Your Privacy Matters
This Privacy Policy describes how 386 LLC ("we," "us," or "our") collects, uses, and protects your personal information when you use the SentinelSAST platform. We are committed to GDPR and CCPA compliance and will never sell your data.
End-to-End Encrypted
All data in transit and at rest is encrypted using industry-standard protocols.
GDPR & CCPA Compliant
We honor your rights under EU and California privacy regulations.
Data Never Sold
Your personal information and submitted code are never sold to third parties.
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, and authentication credentials.
Submitted Content: Code snippets, files, and URLs you submit for security analysis. This content is processed solely to deliver the Service and is not used for any other purpose.
Usage Data: Information about how you interact with the Service, including audit history, feature usage, and session data, collected to improve functionality and performance.
Technical Data: IP address, browser type, operating system, and device identifiers collected automatically for security and operational purposes.
2. How We Use Your Information
We use the information we collect to:
- • Provide, operate, and improve the CodeAudit Service
- • Process and return security analysis results to you
- • Authenticate your identity and secure your account
- • Communicate with you about your account, updates, and security notices
- • Comply with legal obligations and enforce these Terms
- • Detect and prevent fraud, abuse, and security threats
3. Data We Do NOT Collect or Sell
4. Data Security & Encryption
We employ industry-standard security measures to protect your data:
- 🔐 TLS 1.3 encryption for all data in transit
- 🔐 AES-256 encryption for data at rest
- 🔐 Regular security audits and penetration testing
- 🔐 Access controls and authentication for all internal systems
- 🔐 Automatic deletion of submitted code after analysis completion
5. Data Retention
We retain your account information for as long as your account is active. Submitted code and analysis results are retained in your account history until you delete them or close your account. Usage logs are retained for up to 90 days for operational purposes.
6. Your GDPR Rights (EU/EEA Users)
If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
Right of Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate or incomplete data
Right to Erasure
"Right to be forgotten" — delete your data
Right to Portability
Export your data in a machine-readable format
Right to Restrict
Limit how we process your data
Right to Object
Object to processing based on legitimate interests
7. Your CCPA Rights (California Residents)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- • Know what personal information is being collected and how it is used
- • Request deletion of your personal information
- • Opt-out of the sale of personal information (we do not sell personal information)
- • Non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us at privacy@386llc.com. We will respond within 45 days.
8. Cookies & Tracking
We use only essential cookies required for authentication and session management. We do not use third-party tracking cookies, advertising pixels, or behavioral analytics tools that share data with external parties.
9. Third-Party Services
The Service uses AI processing infrastructure provided by third-party providers solely to deliver analysis results. These providers are bound by data processing agreements that prohibit them from using your data for any purpose other than providing services to us. We do not share your personal data or submitted code with any other third parties except as required by law.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by prominent notice within the Service. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
12. Contact & Data Requests
For privacy inquiries, data access requests, or to exercise your rights:
386 LLC — Privacy Office
privacy@386llc.com
Response time: within 30 days (GDPR) / 45 days (CCPA)