Privacy Policy
Effective Date: January 2026
This Privacy Policy describes how Marshal Code ("we," "us," or "our") collects, uses, and protects your information when you use Site X-Ray. We are committed to protecting your privacy and being transparent about our data practices.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address - Used for account identification, login, and communication
- Password - Stored securely using bcrypt hashing (we never store plain text passwords)
- Two-factor authentication data - TOTP secret for enhanced security
1.2 Analysis Data
When you analyze a website, we capture and store:
| Data Type | Purpose |
|---|---|
| URL/Domain | Identify the analyzed page |
| Page HTML structure | Technical analysis and AI brief generation |
| Detected technologies | Framework and library identification |
| DOM metrics | Performance and complexity scoring |
| API endpoints discovered | Technical architecture analysis |
| CSS and styling information | Design system analysis |
| UI interactions detected | Functionality mapping |
1.3 Usage Data
We automatically collect:
- Timestamps of analyses performed
- Session information for authentication
- Basic server logs (IP address, browser type) for security and troubleshooting
2. How We Use Your Information
We use your information to:
- Provide the service - Store and display your analyses, generate AI briefs
- Authenticate you - Verify your identity via password and 2FA
- Improve the service - Understand usage patterns to enhance features
- Communicate with you - Send password reset emails and important service updates
- Ensure security - Detect and prevent unauthorized access or abuse
3. AI Processing
When you use the "Generate AI Brief" feature:
- Your captured analysis data is sent to Google's Gemini AI for processing
- The AI generates development recommendations based on the captured data
- We do not use your analysis data to train AI models
- AI-generated briefs are stored in your account for your reference
Google's AI services are subject to Google's own privacy policies. We recommend reviewing Google's Privacy Policy for more information.
4. Data Storage and Security
4.1 Where We Store Data
Your data is stored on secure servers provided by Replit and their infrastructure partners. Database storage is provided by Neon (PostgreSQL).
4.2 Security Measures
We implement industry-standard security measures including:
- Password hashing using bcrypt
- Two-factor authentication (TOTP)
- HTTPS encryption for all data transmission
- Secure session management
- Token-based bookmarklet authentication
5. Data Retention
We retain your data as follows:
- Account data - Retained while your account is active
- Analysis data - Retained until you delete it or close your account
- Server logs - Retained for up to 90 days for security purposes
6. Your Rights
You have the right to:
- Access - View all analyses stored in your account
- Delete - Remove individual analyses or request full account deletion
- Export - Download your analysis data
- Correct - Update your account information
To exercise these rights, contact us at team@chasemarshal.com.
7. Third-Party Services
We use the following third-party services:
- Replit - Application hosting
- Neon - PostgreSQL database hosting
- Google Gemini - AI brief generation
- Brevo - Email delivery (password reset emails)
Each of these services has their own privacy policies governing their data practices.
8. Cookies and Sessions
We use session cookies to:
- Keep you logged in
- Maintain your 2FA verification status
- Remember your preferences
We do not use tracking cookies or third-party advertising cookies.
9. Children's Privacy
Site X-Ray is not intended for users under 18 years of age. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website. Your continued use of Site X-Ray after changes become effective constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
Marshal Code
Email: team@chasemarshal.com