Last updated: 2026-08-05 · Plain text version of this document

Privacy Policy

DRAFT — NOT YET IN FORCE. This document has not been reviewed by counsel and must not be published in this state. Items marked [VERIFY] are assumptions drawn from the codebase that Ryan needs to confirm or correct.

Who we are

After Dark Systems, LLC ("After Dark", "we", "us") is the controller of personal data described in this policy.

This policy covers the corporate site, our security products, and our infrastructure and API services. It does not cover our DNS and internet data intelligence services, which have their own policy at legal.dnsapi.ai.

What we collect

Information you give us

Data Where from Why
Email address signup, contact form account creation, service delivery
Full name signup account identification
Company name signup, optional account context, billing
Phone numbers (home, cell) signup, optional account recovery, support
Password credential or passkey signup, login authentication
Product interests signup, optional routing you to relevant services
Sales contact preference signup, optional marketing consent signal
Support messages support, contact form answering you
Billing details checkout payment, tax records

We use passkeys (WebAuthn) where available. A passkey never transmits a shared secret to us; we hold only a public key and credential identifier.

Payment card numbers are handled by Stripe and never reach our servers.

Information collected automatically

Data Why Notes
IP address security, abuse prevention, rough location treated as personal data
Browser and device string compatibility, abuse detection
Pages requested and timestamps operating the service
Authentication events account security, fraud detection includes failed attempts
Session cookie keeping you signed in strictly necessary

Because every one of our hosts is reachable from the internet and protected by single sign-on rather than a private network, sign-in pages record connection metadata from anyone who reaches them, including people without accounts. We use that record only for security and abuse prevention.

Anti-automation signals

Some of our sites use CaptchANG, our own anti-automation system, to tell humans apart from bots. It analyses interaction patterns — including pointer movement and typing rhythm — while you are on the page.

These signals are used in the moment to allow or block the request and are not retained, not linked to your account, and not used to identify you as an individual. [VERIFY: confirm no derived risk score is persisted per IP or session, and that debug logging does not capture the raw signal stream.]

What we do not collect

We do not knowingly collect data from children under 16. We do not buy personal data from data brokers. We do not use third-party advertising trackers on the services covered by this policy.

Why we use it, and our legal basis

For users in the UK, EU, and EEA, the GDPR requires us to name a lawful basis.

Purpose Lawful basis
Creating and running your account Contract, Art. 6(1)(b)
Delivering a service you bought Contract, Art. 6(1)(b)
Taking payment Contract, Art. 6(1)(b)
Keeping tax and accounting records Legal obligation, Art. 6(1)(c)
Security, abuse prevention, fraud detection Legitimate interests, Art. 6(1)(f)
Keeping the service working and diagnosing faults Legitimate interests, Art. 6(1)(f)
Marketing email about our other products Consent, or soft opt-in for existing customers
Non-essential cookies Consent

Billing and marketing are separate. We keep your billing records because tax law requires it. We do not treat that as permission to market to you. Marketing depends on the separate preference you set at signup, and you can withdraw it at any time without affecting your account.

Sharing

We share personal data with service providers who process it on our behalf under contract. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Our current subprocessors are listed at Subprocessors (plain text).

We also disclose data where we are legally required to, and where necessary to establish or defend legal claims.

When we act for you instead of ourselves

For several of our security products, you upload data about other people — your own employees, your own systems, credentials found in your own breach exposure. For that data you are the controller and we are your processor. We process it only on your instructions and we do not use it for our own purposes.

That relationship needs a Data Processing Agreement, not just these terms. See Security Services Addendum (plain text).

Automated decisions

We use automated processing in two places that can affect you:

Anti-automation. CaptchANG can block a request it scores as automated. This is a security control, not a decision about you as a person. If you are wrongly blocked, email privacy@afterdarksys.com and a person will review it.

Abuse and fraud signals. We may automatically rate-limit or suspend an account showing abuse patterns. A suspension that affects your access is reviewable by a person on request.

We do not make solely automated decisions producing legal or similarly significant effects within the meaning of GDPR Art. 22, and we do not profile you for advertising. Where an automated control affects your access, you can ask for human review, contest the outcome, and get an explanation of the reason.

Artificial intelligence

Some of our services use AI models. Where you are interacting with an AI system rather than a person, we tell you so in the interface.

We do not train models on your personal data or on customer content. [VERIFY: confirm across all products, including any OpenRouter usage.]

Where we send content to a third-party model provider to deliver a feature, that provider is listed as a subprocessor.

How long we keep it

Category Retention
Account records life of the account, then 90 days
Billing and tax records 7 years from the transaction
Support correspondence 3 years from closure
Security and authentication logs 12 months
Marketing preferences until you withdraw consent
Anti-automation signals not retained

[VERIFY: these are proposed periods, not observed system behaviour. Retention needs to be implemented and evidenced before this table is published.]

Where it goes

We operate on private bare-metal servers. Some subprocessors are outside the UK and EEA, principally in the United States. Where we transfer personal data out of the UK or EEA we rely on the UK IDTA or the EU Standard Contractual Clauses together with a transfer risk assessment.

Your rights

Depending on where you live you may have the right to:

To exercise any of these, email privacy@afterdarksys.com. We reply within one month. We do not charge, and we will not treat you differently for asking.

If you are in California, you also have the right to know what we collect, to delete it, to correct it, and to limit use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, so we do not offer a "Do Not Sell or Share" link. If that changes, this policy will change with it and the link will appear.

If you are in the UK or EEA, you can complain to your national supervisory authority. In the UK that is the Information Commissioner's Office.

Security

We protect data with encryption in transit, single sign-on through Authentik, multi-factor and passkey authentication, and access controls limiting staff access to what their role requires.

Our security practices are informed by ISO/IEC 27001 and the NIST frameworks. We are not certified against either standard, and we do not claim to be.

To report a vulnerability, see our security.txt or email security@afterdarksys.com.

Accessibility

We build for screen readers and non-visual use, and every document on this site is available as plain text. See our Accessibility Statement (plain text).

Changes

We will post material changes here and update the date at the top. Where a change reduces your rights or expands our use of your data, we will tell account holders directly before it takes effect.

Contact