Sentinel Privacy Policy
Privacy policy for the NUURBY platform, Chrome extension, and Network Agent.
NUURBY Technologies — Privacy Policy

Last updated:

Note: This policy is written to accurately describe what NUURBY actually does, but it is a draft and has not been reviewed by an attorney. If you're relying on this for compliance purposes (GDPR, CCPA, or otherwise), have it reviewed by qualified legal counsel before treating it as final.

This Privacy Policy explains what information NUURBY Technologies ("NUURBY," "we," "us") collects across our platform — the web dashboard, the NUURBY Sentinel Chrome extension, and the NUURBY Network Agent — how we use it, and what choices you have.

1. Information We Collect

Account information: when you sign up, we collect your email address, a hashed (never plaintext) password, and your organization/company name.

Billing information: if you subscribe to a paid plan, payment is processed by Stripe. We do not receive or store your full card number — Stripe handles that directly. We do receive and store your subscription status, plan, and billing history metadata from Stripe.

Security data you generate: asset inventories, vulnerability findings, detection alerts, incident records, log data, and zero-trust policies you create by using the platform against your own authorized environment. This data is yours — see Section 4.

Contact form submissions: name, email, company, job details, and message content you submit through our contact form.

Extension and Network Agent data: see Section 7 — these components communicate only with the NUURBY instance you configure, not with us.

2. How We Use Information

To provide and maintain the platform; to process payments and manage subscriptions; to respond to contact form inquiries; to send account-related notifications (security alerts you've configured, billing receipts); and to improve the product. We do not sell your personal information, and we do not use your security scan data (vulnerability findings, asset inventories, etc.) to train any AI model or for any purpose beyond delivering the service to you.

3. Third-Party Services We Use

We rely on the following providers to operate NUURBY. Each has its own privacy policy governing how they handle data on our behalf:

Anthropic — email content you submit for phishing analysis, and select security telemetry, is sent to Anthropic's Claude API for AI-assisted analysis.

Stripe — payment processing for paid subscriptions.

Zoho Mail — receives and processes contact form notification emails.

Google Translate — powers the language switcher in our site footer; translation happens in your browser via Google's service.

DigitalOcean — hosts our infrastructure and databases.

4. Your Security Data Is Yours

Vulnerability findings, asset inventories, detection alerts, and other security data generated by scanning your own environment belong to you. Each client organization's data is isolated from every other client's — see our multi-tenancy architecture. We do not access, review, or share this data except: (a) to provide the service to you, (b) when legally required, or (c) with your explicit permission.

5. Data Retention & Security

We retain account and security data for as long as your account is active. If you cancel your subscription, your data remains accessible during any applicable grace period, after which it may be deleted. Passwords are hashed with bcrypt and never stored in plaintext. Sessions are revocable server-side tokens, not indefinitely-valid credentials.

6. Your Rights & Choices

You can access, correct, or request deletion of your account data by contacting us (Section 9). If you're in a jurisdiction with statutory data rights (GDPR, CCPA, or similar), you may have additional rights to data portability, restriction of processing, or objection — contact us to exercise these.

7. The Chrome Extension & Network Agent

The NUURBY Sentinel Chrome extension, once configured with your NUURBY instance URL, reads your security posture score, alerts, vulnerability counts, incident counts, and hunting results directly from the instance you specify — using the same authenticated API your web dashboard already uses. It sends no data to NUURBY's developers, to any analytics service, or to any third party. There is no backend server operated by the extension itself.

The NUURBY Network Agent, run locally on your machine, scans the network it's installed on (with your explicit authorization at each scan) and pushes results only to the NUURBY instance URL you configure. It requires no admin/root privileges for its TCP-connect-based scanning and performs no ICMP or ARP scanning.

NUURBY Clean Web (part of the extension, version 1.1.0+) blocks requests to a curated list of known ad, tracker, fingerprinting, and malvertising domains, and hides common ad elements on pages you visit. This requires broad permission to see and block network requests across the websites you visit — all of this happens locally in your browser. No list of sites you've visited, no browsing history, and no page content is ever sent to NUURBY's servers or to any third party. The only data involved is a running count of items blocked, stored locally on your device. You can disable Clean Web entirely, or add your own custom allow/block domains, from the extension's settings at any time.

8. Cookies & Local Storage

We use browser local storage to keep you signed in between visits (a session token, not a tracking cookie). We do not use third-party advertising cookies or cross-site tracking.

9. Children's Privacy

NUURBY is a business-to-business security platform not directed at children, and we do not knowingly collect information from anyone under 18.

10. Changes to This Policy

We may update this policy as the product evolves. Material changes will be reflected in the "Last updated" date above.

11. Contact Us

Questions about this policy or your data can be sent through our contact form, or to [email protected].