Privacy Policy

Last updated 9 October 2026

Overview

Previdian ("we", "us") operates this website, a known exploited vulnerability intelligence service. This policy describes how we collect and use personal data when you use the website, when we measure site usage through analytics, and when we send account or Watch notification email.

Analytics and Cookies

We use Google Analytics 4 (GA4) to understand how visitors use this website — for example, which pages are viewed, how users navigate the site, and which browsers and devices are used. GA4 is provided by Google and loads via Google Tag (gtag.js).

When you visit the site, GA4 may set first-party cookies (such as _ga and _ga_*) and similar identifiers in your browser. Google may also receive your IP address, which it typically uses to derive approximate location before storage. We use this information only to measure usage, improve the service, and understand how our content and product pages perform.

We use PostHog to measure page views and product actions, including signup, sign-in, feature use, first successful API or RSS use, and billing. The browser snippet sets a first-party ph_ cookie and uses local storage. Signed-in use is tied to your account id, plan, and whether the account is an admin. The server also stores your email address and name on the PostHog person profile. PostHog may receive your IP address and browser details. We record sessions on the public site and in the account workspace. The login page is not recorded. Confirmation and password-reset links are not recorded, because those links contain a one-time token. Typed input is masked, and automatic capture of clicks stays off.

We do not send passwords, API tokens, RSS subscribe URLs, webhook signing secrets, Slack webhook URLs, or contact-form message bodies to PostHog. Those values are left out of session recordings. We do not use GA4 to collect passwords, API tokens, or other account credentials.

Email

Previdian sends transactional email only. We do not operate a marketing newsletter.

  • Account email. Confirmation, password reset, signup help, and similar messages needed to operate your account. These are delivered via Postmark.
  • Watch notifications. Early-warning emails when a vendor, product, or vulnerability you follow matches a Watch signal (or when you enable notifications for every new KEV). These are managed from Watch in your account and include an unsubscribe link in each email.

Postmark processes these transactional messages on our behalf.

Website Usage

Separately from analytics cookies, standard web server and application logs may record your IP address, browser type, requested pages, and timestamps for security, abuse prevention, and service reliability. Pro API access is authenticated via API tokens associated with registered accounts.

Data Sharing

We do not sell personal data. We share data only with service providers needed to operate the service, including hosting, email delivery, and Google and PostHog for website analytics, and when required by law.

Google processes analytics data on our behalf under its own terms. See Google's Privacy Policy and Google Analytics terms for how Google handles that data. PostHog processes analytics data on our behalf. See PostHog's privacy policy.

Your Rights

Depending on your location, you may have rights to access, correct, or delete personal data we hold about you. For Watch notifications, you can unsubscribe via the link in any notification or from Watch settings in your account.

You can limit analytics tracking by blocking or deleting cookies in your browser settings, or by using a browser extension such as the Google Analytics Opt-out Browser Add-on. Blocking cookies limits the PostHog browser snippet and Google Analytics. Account events sent by our servers, including signup, billing, and API and RSS use, still run for a signed-in account. Contact us at [email protected] with privacy requests.

Contact

Questions about this policy: [email protected].