Last Updated: January 2026
Summary: We collect only what's necessary to provide our scanning service. We don't sell your data. Your uploaded files are scanned only, and not retained beyond the scan process. Only a file hash is kept, for verification purposes.
1. Information We Collect
Account Information:
- Name and email address
- Company name (optional)
- Password (encrypted)
Usage Information:
- Files uploaded for scanning are not retained; however, a file hash is generated and saved for verification
- Scan results and history
- API usage statistics
- Login timestamps and IP addresses
Payment Information:
- Billing details are processed by our payment provider (Stripe)
- We do not store credit card numbers
2. How We Use Your Information
We use your information to:
- Send service notifications and updates
- Respond to support requests
- Detect and prevent abuse or fraud
- Comply with legal obligations
3. File Handling
When you upload a file for scanning:
- The file is analyzed by our scanning engine
- File hashes (MD5, SHA-1, SHA-256) are generated for identification
- Files are NOT stored on our servers
- Scan results are stored in your account history
- We may retain anonymized threat data to improve detection
4. Data Sharing
Only your email address is considered shareable and NOT for sale. However, 'data' in this context is more technical, such as IP address, file hashes, etc. We may share these with:
- Service Providers: Payment processors, hosting providers (under strict confidentiality)
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In the event of a merger or acquisition
5. Data Security
We implement industry-standard security measures:
- Encryption in transit (HTTPS/TLS)
- Encrypted password storage
- Periodic security reviews
- Access controls and monitoring
6. Data Retention
- Account Data: Name, email, company name, and encrypted password are retained while your account is active
- Scan History: Retained based on your subscription plan:
- Starter: 30 days
- Builder, Professional, Enterprise: 90 days
Scan history is downloadable as a CSV file at any time during the retention period.
- Uploaded Files: Deleted immediately after scanning
- Logs: Retained for 30 days for security purposes
- After Cancellation: Your data is retained for 30 days after account expiration, then marked for deletion. Data is deleted logically (not physically) for compliance purposes.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data (scan history as CSV)
- Opt out of marketing communications
To exercise these rights, contact us at [email protected]
8. Cookies
We use essential cookies to:
- Keep you logged in (session management)
- Remember your preferences
- Prevent unauthorized access to your account (session validation)
We do not use tracking or advertising cookies.
9. International Data
Our servers are located in the United States.
10. Children's Privacy
The Service is not intended for users under 18. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via email.
12. Contact Us
For privacy-related questions or concerns:
[email protected]
StrategicPromptArchitect.ca, Canada