Sentrail
Legal

Privacy Policy

Effective January 1, 2026. This Privacy Policy explains how ZerwOne Network LLC ("ZerwOne", "we", "us") collects, uses, and shares information about you when you use Sentrail.

1. Information we collect

We collect the following categories of information:

  • Account data — email, name, hashed password or OAuth identifier, and authentication tokens.
  • Operational data — scan history metadata (host, summary counts, timestamps), audit logs of agent tool calls, and admin configuration choices.
  • Transient data — database connection strings and SQL submitted for scanning, held in volatile memory for the duration of a request and not written to our persistent stores.
  • Device & usage data — IP address, user agent, page views, and approximate location derived from IP.
  • Cookies — strictly necessary cookies and authentication tokens. We do not use third-party advertising cookies.

2. How we use information

  • To provide, operate, and maintain the Service;
  • To authenticate you and prevent fraud or abuse;
  • To improve, secure, and audit the Service;
  • To respond to your support requests and communicate operationally important updates;
  • To comply with our legal obligations and enforce our Terms.

3. Legal bases (GDPR)

Where the GDPR applies, we rely on the following legal bases: (a) performance of a contract to provide the Service; (b) compliance with legal obligations; (c) our legitimate interests in operating and securing our business; and (d) your consent, where required.

4. Sharing & sub-processors

We do not sell personal information. We share data only with:

  • Infrastructure providers — Cloudflare (edge & CDN), Supabase (database & auth), and your selected AI provider (OpenAI, Anthropic, Google, or the Lovable AI Gateway).
  • Payment processors — when you purchase a paid plan.
  • Authorities — when required by law or to protect rights, safety, and security.

5. International transfers

We operate primarily from the United States. If you access the Service from outside the U.S., you consent to the transfer of your information to the U.S. and other jurisdictions where our sub-processors operate, subject to appropriate safeguards (Standard Contractual Clauses where required).

6. Data retention

We retain account data for as long as your account is active and for a reasonable period thereafter to comply with our legal obligations. Audit logs are retained for up to 24 months. Transient scan data is not retained.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, or object to certain processing of your personal information, and to data portability. To exercise these rights, contact privacy@sentrail.dev. We will respond within applicable statutory timeframes.

8. Security

We implement administrative, technical, and physical safeguards designed to protect your information, including TLS in transit, encryption at rest for stored data, role-based access controls, and audit logging. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

9. Children

The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. The "Effective" date above indicates when it was last revised. We will provide reasonable notice of material changes.

11. Contact

Privacy questions or requests: privacy@sentrail.dev. Postal: ZerwOne Network LLC, Privacy Office, United States.

This Privacy Policy template is adapted from common SaaS boilerplate (informed by GDPR Art. 13/14 disclosures and CCPA notice requirements) and is provided for informational purposes only. It is not legal advice. Review with qualified counsel before relying on it.