Redeyed Corporation, a Nevada corporation ("Redeyed", "we", "us", or "our"), respects your privacy and is committed to protecting it. This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the rights and choices you may have. It applies to our websites, Laboratory and Agents, Sentinel, Recon, Guardian, Shield, Developer services, desktop and mobile applications, and related services (collectively, the "Services"). Please read it together with our Terms of Service, Acceptable Use Policy, Cookies Policy, and Security & Compliance Statement.
Redeyed Corporation is a software-as-a-service company based in Nevada, USA. We build privacy-respecting tools that run on our own infrastructure. This Privacy Policy describes how we handle personal information when you visit our websites, create an account, purchase a subscription or credits, or otherwise use the Services.
This Policy applies to information about visitors, account holders, subscribers, and people who contact us. It does not apply to third-party websites, products, or services that we do not control, even if they link to or from the Services. Where Redeyed processes personal information on behalf of a business customer (for example, the visitor data handled by Sentinel, or identifiers a Recon customer submits), our role and responsibilities are described in Section 10.
By using the Services, you acknowledge the practices described in this Policy. Where we rely on your consent (for example, for non-essential cookies or optional marketing), we will ask for it and you may withdraw it at any time.
We collect personal information that you provide to us, that we generate as you use the Services, and that we receive from service providers acting on our behalf. The categories below describe the information we may collect.
When you register, we collect information such as your username, name, email address, hashed password, date of birth (to confirm eligibility), how you heard about us or your referrer, subscription tier, organization or team membership, role assignments, and communication preferences. We also record the versions of the Terms and Privacy Policy you accepted or acknowledged, acceptance time, IP address, and user agent to establish an accurate agreement record. If you enable multi-factor authentication, we store the configuration needed to verify it (for example, an encrypted TOTP secret or a registered security key), but not your underlying credentials in readable form.
Direct subscriptions, credit purchases, and add-ons are processed by Stripe, PayPal, or Coinbase Commerce; purchases made in an Apple application are processed by Apple. When you pay, payment details are submitted to the applicable provider. We do not store full payment card numbers. We receive and retain limited billing metadata such as plan, product, transaction and original-transaction identifiers, storefront, the last four digits and card brand where a direct processor provides them, billing country, invoices, entitlement, and payment or refund status for accounting, entitlement delivery, fraud prevention, and support.
When you use the Laboratory AI tools, we process the prompts, text, files, and other inputs you submit, together with the outputs generated for you. If you upload documents, images, or other materials to the Services, we process and store them to provide the relevant feature. See Section 4 for how prompts and content are handled, including when you select a third-party model and your content is sent to that provider.
As you interact with the Services, we automatically collect usage and technical information, including pages and features accessed, actions taken, credits consumed, API calls, referring and exit pages, timestamps, approximate location derived from IP address, IP address, browser type, operating system, device identifiers, and diagnostic and error logs. We use this information to operate, secure, and improve the Services.
When you install or use Guardian and affirmatively initiate or authorize a scan, diagnostic, live check, or optimization analysis, we process the information needed to provide that feature. Depending on your device and permissions, this may include device and host name; operating-system edition, version, build, installation date, architecture, and product metadata; processor, motherboard, BIOS or firmware, memory, graphics adapters and driver versions; storage capacity, usage, format, and volume labels; display information; network-adapter type and link characteristics; latency, jitter, packet-loss samples, and gateway or connectivity results; game-installation and supported configuration information; security posture; and names of running processes, loaded modules, services, or drivers used to identify integrity, malware, cheat, or compatibility signals.
Stable hardware identifiers such as board UUIDs, processor identifiers, disk serial numbers, MAC addresses, and operating-system device identifiers are designed to be one-way hashed on the device before transmission where supported. We use those hashes to associate scans with the same machine and detect machine substitution; we do not need the corresponding raw identifier for that purpose. Scan reports, device profiles, risk signals, optimization actions, consent records, and administrative reviews may be associated with your account. A live device check requires the consent shown in the client and is logged.
When a business customer deploys Sentinel on their website, Sentinel evaluates traffic to that website and processes visitor data such as IP addresses, coarse device and browser signals, request patterns, and risk and reputation signals used to distinguish humans from automated abuse. For this visitor data, Redeyed generally acts as a processor / service provider on behalf of the website operator, who is the controller. See Section 10.
Recon is a privacy product that helps you remove your personal information from data-broker websites and provides consent-based exposure monitoring of assets you add to your account and verify as your own. To deliver these services, we process the identifiers you submit — for example, your own name, email addresses, phone numbers, postal addresses, or domains — so that we can locate and request removal of matching records and alert you to new exposures. Recon performs defensive privacy monitoring only; we process the identifiers you have verified as belonging to you (or, for business monitoring, that your organization is authorized to monitor).
We and our analytics provider use cookies and similar technologies to operate the Services, remember your preferences, secure your session, and understand usage. Our website uses Google Analytics (gtag.js). For details and your choices, see Section 6 and our Cookies Policy.
When you contact us for support, submit a form, subscribe to a newsletter, or otherwise communicate with us, we collect the information you provide and a record of our correspondence so we can respond and keep an account of the request.
We use personal information for the following purposes:
The Laboratory AI tools are served by Redeyed's own self-hosted models, operated on infrastructure we control, and — where you choose them — by third-party AI providers. Our self-hosted model is the default. Where a third-party model is available, the chat interface names the provider before you send, and your selection is what determines where that message is processed.
If you select a third-party model, the content of that request — your prompt, the earlier messages in that conversation, any file or image you attached to it, and system instructions we add — is transmitted to that provider's API so it can generate a reply. The providers we currently use for this are Anthropic (Claude models) and OpenAI (GPT models). Their handling of that content is also governed by their own terms and privacy policies.
We use these providers through their business APIs, under terms which provide that content submitted through the API is not used to train the provider's models. Providers may nonetheless retain content for a limited period for abuse monitoring and legal compliance under their own policies. We do not control those retention periods.
Third-party models are reachable only for a defined set of general-purpose language tasks: conversation, rewriting, summarizing, explaining, and drafting written reports. Security testing work — including anything involving exploitation, penetration testing, or payload generation — is always processed on our own self-hosted models and is never sent to a third-party AI provider, regardless of which model you have selected. This restriction is enforced in the software itself rather than by policy alone: a model preference cannot override it.
Scan results, Sentinel visitor data, Recon identifiers, and Guardian device data are likewise not sent to third-party AI providers except where they form part of a request you have chosen to send to a third-party model.
If you would rather nothing left our infrastructure, use the self-hosted model. It is the default, and it remains available on every plan. We may retain and review content to operate the tools, maintain safety, and improve our self-hosted models, and we work to minimize and filter personal information from training material. Please avoid submitting sensitive personal, financial, or confidential information you would not want processed for these purposes — and note that content you send to a third-party model cannot be recalled from that provider by us. You may request deletion of content we hold as described in Section 9 and Section 14.
We share personal information only as described below, and we require recipients to protect it appropriately.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law. We do not trade your personal information to third parties for money or other valuable consideration.
We use cookies and similar technologies for essential functions (such as session and CSRF protection), preferences, security, and analytics. Google Analytics is disabled by default and loads only after you select Allow analytics. If enabled, it helps us understand aggregate usage and may collect information such as a truncated or anonymized IP address, device and browser characteristics, pages viewed, and a randomized identifier. A supported Global Privacy Control signal overrides stored analytics consent and prevents the analytics tag from loading.
For a full description of the cookies we use, how long they last, and how to manage or disable them, please see our Cookies Policy.
We retain personal information for as long as needed to provide the Services and for the purposes described in this Policy, after which we delete or anonymize it. The period depends on the type of information and our legal and operational needs:
We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (TLS) and application-level encryption for designated sensitive data at rest, hashed passwords, optional multi-factor authentication (TOTP, security keys, and email), scoped and IP-bound API keys, role-based access controls, least-privilege practices, audit logging, and ongoing monitoring. Additional detail and our independent-assurance status appear in the Security & Compliance Statement.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where required by law, we will notify affected individuals and regulators of qualifying personal data breaches.
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the following rights, subject to certain exceptions:
To exercise these rights, contact us at [email protected]. We will verify your request and respond within the timeframes required by law.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights, subject to applicable law:
Our legal bases for processing personal data include: performance of a contract (to provide the Services you request); legitimate interests (to secure the Services, prevent abuse, operate Sentinel's reputation scoring, and improve our products, balanced against your rights); consent (for non-essential cookies and optional marketing); and compliance with a legal obligation (for tax, accounting, and other statutory requirements).
Our role under data protection law depends on the Service and whose data is being processed.
For the visitor data that Sentinel processes on a customer's website — such as IP addresses, coarse device and browser signals, and risk and reputation signals — the website operator is the controller and Redeyed acts as a processor / service provider, handling that data to provide and secure the CAPTCHA and IP-reputation service on the operator's behalf and instructions. Our Data Processing Addendum applies to covered business processing.
For Recon, we process the identifiers you submit and verify as your own (or, for business monitoring, that your organization is authorized to monitor) to perform data-broker removals and consent-based exposure monitoring. Recon is defensive privacy monitoring only.
For an individual account, Redeyed generally acts as controller for Guardian account, scan, device-profile, consent, integrity, and usage information. Where an organization deploys Guardian to authorized users or devices and determines the purpose and means of the scan, the organization may act as controller and Redeyed may act as its processor or service provider for covered device data, subject to the agreement and DPA. The organization remains responsible for lawful authority, appropriate notices, permissions, and use of results.
For the account, billing, content, and usage information described in this Policy, Redeyed acts as the controller.
Redeyed is based in the United States, and we and our service providers may process personal information in the United States and other countries. These countries may have data protection laws that differ from those in your jurisdiction. Where we transfer personal data from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable). You may request more information about these safeguards by contacting us.
The Services are not directed to children under 16, and an individual must be at least 16 years old to create an account. Where applicable law requires parental or guardian consent for a 16- or 17-year-old to use the Services or for us to process their personal information, the account may be used only with that consent. We do not knowingly permit a child under 16 to maintain an account. If you believe a child has provided us personal information or created an account, contact us at [email protected] and we will investigate and take appropriate action, including deletion where required.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you acknowledge the revised Policy.
To ask a question about this Policy or exercise your privacy rights, contact our privacy and legal team at [email protected]. The current Data Processing Addendum is available online. For general inquiries you may reach us at [email protected], and for product help at [email protected]. We may need to verify your identity before acting on a request. This Policy is governed by the laws of the State of Nevada, USA.
Redeyed CorporationRelated policies: Terms of Service, Acceptable Use Policy, and Cookies Policy.