Binary Intelligence

Privacy

Effective date: [EFFECTIVE_DATE]. Owner: C2Consultants, LLC, registered at [COMPANY_ADDRESS].

Draft — pending counsel review.

This notice reflects the operational privacy posture of Binary Intelligence and is published for transparency. Final binding language is delivered by counsel before first sale; that final language supersedes this page in case of conflict.

This notice covers the public website, the customer portal, and the Binary Intelligence Windows client. We minimize personal data collection by design and are explicit about what telemetry the client contributes.

What we collect on the website

  • No third-party analytics, no cookies, no advertising tracking on the public marketing pages.
  • Forms (contact, sales, support) collect the fields you submit, used to respond to your inquiry.
  • The customer portal sets a single HttpOnly + Secure + SameSite=Lax session cookie (bi_session) used only to authenticate you. No tracking cookie is set.

What we collect at checkout and in your account

  • Email address (used as your account identifier and for transactional email).
  • Billing address and tax ID, collected by Stripe and used for invoicing and tax compliance.
  • Subscription state (active, cancelled, refunded) and a record of licenses issued.

Telemetry from the client

Binary Intelligence contributes anonymized signals to the shared Mimir corpus to improve detection and reasoning. Contribution behavior varies by tier:

  • Home: contribution is mandatory and a condition of the Home license.
  • SMB: contribution is enabled by default; you can opt out from Settings → Telemetry in the client.
  • Enterprise: contribution is disabled by default; you can opt in.

Contributed signals consist of:

  • Hashed error signatures (deterministic hashes derived from the structure of the event, not its content).
  • Service / component identifiers as exposed by Windows (e.g. Service-Spooler, DismApi).
  • Remediation outcome (succeeded / failed / validated-healthy) and the validation interval.
  • Anonymous installation ID (generated locally; not tied to the customer email or activation key).

Contributed signals do NOT include:

  • Machine names, user names, IP addresses, MAC addresses, or BIOS serial.
  • File contents, registry contents, command output, or stack traces.
  • Personal data of any kind from your environment.
  • The activation key, the license envelope, or any value that could correlate signals back to a customer.

What we share

We do not sell personal data. We share data with the subprocessors listed in our DPA (Microsoft Azure, Stripe, Microsoft 365) only as needed to deliver the service. We disclose data to law enforcement only in response to a valid legal process.

Your choices

  • Telemetry opt-out (SMB and Enterprise): toggle in the client.
  • Email opt-out: transactional emails (license delivery, billing) cannot be turned off while you have an active subscription. We send no marketing emails by default; any future newsletter will be opt-in.
  • Account deletion: request via privacy@binaryintelligence.ai. Account personal data is deleted within 30 days; license-audit metadata (claim IDs, issuance/renewal/revocation timestamps) is retained as required to operate the licensing system.

EU, UK, and California residents

Data subjects in the EU/EEA, UK, and Switzerland have rights under GDPR/UK GDPR (access, rectification, erasure, portability, restriction, objection). California residents have rights under the CCPA/CPRA (know, delete, correct, opt out of sale — we do not sell). To exercise any right, contact privacy@binaryintelligence.ai.

Security

Activation keys are stored only as sha256(pepper || key). License envelopes are signed in Azure Key Vault using RS256-PSS; private keys never leave the HSM. Session cookies are HttpOnly + Secure + SameSite=Lax. Webhook signatures are verified on every payment event.

Contact

privacy@binaryintelligence.ai