Privacy Policy
We believe in transparency about how we collect and use data. This policy describes exactly what we collect, why, and how we protect it.
Table of Contents
- 1. Overview
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Third-Party Service Providers
- 5. Uploaded Files and Scan Data
- 6. Data Retention
- 7. Security
- 8. Cookies and Local Storage
- 9. Your Rights and Choices
- 10. Children's Privacy
- 11. International Data Transfers
- 12. Changes to This Policy
- 13. Contact Us
1 Overview
Strata Security ("we," "us," or "our") operates the Strata Security application security assessment platform ("Service") at strata-security.com. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Service.
By using the Service, you agree to the collection and use of information described in this policy. If you are using the Service on behalf of an organization, you represent that you have authority to bind that organization to this policy.
2 Information We Collect
Account Information
When you create an account, we collect:
- Email address (required)
- Full name (optional, collected during onboarding)
- Organization name (optional)
- Password (hashed; we never store plaintext passwords)
Usage Data
When you use the Service, we automatically collect:
- IP address and approximate geographic location
- Browser type and version, operating system
- Pages visited and actions taken within the Service
- Timestamps of logins and activity
- API request logs (endpoint, status, duration) — retained for operational purposes
Uploaded Content
When you use the Service, you may upload application files (APKs, IPAs, ZIP archives, source code) and provide repository URLs or CI/CD webhook configurations. See Section 5 for details on how we handle this data.
Billing Information
If you subscribe to a paid plan, payment is processed by Stripe. We do not store credit card numbers or full card data on our servers. We receive from Stripe: the last four digits of your card, card type, billing name, and billing email.
Communications
If you contact us by email or through our contact form, we retain those communications to respond to your request and improve our support.
Error and Performance Data
We use Sentry for error tracking. When an error occurs, Sentry may capture the stack trace, browser user agent, device type, the URL where the error occurred, and user-provided context (such as your user ID). We configure Sentry to minimize capture of personal data.
3 How We Use Your Information
We use the information we collect to:
- Provide the Service — process your scans, generate reports, manage your account
- Authenticate you — verify your identity and protect your account
- Send transactional emails — scan completion notifications, billing receipts, password resets, account verification
- Process payments — bill for subscriptions, send invoices, handle disputes
- Provide support — respond to your questions and resolve issues
- Improve the Service — analyze usage patterns to identify features to build and bugs to fix
- Ensure security — detect and prevent abuse, fraud, and unauthorized access
- Comply with legal obligations — respond to lawful requests from authorities
We do not sell, rent, or share your personal information with third parties for their marketing or advertising purposes. We do not use your security findings or uploaded Content to train AI models or for any purpose other than delivering the Service to you.
4 Third-Party Service Providers
We use the following third-party providers to operate the Service. Each provider processes data on our behalf under a data processing agreement and their own privacy policies.
Supabase hosts our PostgreSQL database, authentication system, and file storage. Your account data (email, profile, organization memberships), scan metadata (filenames, results, timestamps), and uploaded files are stored in Supabase infrastructure. Supabase operates on AWS in the US East region. Row-Level Security policies ensure that your data is only accessible by your organization's members.
Stripe processes subscription payments and stores your billing information (card details, billing address). When you subscribe, you interact directly with Stripe's secure checkout. We store only the Stripe customer ID and last-four card digits on our servers. Stripe is PCI-DSS Level 1 certified.
Resend delivers transactional emails such as scan completion notifications, account verification emails, password reset emails, and billing receipts. Resend receives your email address and the content of these emails. Email content may include your name, organization name, scan result summaries, and links to view full reports.
Sentry captures application errors and performance data to help us diagnose and fix bugs. When an error occurs, Sentry may receive your anonymized user identifier, browser information, the URL where the error occurred, and the error stack trace. We configure Sentry to avoid capturing raw personal data in error events.
Upstash Redis is used for rate limiting (tracking request counts per user), upload job locking (preventing duplicate concurrent scans), token revocation (invalidating sessions), and notification deduplication. Data stored in Redis is short-lived (seconds to hours) and does not include full personal data — only hashed user identifiers and counters.
If configured, uploaded files may be checked against VirusTotal's file reputation database using a cryptographic hash (SHA-256). We do not upload file contents to VirusTotal — only the hash is sent. VirusTotal may log query hashes and associate them with our API key. VirusTotal integration can be disabled for self-hosted or private deployments.
The Strata Security backend API is hosted on Render (render.com). The frontend is hosted on Vercel or similar static hosting. These providers run the servers and network infrastructure needed to operate the Service and may log IP addresses and request metadata for operational purposes.
5 Uploaded Files and Scan Data
What We Store
When you upload a file (APK, IPA, ZIP, or other) for analysis, we:
- Store the file in Supabase Storage, encrypted at rest
- Process the file to extract security findings
- Store the resulting security report and finding details in our database
- Associate the file and results with your organization's isolated data partition
Data Isolation
Your organization's data is isolated from other organizations using Supabase Row-Level Security (RLS) policies. No other organization can access your files, scan results, or findings.
What We Don't Do
We do not share your uploaded files or security findings with third parties. We do not use your uploaded Content to train machine learning models (unless you have explicitly opted in). We do not sell or license your findings to anyone.
Repository and CI/CD Data
If you connect a GitHub or GitLab repository, we store OAuth tokens (encrypted using AES-256 Fernet encryption), repository identifiers, and webhook configurations needed to perform security scans. Repository source code is processed transiently during scans and is not retained beyond what is needed for the scan.
6 Data Retention
We retain data for the following periods:
- Scan files and results: 30 days (Free tier), 1 year (Pro), indefinitely (Team), unless you delete them earlier
- Account information: Retained for the life of your account. Upon account deletion, personal data is deleted within 30 days, except where retention is required by law (e.g., billing records retained for 7 years for tax compliance)
- API and server logs: 90 days for operational logs; security event logs may be retained longer
- Redis/Upstash data: Rate limiting counters and locks expire automatically in seconds to hours
- Backup data: Deleted data may persist in encrypted backups for up to 30 days before permanent removal from backup media
You can delete your scans, files, and reports at any time through the Service. To request account deletion, contact support@strata-security.com.
7 Security
We take security seriously and implement industry-standard protections:
- Encryption in transit: All data is transmitted over HTTPS/TLS
- Encryption at rest: Data stored in Supabase is encrypted at rest by the cloud provider
- OAuth tokens: Encrypted using AES-256 Fernet encryption before database storage
- Password security: Passwords are hashed using bcrypt by Supabase; we never see or store plaintext passwords
- Access controls: Role-based access control limits what each user can access within an organization
- Rate limiting: Request rate limiting protects against credential stuffing and abuse
- Monitoring: Sentry monitors application errors; we monitor for unusual activity
No method of transmission or storage is 100% secure. While we implement strong security measures, we cannot guarantee absolute security. If you discover a security vulnerability, please report it to security@strata-security.com. See our Security page for our responsible disclosure policy.
9 Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate personal data (most can be updated directly in account settings)
- Deletion: Request deletion of your account and personal data
- Portability: Request your data in a machine-readable format
- Restriction: Request that we limit processing of your data in certain circumstances
- Objection: Object to certain types of processing
- Withdraw Consent: Where processing is based on consent, withdraw that consent at any time
To exercise these rights, contact us at privacy@strata-security.com. We will respond within 30 days (or as required by applicable law). We may need to verify your identity before processing certain requests.
Email Communications
Transactional emails (scan results, billing, security alerts) cannot be opted out of while your account is active, as they are necessary for the Service. You can delete your account to stop receiving all communications.
Account Deletion
To request complete account deletion, email support@strata-security.com from your registered email address. We will process the deletion within 5 business days and confirm when complete.
10 Children's Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal information from a child, we will delete it promptly. If you believe we may have data from a minor, contact privacy@strata-security.com.
11 International Data Transfers
Strata Security is based in the United States. Our third-party providers (Supabase, Stripe, Resend, Sentry, Upstash) operate primarily on US infrastructure. If you use the Service from outside the United States, your information will be transferred to, and processed in, the United States and other countries where our providers operate.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) and the data processing agreements with our sub-processors as the lawful mechanism for international data transfers. Contact us if you have questions about the transfer mechanisms in place.
12 Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes affecting how we collect, use, or share your personal data, we will notify you by email and/or by prominent notice in the Service at least 14 days before the change takes effect.
For non-material changes (corrections, clarifications), we may update this policy with the revised date shown at the top without advance notice. Your continued use of the Service after changes take effect constitutes acceptance.
13 Contact Us
For privacy-related questions, requests, or concerns:
- Privacy inquiries: privacy@strata-security.com
- Security vulnerabilities: security@strata-security.com
- General support: support@strata-security.com
- Contact form: strata-security.com/contact
Privacy Questions?
We're committed to transparency. If you have questions about how we handle your data, we're happy to explain.