Legal

Privacy Policy

Last updated 3 August 2026

Information we collect

Account information. When you create an organization we store your name, email address, and organization details. Authentication is handled by our identity provider; we do not store your password.

Detection data. Agents you deploy send security events generated when one of your honeypots is interacted with. These events contain identifiers from your environment, such as account names, security identifiers, hostnames, and source addresses.

Billing information. Payments are processed by our payment provider. We store subscription state and plan tier; we do not store card numbers.

Service logs. We log API requests and platform activity for security, debugging, and abuse prevention.

How we use information

We use it to operate the service: authenticating you, delivering alerts, showing your detection history, enforcing plan limits, billing your subscription, and investigating security or reliability problems. We do not sell personal information, and we do not use your detection data to advertise to you.

Tenant isolation

Each customer's data is isolated at the database level with row-level security. Where a managed service provider administers multiple customer tenants, that separation is preserved — the management layer is additive and does not merge tenant data.

Retention

Detection events are retained according to your plan. Deleting your organization removes its data from active systems; backups age out on their own schedule.

Subprocessors

We rely on third parties for cloud hosting, authentication, payments, and email delivery. They process data only as needed to provide those functions.

Your rights

You may request access to, correction of, or deletion of your personal information, and an export of your organization's data. Contact us and we will respond within the period required by applicable law.

Contact

Questions about this policy: contact@claymorelabs.io