Legal
Last updated: 21 September 2026
When you create a Rakshak account, we collect your name, email address and authentication details via Supabase Auth. When a website you connect sends traffic to Rakshak, we collect visitor IP addresses, approximate location (country and city, taken from location headers added by the hosting platform, not from a third-party lookup), user agent strings, requested URLs and timestamps.
This data is used to power your dashboard: showing live traffic, detecting suspicious behaviour such as DDoS, scanning, brute-force attempts, SQL injection, XSS and bot activity, generating alerts, and letting you block or unblock IP addresses on websites you monitor.
Data only reaches Rakshak when a website you control sends it to our ingest endpoint using the tracking script or server middleware provided in your dashboard, authenticated with a key that belongs to your website (a public browser key for the tracking script, or a private secret for the server middleware). We do not scan or collect data from websites that have not been connected by their owner.
All data is stored in Supabase (Postgres) with Row Level Security enabled, so each account can only see data belonging to websites it owns. Sensitive account actions, such as changing a password or deleting a website, are checked on our servers and require you to re-enter your password. Keep your secret key private, and regenerate your keys from Settings if you think one has been exposed.
We use Supabase for the database and sign-in, Vercel for hosting, Cloudflare Turnstile to protect sign-in from bots, and the Gemini API to power the in-app assistant. The assistant only receives your question and a short summary of the screen you are on (counts and alert types), never raw visitor logs. Visitor IP addresses are not sent to any location-lookup service. None of these providers are used for advertising.
On the Free plan, visitor logs, request logs, alerts and the history of unblocked IPs are kept for 7 days and then deleted automatically. On the Pro plan they are kept for 30 days and then deleted automatically. If a Pro plan ends, the longer history is kept for 3 more days so you can renew, after which the Free plan's 7-day limit applies. Currently blocked IP addresses stay on your blocklist until you unblock them. When you delete a website, all data stored for it is permanently deleted immediately. You may request deletion of your account and associated data at any time by contacting us on Telegram.
You control which website is connected to Rakshak. You can export your alerts as a CSV file (and, on Pro, a PDF report), regenerate your keys, permanently delete the website and all of its data from Settings, and stop future data collection at any time by removing the tracking snippet or middleware.
Rakshak uses only the minimal cookies/local storage required to keep you signed in. We do not use advertising or cross-site tracking cookies.
We may update this privacy policy from time to time. Material changes will be reflected here with an updated date.
Pro is paid for directly with the Rakshak team in a private Telegram chat. We do not collect card details and payments are not processed inside the app. The payment screenshot, transaction ID and account email you send us in that chat are used only to verify your payment and to switch Pro on for your account. The app stores the plan you are on and when it ends.
For privacy-related questions or data deletion requests, message us on Telegram at @rakshak_firewall_breaker.