Privacy Policy
How RogueTrace collects, uses, discloses, and protects your information, and the rights you have over it under U.S. and international law.
RogueTrace ("RogueTrace," "we," "us," or "our") provides threat intelligence, security research, and AI-assisted analysis tools available at roguetrace.com and www.roguetrace.com (the "Site" or "Services"). This Privacy Policy explains what personal information we collect, how we use and disclose it, how long we keep it, and the rights and choices available to you under applicable law, including U.S. state privacy laws, the EU/UK General Data Protection Regulation ("GDPR"), and other data protection laws that may apply to you.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described here, please do not use the Services. This Policy does not apply to third-party websites, products, or services that may be linked to or integrated with the Services; those are governed by the privacy practices of the applicable third party.
- Definitions
- Information We Collect
- How We Use Your Information
- Our Use of Artificial Intelligence
- Legal Basis for Processing (EU/UK GDPR)
- How We Share Your Information
- Cookies and Tracking Technologies
- Data Retention and "Soft Deletion"
- Your Privacy Rights and Choices
- International Data Transfers
- Data Security
- Children's Privacy
- Do Not Track and Global Privacy Control
- Marketing Communications
- Security Incident and Breach Notification
- Automated Decision-Making and Profiling
- Third-Party Links and Services
- Changes to This Policy
- Governing Law and Dispute Resolution
- Contact Us
1. Definitions
Personal Information / Personal Data means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual or household, as defined under applicable law (for example, the CCPA/CPRA and the GDPR).
Processing means any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
Controller / Business refers to RogueTrace as the entity that determines the purposes and means of processing personal information collected through the Services, unless otherwise specified.
Processor / Service Provider means a third party that processes personal information on RogueTrace's behalf and under our instructions.
2. Information We Collect
We collect the following categories of information:
Account & Profile Data: When you create an account, we collect your name, email address, login credentials (stored using industry-standard hashing; we never store your password in plain text), organization or company name, billing information (processed by our payment processor; RogueTrace does not directly store full payment card numbers), and account preferences or settings.
User Uploads & Content: Files, documents, text, images, indicators of compromise, logs, or other materials you submit, upload, or paste into the Services for analysis ("User Content"). User Content may itself contain personal information about you or third parties, for example employee data in a leaked-credential file, or names in a phishing email submitted for analysis. You represent that you have the right to submit any User Content you provide, including any third-party personal information it may contain, and that you have satisfied any notice or consent obligations owed to those third parties before uploading it.
Usage & Technical Data: IP address, browser type and version, device identifiers, operating system, referring and exit pages, timestamps, clickstream data, log files, crash reports, and other technical and interaction data collected automatically as you use the Services.
Cookies & Similar Technologies: Data collected through cookies, pixels, local storage, and similar technologies, described further in Section 7.
Communications: Records of correspondence when you contact us for support, sales, or security inquiries, including the content of your messages.
We do not intentionally collect sensitive categories of personal information, such as government identification numbers, precise geolocation, health information, or biometric data, except where you choose to include such information within User Content you submit, in which case it is handled under the safeguards described in this Policy.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, maintain, and improve the Services, including processing the analyses, reports, and outputs you request.
- To create and manage your account and authenticate your access.
- To communicate with you, including responding to support requests, sending administrative or transactional messages, and, where you have opted in, sending marketing communications.
- To monitor, detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents affecting the Services or our users.
- To comply with legal obligations, respond to lawful requests from public authorities, and enforce our Terms of Service.
- To conduct internal research, analytics, and product development, including understanding how the Services are used so that we can improve them.
- For any other purpose disclosed to you at the time we collect your information, or with your consent.
4. Our Use of Artificial Intelligence
RogueTrace integrates artificial intelligence and machine learning technologies, including third-party large language model providers such as Google's Gemini models, into the core functionality of the Services. When you use AI-assisted features, User Content and related inputs may be transmitted to and processed by these AI systems to:
- Analyze and trace data patterns, indicators of compromise, and other technical artifacts according to the platform's functionality, for example natural-language search and correlation against threat-intelligence frameworks such as MITRE ATT&CK and Sigma rules.
- Automate the generation of insights, summaries, reports, and other analytical outputs.
- Improve, train, and refine our internal models, algorithms, and product features, subject to the limitations below.
Use of Third-Party AI Models
Where we rely on a third-party AI provider to process your data, that provider acts as our service provider or processor and is contractually restricted from using your data for its own independent purposes, except as required to provide the underlying AI service to us. We do not sell your personal information to AI providers.
Training Limitations
We do not use your User Content to train third-party foundation models made available to the general public. Where we use aggregated, de-identified data, or your own account data, to improve RogueTrace's own internal models and features, we take reasonable steps designed to prevent re-identification of individuals. If we ever intend to use identifiable User Content for model training beyond improving the Services you asked for, we will provide additional notice and, where required by law, obtain your consent.
Human Oversight
Outputs generated by AI features are intended to assist, not replace, human judgment. RogueTrace does not use AI to make decisions that produce legal effects concerning you, or similarly significant decisions about you, without the opportunity for human review.
5. Legal Basis for Processing (EU/UK GDPR)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following legal bases:
- Performance of a contract: to provide the Services you have requested and to manage your account.
- Legitimate interests: for security, fraud prevention, service improvement, and analytics, where those interests are not overridden by your data protection interests or fundamental rights.
- Consent: where you have given specific consent, such as for optional marketing communications or certain cookies; you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Legal obligation: where processing is necessary to comply with a legal obligation to which we are subject.
6. How We Share Your Information
We do not sell your personal information for money. We disclose personal information only in the following circumstances:
Service Providers and Data Processors. We share information with vendors who perform services on our behalf, under contractual confidentiality and data protection obligations, including:
- Cloud Storage & Infrastructure Providers: secure cloud infrastructure used to host the Services and store system logs, User Content, assets, and generated reports.
- Analytics Providers: tools used to monitor traffic, performance, and usage trends on an aggregated basis.
- AI Models & Processing Services: third-party machine learning APIs, including Google Gemini and similar providers, used to process inputs and generate outputs as described in Section 4.
- Payment Processors: third-party providers who process subscription and billing transactions.
- Communication Tools: email and customer support platforms used to communicate with you.
Corporate Transactions. If RogueTrace is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be disclosed or transferred to the parties involved, subject to standard confidentiality arrangements and, where required by law, notice to affected users.
Legal Requirements and Safety. We may disclose information where we believe in good faith that disclosure is necessary to comply with a legal obligation, subpoena, court order, or governmental request; enforce our Terms of Service and other agreements; protect the security, rights, property, or safety of RogueTrace, our users, or the public; or detect, prevent, or address fraud, security, or technical issues.
With Your Consent. We may share information with third parties when you direct us to do so or otherwise provide consent.
All third-party service providers who process personal information on our behalf are bound by written data processing agreements requiring them to use the information solely to provide services to us and to maintain appropriate confidentiality and security safeguards, consistent with applicable law, including, where applicable, GDPR Article 28 and analogous state-law requirements for "service providers" and "contractors."
7. Cookies and Tracking Technologies
We and our service providers use cookies, web beacons, pixels, and similar technologies to operate the Services, remember your preferences, understand usage patterns, and support analytics. Categories of cookies we use include strictly necessary cookies required for the Services to function, performance and analytics cookies, and functionality cookies. Where required by applicable law, we will request your consent before placing non-essential cookies and will honor your choices, including signals such as the Global Privacy Control described in Section 13. You can control cookies through your browser settings; disabling certain cookies may affect the functionality of the Services.
8. Data Retention and "Soft Deletion"
When you delete your account or remove content from RogueTrace, we use a practice we call soft deletion, described below, before certain data is eventually and permanently erased.
What Is Soft Deletion?
Unlike hard deletion, which immediately and permanently erases data from all systems, soft deletion flags your profile and associated records as inactive or removed in our production, user-facing systems, while certain records are retained in non-public backend storage for the limited purposes described below.
How Soft Deletion Works at RogueTrace
- User Profile: Your account is deactivated and hidden from public or active-user interfaces. Login access is disabled.
- User Uploads: Files and inputs you directly uploaded are marked for removal from active workflows and are not accessible through the Services going forward.
- System Reports & Storage Buckets: Reports, analytical outputs, system logs, and backend cloud storage generated in connection with your use of the Services may remain in backend systems for the retention period described below, even after your profile and uploads have been soft-deleted.
Why We Use Soft Deletion
We retain certain backend records after soft deletion for legitimate and limited purposes, including maintaining the technical integrity and security of the platform; fulfilling reporting and audit dependencies tied to shared or multi-party investigations; complying with legal, tax, accounting, or regulatory recordkeeping obligations; preserving evidence relevant to actual or reasonably anticipated disputes, claims, or legal proceedings; and detecting and preventing fraud or abuse of the Services.
Retention Periods and Hard Deletion
Soft-deleted data is retained only as long as reasonably necessary for the purposes above, and in any event no longer than thirty-six (36) months following account deletion, except where a longer period is required to comply with a legal obligation, resolve a dispute, or enforce our agreements, in which case we retain only the specific data needed for that purpose and for no longer than necessary. After the applicable retention period, soft-deleted data is permanently and irrecoverably erased, or fully de-identified and anonymized such that it can no longer be associated with you.
Your Right to Request Earlier Deletion
Where required by applicable law, including the CCPA/CPRA, GDPR, and comparable state laws, you may request that we delete personal information sooner than the retention periods above, subject to the exceptions those laws recognize, for example completing a transaction, security, legal compliance, and internal uses reasonably aligned with your expectations. See Section 9.4 for how to submit a request.
9. Your Privacy Rights and Choices
Depending on where you live, you may have some or all of the following rights regarding your personal information. We honor valid requests consistent with applicable law, regardless of where you are located, and we do not discriminate against you for exercising any of these rights.
9.1 If You Are in the European Economic Area or United Kingdom (GDPR / UK GDPR)
You have the right to access the personal data we hold about you; rectify inaccurate or incomplete data; request erasure ("right to be forgotten"), subject to legal exceptions; restrict or object to certain processing, including processing based on legitimate interests and direct marketing; request portability of data you provided to us in a structured, machine-readable format; withdraw consent at any time where processing is based on consent; and lodge a complaint with your local data protection supervisory authority. To the extent required by law, you may also request the identity of our EU or UK representative by contacting us at the address in Section 20.
9.2 If You Are a California Resident (CCPA / CPRA)
You have the right to know what personal information we have collected, used, disclosed, and, if applicable, sold or shared, and the categories and specific pieces of that information; delete personal information we have collected from you, subject to statutory exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information; limit the use and disclosure of sensitive personal information to purposes permitted by law; and not be discriminated or retaliated against for exercising any of these rights. California residents may designate an authorized agent to submit requests on their behalf, subject to identity-verification requirements.
Do Not Sell or Share My Personal Information. RogueTrace does not sell personal information for monetary consideration and does not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. Because we do not engage in these practices, no "Do Not Sell or Share" opt-out mechanism is currently required; if our practices change, we will update this Policy and implement the required opt-out tools, including recognition of the Global Privacy Control.
9.3 If You Are a Resident of Other U.S. States
Residents of states with comprehensive privacy laws currently in effect or coming into effect, including, among others, Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with substantially similar laws, have rights that generally include the right to confirm whether we process your personal data, access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling in furtherance of decisions that produce legal or similarly significant effects. RogueTrace does not engage in the sale of personal data or targeted advertising as those terms are defined under these laws. Where applicable law provides a right to appeal a denied request, we will provide instructions for doing so in our response.
9.4 How to Exercise Your Rights
You may submit a privacy request by contacting us using the details in Section 20. To protect your information, we will take reasonable steps to verify your identity before fulfilling a request, which may include confirming information associated with your account. We will respond to verifiable requests within the timeframe required by applicable law, for example forty-five (45) days for California requests, extendable once by an additional forty-five (45) days when reasonably necessary, and one (1) month for GDPR/UK GDPR requests, extendable by two further months for complex requests, and we will inform you of any extension and the reason for it.
10. International Data Transfers
RogueTrace is based in the United States, and personal information we collect may be stored and processed in the United States and other countries where our service providers operate. If you are located outside the United States, including in the EEA, UK, or Switzerland, your information will be transferred to a country that may not have data protection laws equivalent to those in your home jurisdiction. Where such transfers occur, we rely on appropriate safeguards, which may include Standard Contractual Clauses approved by the European Commission or the UK Information Commissioner's Office, or other lawful transfer mechanisms recognized under applicable data protection law, along with contractual and technical measures designed to protect your information consistent with the level of protection required in your jurisdiction. You may contact us for more information about the safeguards used for a specific transfer.
11. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction, including encryption of data in transit, access controls, network monitoring, and vendor security review. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for notifying us promptly of any unauthorized use of your account.
12. Children's Privacy
The Services are not directed to, and are not intended for use by, individuals under the age of 18, and we do not knowingly collect personal information from children under 13, or the applicable minimum age in your jurisdiction, within the meaning of the U.S. Children's Online Privacy Protection Act ("COPPA") or comparable laws. If we learn that we have collected personal information from a child in violation of applicable law, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us using the details in Section 20.
13. Do Not Track and Global Privacy Control
Some browsers transmit "Do Not Track" signals; because there is no accepted industry standard for how businesses should respond, we do not currently respond to browser Do Not Track signals. Where required by applicable law, we honor the Global Privacy Control ("GPC") signal as a valid request to opt out of the sale or sharing of personal information for browsers or extensions that transmit it, to the extent our practices involve such activity.
14. Marketing Communications
If you receive marketing emails from us, you may opt out at any time by using the unsubscribe link included in those emails or by contacting us directly. We comply with the U.S. CAN-SPAM Act and comparable laws, including honoring opt-out requests promptly and not using false or misleading header or subject-line information. Opting out of marketing communications does not affect transactional or administrative messages necessary to operate your account.
15. Security Incident and Breach Notification
In the event of a security incident that compromises the confidentiality, integrity, or availability of personal information in a manner that triggers notification obligations under applicable law, we will notify affected individuals and, where required, regulators and other authorities, without undue delay and in the manner required by the applicable breach notification law, which may include state data breach notification statutes, GDPR Articles 33-34, and other comparable laws, and we will describe the nature of the incident and the measures taken or recommended in response.
16. Automated Decision-Making and Profiling
Certain features of the Services involve automated processing, including AI-assisted analysis described in Section 4. We do not use automated decision-making, including profiling, to make decisions that produce legal effects concerning you or that similarly significantly affect you, without an opportunity for meaningful human involvement. If this changes, we will update this Policy and provide any additional rights or disclosures required by applicable law, including the right to obtain human intervention, to express your point of view, and to contest an automated decision.
17. Third-Party Links and Services
The Services may contain links to third-party websites, plug-ins, and applications that are not operated or controlled by RogueTrace. This Privacy Policy does not apply to those third-party services, and we encourage you to review their privacy policies before providing any information to them. We are not responsible for the content, security, or privacy practices of third-party sites.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. If we make material changes, we will provide notice as required by applicable law, such as by updating the "Last Updated" date above, posting a notice on the Site, or, where required, contacting you directly. Your continued use of the Services after an update becomes effective constitutes your acceptance of the revised Policy, to the extent permitted by applicable law.
19. Governing Law and Dispute Resolution
This Privacy Policy is governed by the laws of the United States and the state in which RogueTrace is established, without regard to conflict-of-laws principles, except where applicable data protection law requires otherwise, for example rights available to EEA, UK, or California residents under their local law are not diminished by this section. Nothing in this Policy limits any statutory rights you may have that cannot be waived under applicable law.
20. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, including to exercise any of the rights described above, please contact us:
- Website:www.roguetrace.com / roguetrace.com
- For privacy requests and data protection inquiries, please use the contact form on our Contact page or reach out through the channels listed on our Site.
We aim to acknowledge privacy-related inquiries promptly and to respond within the timeframes described in Section 9.4.