension's requests to our API. It is not tied to your identity.
- Reports: when you report a site or dispute a verdict, we record the URL, domain, the displayed verdict, and your IP address and browser type (to prevent abuse).
- Payment (Pro/Team plans): billing data is processed by our payment provider; Resku does not store your card details.
3. Purposes and legal bases
- Waitlist management : consent (checkbox or sign-up action).
- Security analysis of pages and score computation : performance of the contract (providing the service) and legitimate interest (protecting you from fraud).
- Password-reuse protection (local processing) : legitimate interest (security), without transmission to our servers.
- Handling reports and improving detection rules : legitimate interest (service quality and security).
- Subscription billing : performance of the contract.
4. Processors
- Payment provider : billing for paid subscriptions.
- Email provider : transactional messages (waitlist).
5. Retention periods
- Waitlist: 12 months maximum after sign-up, unless earlier deletion is requested (email to [email protected], subject “Waitlist : deletion”).
- Analysis signals sent to the API: cached temporarily (under 24h) to avoid re-analyzing the same page, then deleted or anonymized. The page screenshot (Pro) is used only for the duration of the analysis and is not retained.
- Reports: kept for the time needed to process the report and improve detection rules, then anonymized.
- Local processing (password fingerprints): stored only in your browser; deleted when you uninstall the extension or clear your browser data.
- Account and billing: duration of the contractual relationship plus legal obligations (accounting).
6. Your rights
Under the GDPR, you have the rights of access, rectification, erasure, objection, restriction and portability. To exercise your rights: [email protected]. Response within 30 days.
You may lodge a complaint with the CNIL: https://www.cnil.fr
7. Transfers outside the European Union
We prefer providers located in the European Union. If a processor handles data outside the EU, we ensure appropriate safeguards (standard contractual clauses or an adequacy decision).
8. Cookies
For details of the trackers used, see our cookie policy (/en/cookies).
9. Contact
This document does not replace tailored legal advice. A professional review is recommended before billing at scale.