Privacy Policy
Last updated: 2026-06-12
1. Who We Are and What This Policy Covers
ShadowGuard is an AI governance and security platform operated by RLS VENTURES, LLC ("ShadowGuard," "we," "us"). It helps organizations discover AI tools connected to their Google Workspace and Microsoft 365 environments, maintain an AI system registry, assess risk, and produce governance reports and evidence.
This policy explains what we collect when you use the ShadowGuard service at shadowguard.us, why we collect it, and the choices you have. It applies to account holders and to the workspace data their organization connects. If your employer connected your workspace to ShadowGuard, your employer is the data controller for that workspace data and we process it on their behalf.
2. Information We Collect
Account and profile data. Your email address, authentication credentials (passwords are hashed by our authentication provider, Supabase Auth, and never visible to us), your role within your organization, and your multi-factor authentication enrollment status. If MFA backup codes are issued, we store only one-way hashes of them.
Organization and workspace data. Your organization name, email domain, membership, member roles, and subscription plan.
Google / Microsoft connection data. When an administrator connects Google Workspace or Microsoft 365, we receive OAuth tokens authorized by that administrator. Tokens are encrypted at rest with AES-256-GCM before storage. We use them only to enumerate third-party applications and OAuth grants in your tenant — which apps are connected, which permission scopes they hold, and which users granted them. We do not read email bodies, file contents, calendars, or chat messages. Disconnecting a workspace stops further collection.
Scan and governance data. The output of scans and the records your team creates in the product: the application inventory, OAuth permission scopes, the workspace email addresses of users connected to each app, risk scores and their history, AI system registry entries, risk assessments, control status, evidence records (we store titles, links, and notes you enter — the product does not host uploaded documents), report snapshots, and audit logs of actions taken in the product.
AgentGuard and MCP activity metadata.When activity is submitted for classification, content is analyzed in memory and we persist only the classification result (for example, "contains PII") and the content length. Raw prompt or response content is not stored.
Billing data. Payments are processed by Stripe. We store your Stripe customer and subscription identifiers and billing event records. We never see or store full card numbers.
Operational logs. Timestamps, IP addresses, user agents, and request identifiers, used for security monitoring, abuse prevention, and debugging.
3. How We Use Information
- To provide the service: scanning, risk scoring, registry, reports, and alerts.
- To authenticate you and keep your organization's data isolated from other tenants.
- To send transactional messages such as confirmation, password reset, and security notices.
- To bill subscriptions through Stripe.
- To detect, investigate, and prevent abuse or security incidents.
- To comply with legal obligations.
We do not sell customer data. We do not share it with advertisers. We do not use customer data to train AI models.
4. Legal Bases
Where the GDPR or similar laws apply, we process data to perform our contract with you (providing the service), to pursue our legitimate interests (securing and improving the service, preventing abuse), to comply with legal obligations (tax and accounting records), and — for any optional communications — with your consent, which you can withdraw at any time.
5. Sub-processors
We use the following providers to operate the service:
- Supabase — database, authentication, and storage (US).
- Vercel — application hosting (US).
- Stripe — payment processing (US).
- Cloudflare — DNS, CDN, and CAPTCHA where enabled (global).
- Google LLC — Workspace APIs called on your organization's behalf when connected.
- Microsoft Corporation — Graph APIs called on your organization's behalf when connected.
- Upstash — request rate limiting, where configured (US).
We will update this list when sub-processors change. A Data Processing Addendum is available on request.
6. Data Retention and Deletion
- Account and organization data is retained for the life of your subscription and deleted within 30 days after termination, except where law requires longer retention.
- OAuth tokens are deleted when you disconnect a workspace or close your account.
- Operational logs are retained for 30 days.
- Billing records are retained for 7 years for tax compliance.
- You can request earlier deletion of your organization's data at any time using the contact below.
7. Security
- All traffic is encrypted in transit with TLS 1.2 or higher.
- Workspace OAuth tokens are encrypted at rest with AES-256-GCM, with support for key rotation.
- Database row-level security isolates each organization's data at the database layer.
- Administrative actions require multi-factor authentication.
- Administrative and governance actions are recorded in an audit log.
No system is perfectly secure. If we learn of a breach affecting your data, we will notify affected customers without undue delay and as required by law.
8. Your Rights
Depending on your jurisdiction (including the GDPR, UK GDPR, CCPA/CPRA, and LGPD), you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@shadowguard.us. We respond within the timelines required by applicable law. If your data was provided through your employer's workspace, we may direct your request to your employer as the controller.
9. International Transfers
Customer data is processed in the United States. Where data is transferred from the EU, UK, or other regions with transfer restrictions, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Cookies
We use strictly necessary cookies for authentication and security (your Supabase session and OAuth state), and we store interface preferences (such as theme and your cookie-banner choice) in your browser's local storage. We do not use advertising cookies or third-party analytics cookies.
11. Children
The service is intended for business use and is not directed to anyone under 16. We do not knowingly collect data from children.
12. Changes and Contact
If we make material changes to this policy, we will notify account owners by email at least 30 days before the changes take effect.
Questions or requests: privacy@shadowguard.us
RLS VENTURES, LLC, Edmond, OK 73013-7517
