Privacy Policy
Last updated: April 17, 2026
Strixl Labs (“Strixl Labs,” “we,” “us”) provides a network-traffic analysis platform at strixllabs.com. This Privacy Policy describes what information we collect, how we use it, and the choices you have. By creating an account or using the service you agree to this policy.
1. Information we collect
Account data
When you sign up we collect your email address, a hashed password, and optional profile details (display name, organization). If you sign in via a third party (e.g. Google, GitHub), we receive the identifiers that provider shares with us.
Uploaded files
The service is designed around files you upload: PCAPs, Zeek logs, Suricata eve.json, NDJSON, CSV, and similar network-telemetry formats. We store these files and the derived detection results in your workspace for analysis.
Usage data
We log technical information necessary to operate and secure the service: IP address, browser user agent, timestamps, endpoints accessed, upload sizes, and detection-engine metrics.
Billing data
If you subscribe to a paid plan, our payment processor (Stripe) collects payment information directly. Strixl Labs does not store full payment-card numbers.
2. How we use your information
- To operate the detection engine on files you upload.
- To authenticate you and secure your account.
- To meter usage against the limits of your subscription tier.
- To contact you about service-critical events (billing, security, outages, planned maintenance).
- To improve the product, always using aggregated or anonymized data and never by inspecting the contents of your uploaded files.
3. What we do not do
- We do not sell your data. Not to advertisers, not to data brokers, not to any third party.
- We do not train models on your uploaded files. The files you upload are used only to produce your detection results.
- We do not inspect uploaded content outside of automated detection processing, except when you explicitly request support and grant access, or when required by law.
4. Data sharing
We share limited data with a short list of service providers:
- Stripe: subscription billing.
- SendGrid: transactional email (account verification, password reset, billing receipts).
- Render, Vercel, Hetzner, Cloudflare: hosting and network infrastructure.
- Threat-intel providers (VirusTotal, AbuseIPDB, IPinfo, Emerging Threats, ThreatFox, Feodo Tracker): we send IP addresses extracted from your uploads to these services to enrich detections. We do not send the raw files.
We may also disclose information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect the safety of a person or the integrity of the service.
5. Data retention
- Uploaded files: retained for 30 days after upload, then permanently deleted from storage and backups.
- Detection results & audit logs: retained for the life of your account.
- Account data: retained until you delete your account, after which it is purged within 30 days except where we must retain records to comply with legal or tax obligations.
6. Security
All traffic is encrypted in transit (TLS 1.2+). Uploaded files and detection data are isolated per workspace at the storage and queue layer. Passwords are hashed with bcrypt. Access to production systems is restricted, logged, and requires hardware-backed two-factor authentication.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay and in accordance with applicable law.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to restrict or object to certain processing. You can exercise most of these rights directly from your account settings. For anything else, email privacy@strixllabs.com.
8. International transfers
Strixl Labs operates infrastructure in the United States and the European Union. If you use the service from another country you consent to the transfer of your data to those regions.
9. Children
The service is not directed to children under 16 and we do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced by email or in-app notice at least 14 days before they take effect.
11. Contact
Questions or requests: privacy@strixllabs.com
