1. Overview
This Privacy Policy describes how Anchor Cyber Security LLC ("we", "us", "our") collects and uses information in connection with BitDrip — our self-hosted AI privacy protection software — and the portal.bitdrip.app registration and licensing portal.
The architecture boundary: The customer-controlled proxy, policy engine, and dashboard process supported AI content paths in the customer's environment. The separate Anchor-operated portal processes account, licensing, billing, deployment, and release-delivery data described below. Prompt and response content is not part of the portal's documented current data path.
2. What We Collect
We collect only the data strictly necessary to fulfill your license and operate the portal.
Registration data — when you create an account at portal.bitdrip.app:
- Full name
- Email address
- Organisation name
Payment data — when you purchase a subscription:
- Payment is processed entirely by Stripe, Inc. We never see, store, or handle your card number, CVV, or full payment details.
- We receive only a transaction confirmation and the associated Stripe customer ID so we can link your payment to your license.
License validation fingerprint — once BitDrip is running in your environment:
- The software periodically contacts portal.bitdrip.app to confirm the license is active. The automated telemetry contains authentication and license data, a deployment fingerprint, the reported server hostname when available, the running version, and health status.
- The fingerprint is a one-way identifier used solely to count distinct deployments against your license limit — it cannot be reversed to reveal user activity, prompts, or policy data.
- The automated deployment check-in telemetry does not include workstation end-user identity, AI prompt or conversation content, policy configurations, violations, or audit log contents in the documented current path. Registration and support contact data are collected separately as disclosed above; any expansion of automated telemetry requires documentation and approval before release.
Support communications — when you initiate a support request, we receive the contact details and information you choose to provide for that request. Do not include AI prompt content, credentials, private keys, or unnecessary personal data.
3. What We Do NOT Collect
The following data is not part of the Anchor-operated portal's documented current collection path:
- Conversation content — prompts sent to AI services and their responses
- Detected violations or the content that triggered a policy rule
- Employee names, user accounts, or any user data managed inside your BitDrip deployment
- Audit logs generated by your BitDrip installation
- Network topology or internal IP addresses
- Any data processed by the self-hosted policy engine, API gateway, or dashboard
4. How We Use Your Information
- Issue and manage your BitDrip license file
- Send you download links, product updates, and your license renewal notices
- Process your subscription payment via Stripe
- Respond to your support requests
- Verify that an active license is associated with a given installation (via the fingerprint hash)
- Comply with legal obligations
We do not sell your personal data. We do not use your data for advertising or behavioural profiling.
5. Third-Party Processors
We use the following service providers to operate the commercial portal, billing, email, and release delivery:
Stripe, Inc.
Payment processing. Handles all card and billing data. Privacy policy at stripe.com/privacy.
SendGrid (Twilio)
Transactional email delivery — account access, license, download, billing, and renewal messages.
Proton AG
Human-operated support and business mailboxes, including replies to customer support requests.
Cloudflare, Inc.
DNS, CDN, DDoS protection, portal application hosting, licensing data storage, and release delivery. Processes account records and connection metadata under Cloudflare's privacy policy.
6. Data Retention
- Account, authentication, license, deployment, and release-delivery data: retained while needed to provide and secure the service, administer the relationship, resolve disputes, preserve release or security evidence, or meet applicable legal and contractual duties.
- Billing and billing-adjacent records: Stripe applies its own retention obligations. Anchor retains bounded records it receives according to documented business, accounting, tax, dispute, security, and legal-hold criteria.
- Support communications and provider copies: retention depends on the request, system, provider behavior, applicable agreement, and any legal, security, incident, investigation, or dispute hold.
An approved fixed product-data retention and deletion schedule is pending validation of the data map, provider terms, backups, logs, and tested deletion behavior. Until approved, no routine deletion clock is promised. You may request deletion as described in Section 7; we will verify authority and scope, assess applicable duties and holds, and explain the available action or status.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request erasure of your data (subject to legal retention requirements)
- Portability — receive your data in a structured, machine-readable format
- Objection / Restriction — object to or restrict certain processing activities
- Opt out of sale — we do not sell personal data; this right is satisfied by our business model
To exercise any of these rights, email privacy@anchorcybersecurity.com. We will respond within 30 days. We may need to verify your identity before acting on a request.
8. Security
- In transit: Data transmitted to and from portal.bitdrip.app is protected with HTTPS/TLS.
- At rest: Encryption at rest is a required control for portal database and release records. Verification of the deployed provider configuration, key controls, logs, and backup behavior remains pending the validated data-map evidence.
- Infrastructure: The commercial portal and licensing control plane run on Cloudflare Workers, D1, and R2. Customer policy data remains in the customer's self-hosted environment.
- Access control: Role-restricted administrative access is a required control. The deployed identity, authorisation, access-review, and administrative-logging evidence remains pending validation; this policy does not claim those controls have been fully verified.
While we take these precautions, no transmission over the internet is guaranteed to be 100% secure. Please report security concerns to privacy@anchorcybersecurity.com.
9. Children
BitDrip is enterprise software intended for use by organisations and their employees. We do not knowingly collect personal data directly from individuals under the age of 18. If you believe such data was provided, contact us so we can verify the request and determine the appropriate action under applicable duties, system behavior, and preservation requirements.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes — such as collecting new categories of data or sharing data with new third parties — we will notify registered users by email at least 30 days before the change takes effect. This revision was published on 2026-08-28 and is scheduled to become effective 2026-09-27; the prior version remains effective until 2026-09-27. Registered-user notice is required before that effective date. This page does not state that notice has already been sent. Continued use of the portal after the applicable effective date constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions, data subject requests, or to report a concern: