RIL Warden · Terms · DPA

DRAFT FOR LEGAL REVIEW. This describes how Warden actually handles data today. It is not legal advice and has not been reviewed by counsel. [bracketed items] need a Rip It Labs or attorney decision before publishing.

Privacy Policy

Effective date: [effective date] · Last updated: [date]

This policy explains what Rip It Labs, LLC ("we") collects when you use RIL Warden, how we use it, and your choices. For business customers, the Data Processing Addendum governs data your agents send through Warden on your behalf; where the two differ for that data, the DPA controls.

Two kinds of data

Account data is about you as a customer: how you sign in, pay, and get support. We act as the controller of it. Gateway data is what your agents route through Warden. For business customers we process it as your processor, on your instructions, under the DPA.

What we collect

CategoryExamplesWhy
AccountEmail and name (including from Google Sign-In), workspace and member names, hashed access keysCreate and secure your account, sign you in
BillingPlan, subscription status, and a customer record at our processor (Stripe). We do not store full card numbers.Take payment, manage your plan
Gateway logsAgent identity, destination host, method, path, request/response sizes, timestamps, the allow/block decision and reason, and the source IP of the calling agentEnforce your rules and keep the tamper-evident audit trail
Vaulted secretsThe API keys or tokens you give an agent, stored encryptedInject them toward approved hosts so the agent never sees them
Support & early accessMessages you send us, early-access form entriesRespond to you and set up accounts
Site analyticsFirst-party page-view counts on our public pagesUnderstand which pages are useful

Warden is built to see as little as it can: an agent's API keys are stored encrypted and are redacted if a site echoes them back, and request bodies are not retained in the log. [Confirm final log-field list with engineering before publishing.]

How we use data

On-chain anchoring

Warden periodically writes a hash of a log checkpoint to public blockchains so the log's integrity can be proven later. A hash is a one-way fingerprint. Your request contents, destinations, account details, and secrets are never written to any blockchain and cannot be recovered from the hash. Because blockchain records are permanent, the checkpoint hashes cannot be deleted.

Who we share with (sub-processors)

We use a small set of providers to run the Service:

ProviderPurpose
HetznerHosting the Service [confirm data-center region]
CloudflareNetwork, TLS, and DNS in front of the Service
GoogleOptional Google Sign-In, and outbound email
StripePayment processing for paid plans
Your chosen destinationsntfy, Slack, or a SIEM (Splunk/Datadog) only if you enable alerts or log streaming to them

We share data with providers only as needed to run the Service, and otherwise only to comply with law or protect rights and safety. A current sub-processor list for business customers is in the DPA.

Retention

We keep account and billing data for as long as your account is active and as needed for legal and tax purposes. Gateway logs are retained [retention period / until you delete them]. Anchored checkpoint hashes are permanent by design (see above). [Set concrete retention periods with counsel.]

Security

We protect data in transit with TLS, store vaulted secrets and backups encrypted, hash access keys, isolate each workspace's data, restrict staff access, and maintain the tamper-evident audit log. No system is perfectly secure. We describe our vulnerability-reporting process at /security.

International transfers

We may process data in the country where our providers operate. If you are outside that country, your data may be transferred there. [Counsel: confirm hosting region and, if serving EU/UK customers, the transfer mechanism such as Standard Contractual Clauses.]

Your choices and rights

You can access, correct, export, or delete workspace data in the console or by contacting us. Depending on where you live you may have additional rights (for example under GDPR or the CCPA) to access, delete, correct, or restrict use of your personal data, and to complain to a regulator. To exercise them, email [email protected]. [Counsel: confirm which privacy laws apply and add the required specifics.]

Children

The Service is for organizations and adults. It is not directed to children, and we do not knowingly collect data from anyone under [18].

Changes

We may update this policy and will post the new effective date here, giving notice of material changes where practical.

Contact

Rip It Labs, LLC · [business address] · [email protected] · Privacy contact: [name/role]