All policies

Privacy Policy

Last updated June 15, 2026

How DataStrict, Inc. collects, uses, and protects personal information across our website and services - and the architectural reason we never see your governed data.

Overview

DataStrict, Inc. ("DataStrict", "we", "us") provides the control layer for modern AI systems. This Privacy Policy explains what personal information we collect when you visit datastrict.com, contact us, or use our services, how we use it, and the choices you have.

We designed our product so that the most sensitive data - the traffic our software governs - stays inside your infrastructure. The collection described below relates to operating our website and our commercial relationship with you.

Information we collect

Information you provide: your name, work email, company, role, and any message content when you fill in a form, request a demo, contact support, or sign in.

Information collected automatically: standard log and device data (IP address, browser type, pages viewed) and, only with your consent, product analytics. Analytics are loaded after you accept them in our cookie banner and never before.

We do not buy personal information from data brokers, and we do not collect special categories of data through our website.

Your governed data

Because DataStrict is deployed inside your own environment (on-premises, your private cloud, or air-gapped), the governed traffic it inspects - prompts, retrievals, tool calls, and model outputs - is processed entirely within your own environment and is never transmitted to DataStrict. This document concerns the limited data we process to operate our website and commercial relationship, not your governed data.

Where you operate DataStrict as managed software, the audit Ledger and policy decisions are written to a database you run. Your evidence never leaves your jurisdiction unless you choose to share it with us for support.

How we use information

To respond to your enquiries, provide and improve our services, secure our systems, send service and (where permitted) marketing communications you can opt out of, and meet legal obligations.

We do not sell personal information, and we do not use your content to train models.

How we share information

We share personal information with vetted service providers who process it on our behalf under contract - our current subprocessors are listed on our Subprocessors page. We may also disclose information to comply with law or to protect rights and safety. If we are involved in a merger or acquisition, information may transfer as part of that transaction subject to this Policy.

Security

We maintain administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, least-privilege access, and audit logging. No method of transmission or storage is perfectly secure, but security is the core of what we build.

Data retention

We keep personal information only as long as needed for the purposes described here or as required by law, then delete or anonymize it.

Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object or withdraw consent. To exercise these rights, email [email protected]. We will not discriminate against you for exercising them.

International transfers

We are based in the United States and may process information there and in other countries. Where required, we use appropriate safeguards such as the Standard Contractual Clauses for cross-border transfers.

Changes and contact

We may update this Policy and will revise the date above when we do. Questions or requests: [email protected], DataStrict, Inc., San Francisco, CA.

Questions about this policy? Email [email protected].