Offscript
Privacy

Privacy policy

Offscript is built to detect browser malware with as little data as possible. This page describes what we collect, why, how long we keep it, and who processes it on our behalf.

What we collect, and why

CSP violation reports: when a customer points an app's Content Security Policy reporting directive at an Offscript route, browsers loading that app send us violation reports. For each report we store the raw CSP payload, its content type, the reporting browser's IP address, and a received-at timestamp, plus any detections that result from analyzing it. We intentionally do not store the request headers of reporting browsers.

Account data: signing in is handled by Clerk, our authentication provider. We keep the organization name, the signed-in member's email address, and the organization identifiers needed to route data to the right tenant.

Contact messages: details submitted through our contact form (name, email address, message) are used only to answer your message.

What we never collect

We only receive CSP violation reports generated by our customers' own apps — essentially the address of a script or connection a browser blocked. We never see browsing history, page contents, form data, or keystrokes, and nothing about what people do on other sites. Offscript is not an employee-monitoring tool, and we do not sell or rent any data we process.

Retention

Raw CSP violation reports and their associated reporter IP addresses are automatically purged after 30 days. Detection records are retained so your dashboard and webhook history remain useful. Account data is kept for as long as the account exists.

Where data lives, and who processes it

Report data is stored in a managed Postgres database hosted on Supabase in the us-east-1 region, reaches us over encrypted HTTPS connections, and is encrypted at rest. We use a small set of subprocessors to run the service: Clerk (authentication), Supabase (database hosting), Vercel (website hosting), and Google Cloud (report ingestion and analysis). Blocked URLs extracted from CSP reports are shared with threat-intelligence providers solely to classify them as malicious or benign; no customer or reporter identity accompanies those lookups.

Your choices and how to reach us

Customers control which apps report to Offscript and can stop at any time by removing the reporting directive from their Content Security Policy. To ask about the data we hold, request deletion, or raise any privacy question, reach us through the contact page and we will respond, usually within one business day.

Questions about anything on this page? Get in touch.