Legal

Privacy Policy

How Shieldra collects, uses, protects, and processes personal information and customer data. Version 2026-09-16, effective September 16, 2026.

Key takeaways

  • Shieldra collects account details you provide plus usage, security, and consent-record data; we do not sell personal information.
  • The standard platform is a No-PHI service — it is built for policies, risk assessments, and audit evidence, not protected health information. Do not upload PHI unless Shieldra authorizes it in writing.
  • Customer data is encrypted at rest with AES-256 and in transit with TLS, behind role-based access control and multi-factor authentication.
  • AI features run through Shieldra-managed providers — Anthropic, OpenAI, and Google — under terms that exclude training on your data; prompts and responses are stored per-tenant for history and auditability, with optional bring-your-own-key.
  • No advertising or remarketing technology loads without your consent: Google Analytics 4 (where enabled) is consent-gated with Consent Mode v2, Cloudflare Web Analytics is cookieless, and the Meta Pixel loads only if you enable the optional Marketing category.
  • You can request access, correction, deletion, or portability at shieldra.ai/privacy-request or privacy@shieldra.ai.

What we collect and why

We collect account and signup data — name, work email, company name, a hashed password, signup IP address, and records of which document versions you accepted — plus usage and security data such as server logs, tenant audit trails, session and device information, and multi-factor authentication data.

Website and sign-up measurement: Shieldra’s own first-party measurement records the public pages you view and steps such as starting or completing a free checker (the resulting risk tier, never your answers) or opening the sign-up page, how you arrived (utm campaign parameters, the referring domain, and which kind of ad click identifier was present), your approximate country from our CDN, and your device type. We do not store your IP address or user-agent string for this. If you create an account, the campaign parameters, landing page, and ad click identifier from your visit are stored with it.

Customer Data processed on your organization’s behalf can include uploaded documents and evidence, compliance questionnaires and classification records, device posture data from connected MDM tools, cloud security findings from CSPM tools, security-training records, and prompts and responses from AI features — governed by our Data Processing Addendum. For business outreach we process business contact details from public and professional sources and enrichment providers (currently Hunter.io), with delivery, open, click, and unsubscribe events.

Protected health information (PHI)

The standard Shieldra platform is a No-PHI service. It is intended for compliance documentation, policies, risk assessments, audit evidence, and related operational materials — not protected health information. You must not upload PHI, including within monitoring feeds or access logs from connected systems, unless Shieldra expressly authorizes that processing in writing.

Where PHI processing is separately authorized, Shieldra handles it under the applicable No-PHI acknowledgment, contingent Business Associate Agreement, or separate BAA, and applies appropriate administrative, physical, and technical safeguards.

How we protect your data

  • AES-256 encryption at rest and TLS encryption in transit
  • Role-based access controls and multi-factor authentication
  • Audit logging and continuous automated monitoring
  • A responsible disclosure program (security@shieldra.ai)

AI features, sharing, sub-processors, and analytics

AI features are powered by Shieldra-managed large language model providers — currently Anthropic, OpenAI, and Google — acting as sub-processors under agreements or service terms that exclude use of your data to train their models. Calls route through Shieldra’s backend with automated redaction applied where applicable; prompts, responses, and usage metadata are stored in your workspace for history and auditability and are deleted with your tenant data. If your organization configures its own AI provider key (bring your own key), those calls are governed by your organization’s agreement with that provider.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising unless you expressly enable the optional Marketing cookie category.

Third-party services we use

  • Railway, Neon, and Cloudflare — application hosting, managed PostgreSQL, and DNS/CDN plus R2 object storage for customer documents.
  • Stripe — payment processing. Card details go directly to Stripe and never touch our servers.
  • Resend — transactional and program email delivery.
  • Google Analytics 4 — where enabled on our sites, run with IP anonymization and Google Consent Mode v2, denied by default until you accept analytics cookies. Google Signals and remarketing are not enabled.
  • Cloudflare Web Analytics — cookieless, privacy-preserving measurement.
  • Shieldra first-party measurement — without analytics consent, a random identifier and campaign source kept in session storage for the current tab only; with Analytics consent, also a random visitor identifier in local storage and a first-party sh_attr cookie (90 days). Events are deleted after 13 months.
  • Google Ads — if you enabled Marketing before signing up, the ad click identifier from your visit and the time of your sign-up or first payment may be uploaded so Google can measure our campaigns. Ad click identifiers stored with an account are deleted 180 days after the click.
  • Meta (Facebook) Pixel — loads only if you enable the optional Marketing consent category; no advertising or remarketing technology loads without your consent.
  • Google Drive (optional) — requests only the narrow drive.file OAuth scope, so Shieldra sees only files you explicitly pick plus files it creates. Use of Google API data follows the Google API Services User Data Policy, including Limited Use.
  • Microsoft 365 / OneDrive (optional) — delegated, read-only Files.Read.All and User.Read scopes, revocable at any time from your Microsoft account.

Retention, transfers, and your rights

Account data is retained for the life of the account. Customer Data is exportable for 30 days after termination and is deleted or anonymized within 90 days of a deletion request, except where law or our legitimate audit and dispute-resolution needs require retention — certain compliance and incident records are retained for up to six years, as described in the Terms.

Our services are hosted in the United States, so information from outside the US is transferred there; where GDPR or similar laws apply we rely on Standard Contractual Clauses and equivalent safeguards under our DPA. Depending on your jurisdiction you may have rights to access, correct, or delete your personal information, opt out of marketing, request portability, and withdraw consent — submit requests through shieldra.ai/privacy-request or privacy@shieldra.ai and we respond within 30 days.

Frequently asked questions

Does Shieldra store protected health information?

The standard Shieldra service is a No-PHI platform intended for compliance documentation, policies, risk assessments, and audit evidence. You must not upload PHI unless Shieldra authorizes that processing in writing, in which case it is governed by the applicable BAA or No-PHI acknowledgment.

Does Shieldra sell personal information?

No. Shieldra does not sell personal information, and it does not share it for cross-context behavioral advertising unless you expressly enable the optional Marketing cookie category. No advertising or remarketing technology loads without your consent.

How does Shieldra handle AI and my data?

AI features run through Shieldra-managed providers — currently Anthropic, OpenAI, and Google — under terms that exclude training their models on your data. Prompts and responses are stored in your workspace for history and auditability and are deleted with your tenant data. Organizations can optionally bring their own AI provider key, in which case those calls run under their own agreement with that provider.

How do I exercise my data rights?

Use shieldra.ai/privacy-request or email privacy@shieldra.ai; we respond within 30 days. Depending on your jurisdiction you may request access, correction, or deletion of your personal information, opt out of marketing, request data portability, and withdraw consent.

Is analytics tracking enabled by default?

Third-party analytics is not. Where Google Analytics 4 is enabled on our sites it runs with IP anonymization and Google Consent Mode v2, denied by default until you accept analytics cookies, and the Meta Pixel loads only if you enable the optional Marketing category. Cloudflare Web Analytics is cookieless. Shieldra’s own first-party measurement of page views and sign-up steps runs by default without cookies, using an identifier kept only for the current browser tab; a persistent visitor identifier is set only after you accept Analytics. You can change or withdraw your cookie choice at any time.