Argus Scan
Privacy policy
Last updated: July 7, 2026
This policy describes how Argus Labs (“we”, “Argus Labs”) processes personal data in connection with the Argus Scan service at scan.argus-labs.fr.
1Purpose and data controller
Account data: Argus Labs is the controller. Emails you scan: you are responsible for the legal basis of your investigation; Argus Labs acts as a technical processor to forward the query to OSINT services and return results, without long-term storage of the scanned email in our database.
Argus Labs is the data controller for account and billing data. For privacy inquiries: [email protected] or [email protected].
2Data we collect
Account and authentication
- Email address, display name, profile picture (if provided via Google OAuth when enabled)
- Login sessions: IP address, user-agent, session tokens
- Magic link verification tokens (temporary)
Subscription and billing
- Lemon Squeezy identifiers (customer, subscription, variant), subscription status, tier (Investigator, Pro), period end date
- Payment details (card, etc.) are processed solely by Lemon Squeezy as Merchant of Record — Argus Labs does not store your payment credentials
Service usage and quotas
- Monthly and daily scan counters (per user account, IP hash and/or hashed visitor identifier)
- Anonymized usage logs: tier, scan type, duration, IP hash — scanned emails are not stored
- Pro API keys: visible prefix, hashed fingerprint, last used date
Technical and anti-abuse data
- Hashed IP address (HMAC salt) for rate limiting and quotas
- Visitor identifier (FingerprintJS in browser, hashed server-side) to limit anonymous bypass attempts
- Lemon Squeezy webhook events (event id, payload hash) for idempotency
3Data we do not retain
By design, Argus Scan does not store submitted scan email addresses or raw investigation results in our database.
Emails and queries are forwarded in real time to our OSINT partner APIs to produce results displayed in your browser. A temporary cache (Smart Cache, up to 72 hours) may exist on external OSINT infrastructure, as stated on the service homepage.
4Purposes and legal bases
- Contract performance: account creation, authentication, scans, quota management, Pro API access
- Legitimate interest: security, abuse prevention, rate limiting, service improvement, aggregated analytics without advertising profiling
- Legal obligation: billing records via Lemon Squeezy
- Consent: where required for optional communications (not applicable to essential transactional emails)
6Analytics
We use Umami Analytics, self-hosted at analytics.argus-labs.fr (servers in France). Umami is configured to limit collection: no third-party advertising cookies, no data resale, no Google Analytics or Facebook Pixel.
Measured events are aggregated (clicks, scans started, errors) without building advertising profiles.
7Subprocessors and recipients
We do not sell or rent your data. We rely on the following subprocessors:
- OVHcloud (France) — application hosting, PostgreSQL, Redis, Coolify infrastructure
- Lemon Squeezy (USA/UK) — payments, subscriptions, billing (Merchant of Record)
- Resend (USA) — transactional email (magic sign-in links)
- External OSINT API — scan query processing (email transmitted for search)
- GitINT — GitHub OSINT enrichment (GitHub username)
- Enzoic — breach count check for an email (Member tier and above)
- cap.js (self-hosted) — proof-of-work anti-bot, no advertising profiling
8Retention periods
- Account data: while the account is active, then deleted within 30 days after deletion request (unless legally required to retain)
- Expired sessions: automatic deletion
- Redis quotas: expire at end of month or day depending on counter
- Usage logs: kept for account statistics, without scanned emails
- Lemon Squeezy billing data: per Merchant of Record legal obligations (up to 10 years for accounting)
9Security
We implement appropriate technical and organizational measures: TLS in transit, hashed IP and visitor identifiers, API keys stored hashed/encrypted, rate limiting, CAPTCHA for free tiers.
No system is perfect; if an incident affects your personal data, we will follow the notification obligations below.
10Transfers outside the European Union
Some subprocessors (Lemon Squeezy, Resend) may process data outside the EU. We ensure appropriate safeguards (EU Standard Contractual Clauses or equivalent mechanisms).
11Your rights (GDPR)
Under the GDPR, you have rights of access, rectification, erasure, restriction, objection, and portability regarding your account data.
To exercise your rights: [email protected]. We respond within 30 days.
You may also lodge a complaint with the CNIL.
12Data breach notification
- Notification to the CNIL within 72 hours if the breach is likely to pose a risk to rights and freedoms
- Notification to affected individuals without undue delay when risk is high
- Internal documentation of the incident and remedial measures
13Minors
The service is intended for users aged 18 or older, or minors using the service under parental or legal guardian supervision who has accepted these terms.
14Changes
We may update this policy. Material changes will be brought to your attention by appropriate means (site notice or email for registered accounts).