Privacy Policy
DRAFT — NOT YET IN FORCE. This document has not been reviewed by counsel and must not be published in this state. Items marked
[VERIFY]are assumptions drawn from the codebase that Ryan needs to confirm or correct.
Who we are
After Dark Systems, LLC ("After Dark", "we", "us") is the controller of personal data described in this policy.
- Postal address:
[VERIFY: registered address needed] - Privacy contact: privacy@afterdarksys.com
- EU representative (GDPR Art. 27):
[VERIFY: not yet appointed — required if we have EU users and no EU establishment] - UK representative:
[VERIFY: not yet appointed]
This policy covers the corporate site, our security products, and our
infrastructure and API services. It does not cover our DNS and internet data
intelligence services, which have their own policy at legal.dnsapi.ai.
What we collect
Information you give us
| Data | Where from | Why |
|---|---|---|
| Email address | signup, contact form | account creation, service delivery |
| Full name | signup | account identification |
| Company name | signup, optional | account context, billing |
| Phone numbers (home, cell) | signup, optional | account recovery, support |
| Password credential or passkey | signup, login | authentication |
| Product interests | signup, optional | routing you to relevant services |
| Sales contact preference | signup, optional | marketing consent signal |
| Support messages | support, contact form | answering you |
| Billing details | checkout | payment, tax records |
We use passkeys (WebAuthn) where available. A passkey never transmits a shared secret to us; we hold only a public key and credential identifier.
Payment card numbers are handled by Stripe and never reach our servers.
Information collected automatically
| Data | Why | Notes |
|---|---|---|
| IP address | security, abuse prevention, rough location | treated as personal data |
| Browser and device string | compatibility, abuse detection | |
| Pages requested and timestamps | operating the service | |
| Authentication events | account security, fraud detection | includes failed attempts |
| Session cookie | keeping you signed in | strictly necessary |
Because every one of our hosts is reachable from the internet and protected by single sign-on rather than a private network, sign-in pages record connection metadata from anyone who reaches them, including people without accounts. We use that record only for security and abuse prevention.
Anti-automation signals
Some of our sites use CaptchANG, our own anti-automation system, to tell humans apart from bots. It analyses interaction patterns — including pointer movement and typing rhythm — while you are on the page.
These signals are used in the moment to allow or block the request and are not
retained, not linked to your account, and not used to identify you as an
individual. [VERIFY: confirm no derived risk score is persisted per IP or session, and that debug logging does not capture the raw signal stream.]
What we do not collect
We do not knowingly collect data from children under 16. We do not buy personal data from data brokers. We do not use third-party advertising trackers on the services covered by this policy.
Why we use it, and our legal basis
For users in the UK, EU, and EEA, the GDPR requires us to name a lawful basis.
| Purpose | Lawful basis |
|---|---|
| Creating and running your account | Contract, Art. 6(1)(b) |
| Delivering a service you bought | Contract, Art. 6(1)(b) |
| Taking payment | Contract, Art. 6(1)(b) |
| Keeping tax and accounting records | Legal obligation, Art. 6(1)(c) |
| Security, abuse prevention, fraud detection | Legitimate interests, Art. 6(1)(f) |
| Keeping the service working and diagnosing faults | Legitimate interests, Art. 6(1)(f) |
| Marketing email about our other products | Consent, or soft opt-in for existing customers |
| Non-essential cookies | Consent |
Billing and marketing are separate. We keep your billing records because tax law requires it. We do not treat that as permission to market to you. Marketing depends on the separate preference you set at signup, and you can withdraw it at any time without affecting your account.
Sharing
We share personal data with service providers who process it on our behalf under contract. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Our current subprocessors are listed at Subprocessors (plain text).
We also disclose data where we are legally required to, and where necessary to establish or defend legal claims.
When we act for you instead of ourselves
For several of our security products, you upload data about other people — your own employees, your own systems, credentials found in your own breach exposure. For that data you are the controller and we are your processor. We process it only on your instructions and we do not use it for our own purposes.
That relationship needs a Data Processing Agreement, not just these terms. See Security Services Addendum (plain text).
Automated decisions
We use automated processing in two places that can affect you:
Anti-automation. CaptchANG can block a request it scores as automated. This is a security control, not a decision about you as a person. If you are wrongly blocked, email privacy@afterdarksys.com and a person will review it.
Abuse and fraud signals. We may automatically rate-limit or suspend an account showing abuse patterns. A suspension that affects your access is reviewable by a person on request.
We do not make solely automated decisions producing legal or similarly significant effects within the meaning of GDPR Art. 22, and we do not profile you for advertising. Where an automated control affects your access, you can ask for human review, contest the outcome, and get an explanation of the reason.
Artificial intelligence
Some of our services use AI models. Where you are interacting with an AI system rather than a person, we tell you so in the interface.
We do not train models on your personal data or on customer content.
[VERIFY: confirm across all products, including any OpenRouter usage.]
Where we send content to a third-party model provider to deliver a feature, that provider is listed as a subprocessor.
How long we keep it
| Category | Retention |
|---|---|
| Account records | life of the account, then 90 days |
| Billing and tax records | 7 years from the transaction |
| Support correspondence | 3 years from closure |
| Security and authentication logs | 12 months |
| Marketing preferences | until you withdraw consent |
| Anti-automation signals | not retained |
[VERIFY: these are proposed periods, not observed system behaviour. Retention needs to be implemented and evidenced before this table is published.]
Where it goes
We operate on private bare-metal servers. Some subprocessors are outside the UK and EEA, principally in the United States. Where we transfer personal data out of the UK or EEA we rely on the UK IDTA or the EU Standard Contractual Clauses together with a transfer risk assessment.
Your rights
Depending on where you live you may have the right to:
- get a copy of the personal data we hold about you
- correct data that is wrong or incomplete
- have data deleted
- restrict or object to how we use it
- receive your data in a portable format
- withdraw consent at any time
- complain to a data protection regulator
To exercise any of these, email privacy@afterdarksys.com. We reply within one month. We do not charge, and we will not treat you differently for asking.
If you are in California, you also have the right to know what we collect, to delete it, to correct it, and to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, so we do not offer a "Do Not Sell or Share" link. If that changes, this policy will change with it and the link will appear.
If you are in the UK or EEA, you can complain to your national supervisory authority. In the UK that is the Information Commissioner's Office.
Security
We protect data with encryption in transit, single sign-on through Authentik, multi-factor and passkey authentication, and access controls limiting staff access to what their role requires.
Our security practices are informed by ISO/IEC 27001 and the NIST frameworks. We are not certified against either standard, and we do not claim to be.
To report a vulnerability, see our security.txt or email security@afterdarksys.com.
Accessibility
We build for screen readers and non-visual use, and every document on this site is available as plain text. See our Accessibility Statement (plain text).
Changes
We will post material changes here and update the date at the top. Where a change reduces your rights or expands our use of your data, we will tell account holders directly before it takes effect.
Contact
- Privacy: privacy@afterdarksys.com
- Security: security@afterdarksys.com
- Accessibility: accessibility@afterdarksys.com
- Postal:
[VERIFY: registered address needed]