Privacy notice
Privacy, with a local-first boundary
This notice explains how Ciphermap Technologies LLC handles personal information for the CipherMap website, sales and evaluation inquiries, and invitation-only Free Developer Source Preview. It does not describe a future paid or generally available service.
Effective August 30, 2026
Who is responsible
Ciphermap Technologies LLC controls the information described here. Formal notices may be sent to 1500 N Grant St, #11719, Denver, CO 80203, United States. Privacy and deletion requests may be sent to privacy@ciphermap.io.
Information we handle
- Information you send by email, including your name, business email, organization, role, evaluation purpose, operating system, toolchain, and correspondence.
- Information you submit through an evaluation or scanner-help form, including your name, business email, organization, primary goal, approximate repository range, preferred next step, and any message you choose to provide.
- Campaign parameters and advertising click identifiers in the page URL, such as UTM values or a Google click identifier, captured only when you explicitly submit a campaign form.
- Preview administration records, including the archive identifier, accepted document versions, access grant and expiry times, revocation events, and deletion certification.
- Support, bug, security, and privacy reports you choose to submit.
- Limited hosting, access-control, and security logs created by service providers when you visit the public site or access the separately protected source Preview.
The public website and protected source Preview do not mount application analytics, sell personal information, use it for targeted advertising, or accept source-code uploads. Campaign attribution is not collected passively by the application; it is included only with an explicit form submission. Normal CipherMap scans run locally. Do not send repository source, credentials, private keys, regulated data, or other unnecessary sensitive information by email or form.
Why we use it
We use the minimum information reasonably needed to respond to a requested evaluation or scanner question, provide relevant materials, schedule a requested meeting, understand which submitted campaign led to the request, evaluate Preview access requests, deliver and revoke named-recipient access, operate the Preview, provide support, investigate security or abuse, maintain business records, enforce applicable terms, and meet legal obligations. Inquiry and Preview contacts are not added to marketing lists without a separate opt-in.
Service providers and disclosures
We may use providers for website hosting, protected access, transactional email, requested scheduling, anti-abuse controls, and secure file delivery. They may process information only as needed to provide those functions or meet their own legal obligations. We may also disclose information when required by law, to protect people or systems, or in connection with a business transaction subject to appropriate safeguards. We do not sell personal information.
Retention
- Declined Preview access requests
- 90 days after final disposition
- Accepted identity, assent, access, revocation, and deletion-certification records
- 24 months after access ends
- Sales and evaluation inquiries
- 12 months after the last substantive response, unless needed for an active opportunity or legal obligation
- Support messages
- 12 months after issue closure
- Marketing opt-out and suppression records
- For as long as needed to honor the opt-out and applicable legal obligations
- Unsubstantiated security reports
- 12 months after issue closure
- Confirmed security incidents or abuse records
- Three years after closure, or until a legal hold ends
- Routine access and security logs
- 90 days
- Website and deployment-provider logs
- 30 days or the shortest enforceable provider setting, whichever is shorter
We may keep a record longer when reasonably necessary for an active dispute, security investigation, legal hold, or legal obligation, and may delete records sooner when they are no longer needed.
Your choices and requests
You may ask to access, correct, or delete information associated with you, or withdraw from the Preview. We will verify and respond to requests as required by applicable law and will also review reasonable requests when a specific privacy law does not apply. Email privacy@ciphermap.io. Newsletter subscribers can also use the unsubscribe link in each marketing message.
Security, scope, and changes
We use reasonable administrative and technical safeguards, but no system is risk-free. The Preview is intended for U.S.-based professionals acting in a business capacity and is not directed to children. Material changes will be posted here with a new effective date; recipient terms will be re-presented when required.
Security issues should be reported to security@ciphermap.io. See also the security and data-handling page.