Skip to main content
Legal

Privacy Policy

Last updated: August 2, 2026

Botscope ("we", "our", "us") provides bot detection and AI traffic analytics services. This policy describes what data we collect, how we use it, and your rights.

1

Data we collect

Account data

When you register, we collect your email address, name, and organisation name. If you sign in via Google OAuth, we receive your name, email, and profile picture from Google.

Traffic telemetry

Our agent running on your site sends us anonymised request metadata:

  • IP address (used for rDNS verification, not stored long-term)
  • User-Agent string
  • Request path and HTTP method
  • TLS fingerprint (JA3)
  • Decision outcome and reason code
  • Timestamp

We do NOT collect request or response bodies, cookies, authentication tokens, or any personally identifiable information about your end users.

Usage data

Standard server logs, dashboard usage, and feature interactions to improve the product.

2

How we use data

  • Provide and improve the bot detection service
  • Generate analytics dashboards for your account
  • Maintain and update the bot catalog
  • Send product and security notifications (you can opt out)
  • Comply with legal obligations

We do NOT sell your data or your users' data to third parties.

3

Data retention

Traffic telemetry is retained for 90 days by default on all plans. Account data is retained for the lifetime of your account plus 30 days after deletion. You can request earlier deletion at any time.

4

Data sharing

We share data only with:

  • Hosting infrastructure (cloud providers running our servers)
  • Aggregated abuse signals (an IP address or TLS fingerprint, never linked to your identity or your site) with other Botscope customers, and vice versa. This processing is currently disabled platform-wide; once active, each site can turn sharing off independently at any time in its protection settings ("Community reputation" under Core Engine).
  • Payment processors (for billing — we do not store card data)
  • Legal authorities when required by law
5

Security

All data is encrypted in transit (TLS 1.2+) and at rest. API keys are hashed. We conduct regular security reviews and follow responsible disclosure practices.

6

Your rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to access, correct, export, or delete your data. To exercise any of these rights, email us at [email protected].

7

Cookies

The Botscope dashboard uses a single session cookie for authentication. We do not use tracking or advertising cookies. Our agent does not set cookies on your visitors' browsers by default (the session token is optional and configurable).

8

Changes to this policy

We'll notify registered users by email of any material changes. Continued use of the service after notification constitutes acceptance.

Privacy questions?

We respond within 2 business days.

[email protected]