Trust Center / Privacy
Privacy Policy
We don't want your data. We store only what is necessary:
| Activity | Whose data | Data | Purpose and basis | Kept |
|---|---|---|---|---|
| Accounts | Customers' team members | OAuth subject identifier and username or email, from your sign-in provider (such as GitHub or Google) | Sign-in and team management, on our customers' behalf under our DPA | Until 30 days after you leave |
| API requests | API callers | IP address and user agent, never logged or passed on | Answer and secure requests: for customers, on their behalf under our DPA; otherwise legitimate interest | Not kept |
| Usage | Customers | Request counts per org | Quotas and billing; contract | 90 days |
| Billing | Paying customers | Name, email, address, card—held by Stripe | Payment; contract, legal obligation | As tax law requires |
| Verdicts | No one | Artifacts asked about, and their verdicts | Public malware research; legitimate interest | Indefinitely |
| Uploads | Anyone named in an uploaded file | Whatever the file contains | Public malware research; legitimate interest | Indefinitely |
| Correspondence | Anyone who writes to us | Email address and message | Answer you; legitimate interest | As long as needed |
Uploads are public, like VirusTotal: anyone may download them, we share them with the security community. Our models train on them, and only on public data. Our Data Protection Impact Assessment explains why this is fair.
We never sell your data, never name you as a customer without written permission, and never share it beyond our Approved Subprocessors, which lists who handles what. Everything is processed in the US, after the nearest Cloudflare edge cache handles each request; transfers from customers use the EU Standard Contractual Clauses. Our only cookies keep you signed in. No automated decisions are made about you. We sign our DPA on request.
You may access, correct, export, delete, or restrict your data, or object to its use. We redact personal data from uploads on request. Requests about a customer's account or API calls go to that customer. You may also complain to your data protection authority.
The controller is isotope13 LLC, 109 Amber Ct, Carrboro, NC 27510, USA. Privacy contact: Thomas Stromberg, trust(@)isotope13.io