Privacy Policy

Last updated: 2025-06-01

1. Information We Collect

We collect: (a) Account data — email address, username, hashed password, and payment identifiers (Stripe customer/subscription IDs). (b) Usage data — job metadata such as file name, file hash, type, analysis output, and credit cost. Uploaded file binaries are processed ephemerally and are not stored beyond analysis completion. (c) Session data — session cookies required to keep you signed in. (d) Log data — server request logs including IP address, user-agent, and timestamps, retained for up to 30 days.

2. How We Use Your Information

We use your data to: provide and improve the Service; process payments; send transactional emails (verification, password reset, billing receipts); detect and prevent abuse; and comply with legal obligations. We do not sell your data to third parties.

3. Payment Processing

All payment processing is handled by Stripe, Inc. We do not store full card numbers or payment card data on our servers. Stripe's privacy policy applies to the data they collect: stripe.com/privacy.

4. AI Processing

Analysis context (file metadata, decompiled output, your chat messages) is sent to DeepSeek's API to generate AI responses. DeepSeek's data processing terms apply to prompts transmitted to their service. We do not send raw binary content to AI providers.

5. Data Retention

Account data is retained until you delete your account. Job records (metadata only, no binaries) are retained for 90 days after creation. Logs are retained for 30 days. After account deletion, all personal data is purged within 30 days.

6. Cookies

We use one first-party session cookie ("ep_session") strictly necessary for authentication. We do not use tracking cookies, advertising cookies, or third-party analytics.

7. Your Rights

Depending on your jurisdiction you may have the right to access, correct, or delete your personal data. Contact support@entrypoint.rip to make a request. We will respond within 30 days.

8. Security

Passwords are hashed with Argon2id. Data in transit is protected by TLS. We implement access controls and monitoring to protect your information, though no system is completely secure.

9. Children

The Service is not directed to children under 18. We do not knowingly collect data from minors. Contact us if you believe we have collected data from a minor.

10. Changes

We may update this policy. Material changes will be communicated by email or a notice on the Service. Your continued use after changes constitutes acceptance.

11. Contact

Privacy inquiries: support@entrypoint.rip