Skip to main content

Privacy notice

Privacy, with a local-first boundary

This notice explains how Ciphermap Technologies LLC handles personal information for the CipherMap website, sales and evaluation inquiries, and invitation-only Free Developer Source Preview. It does not describe a future paid or generally available service.

Effective August 30, 2026

Who is responsible

Ciphermap Technologies LLC controls the information described here. Formal notices may be sent to 1500 N Grant St, #11719, Denver, CO 80203, United States. Privacy and deletion requests may be sent to privacy@ciphermap.io.

Information we handle

  • Information you send by email, including your name, business email, organization, role, evaluation purpose, operating system, toolchain, and correspondence.
  • Information you submit through an evaluation or scanner-help form, including your name, business email, organization, primary goal, approximate repository range, preferred next step, and any message you choose to provide.
  • Campaign parameters and advertising click identifiers in the page URL, such as UTM values or a Google click identifier, captured only when you explicitly submit a campaign form.
  • Preview administration records, including the archive identifier, accepted document versions, access grant and expiry times, revocation events, and deletion certification.
  • Support, bug, security, and privacy reports you choose to submit.
  • Limited hosting, access-control, and security logs created by service providers when you visit the public site or access the separately protected source Preview.

The public website and protected source Preview do not mount application analytics, sell personal information, use it for targeted advertising, or accept source-code uploads. Campaign attribution is not collected passively by the application; it is included only with an explicit form submission. Normal CipherMap scans run locally. Do not send repository source, credentials, private keys, regulated data, or other unnecessary sensitive information by email or form.

Why we use it

We use the minimum information reasonably needed to respond to a requested evaluation or scanner question, provide relevant materials, schedule a requested meeting, understand which submitted campaign led to the request, evaluate Preview access requests, deliver and revoke named-recipient access, operate the Preview, provide support, investigate security or abuse, maintain business records, enforce applicable terms, and meet legal obligations. Inquiry and Preview contacts are not added to marketing lists without a separate opt-in.

Service providers and disclosures

We may use providers for website hosting, protected access, transactional email, requested scheduling, anti-abuse controls, and secure file delivery. They may process information only as needed to provide those functions or meet their own legal obligations. We may also disclose information when required by law, to protect people or systems, or in connection with a business transaction subject to appropriate safeguards. We do not sell personal information.

Retention

Declined Preview access requests
90 days after final disposition
Accepted identity, assent, access, revocation, and deletion-certification records
24 months after access ends
Sales and evaluation inquiries
12 months after the last substantive response, unless needed for an active opportunity or legal obligation
Support messages
12 months after issue closure
Marketing opt-out and suppression records
For as long as needed to honor the opt-out and applicable legal obligations
Unsubstantiated security reports
12 months after issue closure
Confirmed security incidents or abuse records
Three years after closure, or until a legal hold ends
Routine access and security logs
90 days
Website and deployment-provider logs
30 days or the shortest enforceable provider setting, whichever is shorter

We may keep a record longer when reasonably necessary for an active dispute, security investigation, legal hold, or legal obligation, and may delete records sooner when they are no longer needed.

Your choices and requests

You may ask to access, correct, or delete information associated with you, or withdraw from the Preview. We will verify and respond to requests as required by applicable law and will also review reasonable requests when a specific privacy law does not apply. Email privacy@ciphermap.io. Newsletter subscribers can also use the unsubscribe link in each marketing message.

Security, scope, and changes

We use reasonable administrative and technical safeguards, but no system is risk-free. The Preview is intended for U.S.-based professionals acting in a business capacity and is not directed to children. Material changes will be posted here with a new effective date; recipient terms will be re-presented when required.

Security issues should be reported to security@ciphermap.io. See also the security and data-handling page.