Legal
Privacy Policy
1. Controller
Julian Wessels Herbergsweg 3 26904 Börger Germany Email: info@malwarebuster.live
2. Account and sign-in
We use Firebase Authentication for sign-in. This processes your email address, an encrypted password hash, an internal identifier and sign-in timestamps.
A scan is possible without an account; an anonymous session is created that holds no email address. An account is required for changing files and for the AI analysis.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
3. What a scan processes
Stored are: the address of the installation checked, file paths, SHA-256 checksums, file sizes and modification times, the platform detected and its version, the list of installed extensions with versions, and the report produced.
Not stored are file contents, database contents and credentials. The bridge file reads the credentials from your installation's configuration file locally on your server only, in order to determine the extension inventory; they are not transmitted.
Licence keys for commercial extensions are used when your installation has one stored. They are necessary in order to check such extensions at all: the vendor only serves the original package to a valid key, and without that package there is no way to establish whether the installed files were altered. The key is sent solely to the respective vendor's own update address, held in memory for the duration of the download and not stored; it is stripped from every address kept permanently. The report states for how many extensions a key was used. The legal basis is Art. 6(1)(b) GDPR: the download is part of the check you commissioned.
Legal basis: Art. 6(1)(b) GDPR.
4. AI analysis and transfer of file contents
If you use the AI analysis, the contents of the files previously flagged as suspicious are transmitted to OpenRouter Inc. (USA) and forwarded from there to the respective model provider. Only a limited excerpt of the files concerned is transmitted, at most 25 files per scan.
File contents may contain personal data where your installation places such data in files. This stage is therefore expressly optional and runs only when you trigger it.
A transfer to a third country takes place. We base it on your consent under Art. 49(1)(a) GDPR in conjunction with Art. 6(1)(a) GDPR. Without the AI analysis, no file contents leave your server.
5. Documentation of approvals
Before files are changed we obtain your confirmation. Documented are your identifier and email address, the time, the language, the version identifier of the notice text shown together with its checksum, and your browser identifier.
Each individual change is logged as well: action, path, time, outcome and backup path. Failed attempts are recorded too.
Legal basis: Art. 6(1)(f) GDPR (evidence of approvals given) and Art. 6(1)(b) GDPR.
6. Hosting and storage location
The application runs on Firebase App Hosting, with data held in Cloud Firestore. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Firestore database is located in the “eur3” multi-region within the European Union. Operating the application may technically produce server logs containing IP address, time and the address requested; access from servers in third countries cannot be entirely ruled out with Google services and is based on the Standard Contractual Clauses.
Legal basis: Art. 6(1)(b) and (f) GDPR.
7. Requests to third parties
To compare original files, our server retrieves official releases — for instance from downloads.joomla.org, wordpress.org, api.wordpress.org, GitHub or the respective vendor's update server. The name and version of the extension are transmitted; no data about you or your installation.
The checksums produced are stored independently of any user, so the same version does not have to be downloaded again for every scan.
8. Retention
Scan data and reports remain stored until you delete them. Deleting a scan or your account removes the associated data. Scans made without an account are deleted automatically 90 days after they were created.
Logs of approvals belong to their scan and are deleted together with it.
User-independent checksums of official releases contain no personal data and remain stored permanently.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).
Consent you have given — for instance to the AI analysis — can be withdrawn at any time with effect for the future.
You may lodge a complaint with a supervisory authority, for example the State Commissioner for Data Protection of Lower Saxony. For enquiries please contact info@malwarebuster.live.
10. Cookies, local storage and audience measurement
We use no cookies for analytics or advertising. Technically necessary are: a cookie storing your chosen language, and the local storage of your sign-in session by Firebase Authentication.
To measure reach we count on the server how often a page was requested. All that is stored is a counter per page and day. No cookie is set, no identifier is assigned and no IP address is stored; individual requests are not logged and cannot be attributed to you or to your device. Because this counting neither stores nor reads any data on your device, § 25 TDDDG does not apply to it.
Legal basis: § 25(2)(2) TDDDG (strictly necessary) for the cookies named above; Art. 6(1)(f) GDPR (legitimate interest in designing our service to meet demand) for the aggregate audience measurement.
Last updated: 14 September 2026