SentrinelNet

Privacy Policy

Last updated: May 1, 2026

1. Introduction

SentrinelNet, operated by Xtrinel ("we", "us"), is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

2. Information We Collect

We collect the following information: email address and display name (provided during authentication via Microsoft Entra ID), agent metadata and configuration data submitted for scanning, scan results and findings generated by the Service, credit usage and billing transaction records, and Blue Guardian event telemetry data.

3. Information We Do NOT Collect

Agent source code, model weights, and training data are not stored long-term. Content submitted for analysis (system prompts, tool schemas, agent configurations) is processed transiently in memory to produce results and is not persisted beyond the active scan session.

4. How We Use Your Information

We use your information to: provide and operate the Service, process credit transactions and billing, send transactional emails (welcome, credit alerts, scan results), improve the Service through aggregated and anonymized usage analytics, and comply with legal obligations.

5. Data Retention

Blue Guardian event data is retained for 7 days on Free plans and 90 days on Pro plans. Scan results and compliance reports are retained for 30 days. Account information is retained for the duration of your account. Upon account deletion, all associated data is purged within 30 days.

6. Sub-Processors

We use the following third-party processors to deliver the Service: Anthropic (AI analysis), Microsoft Azure (infrastructure, authentication, database), Amazon Web Services (transactional email), Stripe (payment processing), and Cloudflare (DNS, CDN, security). Each processor is contractually bound to process your data only as necessary to provide their services to us.

7. Data Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest for all stored data, role-based access controls, and regular security assessments. All secrets and credentials are stored in Azure Key Vault with managed identity access.

8. Your Rights

You have the right to: access the personal data we hold about you, request correction of inaccurate data, request deletion of your data (contact legal@xtrinel.com — data will be purged within 30 days), export your scan results and compliance reports, and withdraw consent for marketing communications at any time through your account settings.

9. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on the Service. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

For questions about this Privacy Policy or to exercise your data rights, contact us at legal@xtrinel.com.