1. What this is, and isn't
This policy describes what data takedowns collects when you use takedowns.vesamuni.com, the takedowns web app, and related services. It is written in plain English because the people who need to read it most are often the people with the least patience for legalese.
takedowns is operated by Vesamuni Cybersecurity ("we", "us", "our"). If you have questions about anything in this document, email our team and a human will reply.
2. What we collect
Account data. Email address, display name, and password hash. You must verify control of your email before using the workspace. We also use privacy-preserving network signals to limit abusive duplicate account creation.
Case and review data. The fingerprints, URLs, metadata, reference images, selected video frames, and page screenshots needed to check and review a case. When you upload media or ask us to scan it, a restricted copy may be held for human review for no longer than seven days.
Free check on the home page. The anonymous check runs one search of public sources for the name you enter. We store the name, the profile link, a truncated network identifier, and the count of likely matches for seven days, so the same name is not searched again and abuse can be traced; the row is then deleted automatically. The result you see is a count of pages and sites, never a list of links, and nothing is published or shared.
Weekly leak alerts. If you ask for alerts after a free check, we keep your email address, the name and profile link you checked, and the latest counts until you stop the alerts. Nothing is sent until you confirm from your inbox. Once a week we re-run the same public check and email you only if the number of likely matches has gone up; every email has a one-click stop link, and stopping deletes the record.
Dispatch data. Recipients, timestamps, and notice bodies for every takedown we send on your behalf.
Payment data. Processed by Stripe. We never see your card number. We store only the last four digits, the card brand, and the billing email you used.
Operational telemetry. Server logs (IP address truncated to /24, user agent, request path, status code) retained for 30 days for security and debugging.
3. What we do not collect
We do not collect biometric data. We do not sell your data to third parties. We do not run third-party advertising trackers. We do not fingerprint your device for cross-site tracking.
4. How we use what we collect
- To deliver the service you signed up for (case management, scans, dispatch, monitoring).
- To let authorised reviewers confirm findings, reduce false reports, and investigate abuse.
- To send you service-critical email: account verification, dispatch confirmations, security alerts.
- To send you product email you can opt out of at any time (release notes, tips).
- To respond to lawful legal process. See our trust and security overview for how we handle these requests.
5. How long we keep it
Temporary reference images, selected video frames, and page screenshots are automatically deleted no later than seven days after collection. Case records and derived fingerprints live until you delete the case. Account data is purged within 30 days after account deletion. Dispatch records live for the life of the case plus 7 years because they may be needed as evidence. Server logs auto-purge after 30 days. Financial records (transaction IDs, amounts, billing email) are kept for 7 years for tax compliance.
6. Your rights
You can export everything we have on you from the dashboard at any time. You can delete your account, your cases, and your fingerprints with a single click. You can request an immediate hard delete that bypasses the 30-day grace window. If you are in the EEA, UK, or California, you have additional statutory rights we honour globally: access, rectification, restriction, portability, and objection.
7. Where your data lives
Application data is hosted in Singapore and Frankfurt, with backups in a second region. Payment processing happens in Stripe's PCI-DSS Level 1 infrastructure. Email delivery is handled by a transactional email provider; we never put case content in the body of an email.
8. Children
takedowns is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it within 24 hours.
9. Changes to this policy
If we make a material change, we email you at least 30 days in advance and show a banner on the dashboard. Non-material changes (typo fixes, contact email updates) do not get a banner.
10. Contact
Email our team or write to Vesamuni Cybersecurity, Sri Lanka. The data controller is Vesamuni Cybersecurity, reachable at the same address.