IOnclad Home   Privacy   Terms   EULA
This document is provided in good faith for an independently-run product. It is not legal advice. For binding interpretation consult qualified counsel.

IOnclad Privacy Policy

Effective date: 2026-06-29 Last updated: 2026-06-29

This Privacy Policy explains how The Ritz Plaza LLC, a South Dakota limited liability company, doing business as The IOn Project ("Company", "we", "us", or "our"), handles personal data in connection with IOnclad (the "Software" or "App") — our local-first desktop security and launch-readiness audit application.

This is the IOnclad product-specific Privacy Policy. It is separate from, and supplements, any company-wide privacy policy that applies to our website and general business operations.


1. Summary — The Short Version

IOnclad is built to be local-first and offline by default. Here is the whole picture in plain terms:

If you only read one section, read this one. The rest is the detail.


2. Who We Are — Data Controller Identity

The data controller for the limited personal data described in this policy is:

The Ritz Plaza LLC (d/b/a The IOn Project) The Ritz Plaza LLC, [[FOUNDER: insert full street address]], Winner, South Dakota, USA

Contact:

PurposeContact
Privacy and data-protection requests (DSARs)[email protected]
General and legal enquiries[email protected]
Product pagehttps://theionproject.com/ionclad

Polar is an independent controller and Merchant of Record

When you purchase a Pro license, the seller and merchant of record is Polar Software, Inc. (a Delaware corporation, 3500 South DuPont Highway, Dover, DE 19901, USA). For the data Polar collects to process your purchase, Polar acts as an independent controller (not our processor), and its handling of your data is governed by Polar's own privacy policy: https://polar.sh/legal/privacy (contact: [email protected]). We and Polar are each independent controllers for the data each of us collects.


3. What We Collect, Why, and Our Legal Basis

We describe each category below, including the legal basis under the EU/UK General Data Protection Regulation ("GDPR" / "UK GDPR", Article 6). Most of these categories involve no data reaching us at all.

3(a) Local scanning and analysis — we collect NOTHING

When you run a scan, analyze source code, run the Live Site Auditor locally, or view findings and verdicts, all of that processing happens on your own machine. Your code, file contents, scan history, projects, targets, reports, suppressions, settings, and LaunchGuard intake answers are stored only in a local SQLite database and local config files on your device (see Section 7). None of this is transmitted to us, and we have no access to it. Because no personal data reaches us, no GDPR legal basis is engaged for us as controller here.

3(b) License-activation data — machine fingerprint + license key

What is collected: If, and only if, you activate a paid license, IOnclad makes a one-time HTTPS request to https://api.theionproject.com sending:

  1. your Polar license key, and
  2. a "machine fingerprint" — a SHA-256 hash derived from your operating system, CPU architecture, hostname, and a hardware ID — used to bind the license to that specific device.

The machine fingerprint is an "online identifier" and therefore constitutes personal data under the GDPR.

After this one-time activation, all subsequent license validation is fully offline (using an Ed25519 digital signature). There is no recurring check and no "phone home."

Purpose: license enforcement, device binding, and anti-piracy.

Legal basis: performance of a contract (Art. 6(1)(b)) — activating and enforcing the license you purchased — and our legitimate interests (Art. 6(1)(f)) in protecting the Software against unauthorized use and piracy.

3(c) Purchase data (via Polar)

What is collected: When you buy a license, Polar (as merchant of record and independent controller) collects your name, email address, billing address, payment-card details (card data is handled by Polar's payment processor, Stripe, Inc.; Polar stores only the card type and last four digits), and may collect phone, business name, and tax ID. We receive limited order/license information necessary to provision and support your license; we do not receive or store your full payment-card details.

Purpose: to sell, deliver, and support your license.

Legal basis (for the limited data we process): performance of a contract (Art. 6(1)(b)). Polar processes the purchase data it collects under its own legal bases and privacy policy.

3(d) Support correspondence

What is collected: If you contact us for support, we process the contents of your message and your contact details (e.g., your email address and anything you choose to include).

Purpose: to respond to and resolve your enquiry.

Legal basis: our legitimate interests (Art. 6(1)(f)) in providing customer support and maintaining the Software; where your enquiry relates to your purchase, contract (Art. 6(1)(b)) may also apply.

3(e) Website analytics (GA4) — website only, not the App

What is collected: Our website, theionproject.com, loads Google Analytics 4 (measurement ID G-F0HJN7MT9Z), which sets cookies/identifiers and collects standard usage analytics about website visitors. The downloaded desktop App contains no analytics and makes no analytics calls.

Purpose: to understand and improve our website.

Legal basis: consent (Art. 6(1)(a)), obtained via our website's cookie/consent mechanism. Where required, analytics cookies are set only after you consent, and you may withdraw consent at any time through the website's cookie controls.

3(f) Opt-in network features (all OFF by default)

Each of the following App features is opt-in and ships disabled. When you enable one, you are providing consent for that specific data flow; we also rely on contract / legitimate interests where the feature is integral to a paid capability you have chosen to use. In every case below, no source code and no file contents are transmitted unless expressly stated, and the third party named processes the data under its own privacy policy.

FeatureExactly what is sent, and to whomDefaultBasis
Auto-updaterYour current version number only, sent to theionproject.com to check for a newer release.OFFConsent (Art. 6(1)(a)) + legitimate interests (keeping software current/secure)
AI-guidance pack refreshYour version number (in the request User-Agent) only, sent to theionproject.com to fetch an updated coaching/guidance table. No source code or findings.OFFConsent (Art. 6(1)(a))
Dependency CVE lookupPackage names + versions sent to OSV.dev (Google's open-source vulnerability database, which aggregates CVE/advisory data from many sources). No source code is sent.OFFConsent (Art. 6(1)(a))
File-hash reputationSHA-256 file hashes (never file contents) sent to VirusTotal; requires your own VirusTotal API key.OFFConsent (Art. 6(1)(a))
Live Site Auditor (Pro)Fetches the public URL you enter, natively from your machine, directly to your own site (no Company server in the loop). You must affirm you own or are authorized to test that URL.OFFConsent (Art. 6(1)(a)) + contract (paid feature)
Core Web Vitals (sub-option of Live Site Auditor)The audited URL sent to Google's PageSpeed Insights API to retrieve real-user performance data. This is the only part of an audit that contacts a third party unrelated to your own site.OFFConsent (Art. 6(1)(a))
AI Co-Pilot / MCPConnects an external AI assistant of your choice (e.g., Claude) to IOnclad's local MCP server. That assistant — and its vendor — processes your code under the vendor's own privacy policy. IOnclad redacts detected secrets from MCP responses but does not control or receive what the vendor does. You choose the vendor.OFFConsent (Art. 6(1)(a))

Because the machine fingerprint (Section 3(b)) is an online identifier, we treat it as personal data and apply the protections in this policy to it.


4. What We Do NOT Collect

To be explicit, IOnclad and the Company do not:


5. Third Parties, Processors, and Sub-Processors

The following third parties may receive data only in connection with the features described above. Some act as our processors; Polar acts as an independent controller. We do not control, and are not responsible for, the independent data practices of these third parties, which are governed by their own policies.

Third partyRoleWhat is sharedWhenPrivacy policy
Polar Software, Inc.Merchant of record; independent controller for purchase/billing dataName, email, billing address, card details, optionally phone/business name/tax IDOn purchasehttps://polar.sh/legal/privacy
Stripe, Inc.Polar's payment sub-processor (card processing)Payment-card dataOn purchasehttps://stripe.com/privacy
OSV.devOpen-source vulnerability database (Google)Package names + versionsOnly if CVE lookup enabledhttps://osv.dev (Google — https://policies.google.com/privacy)
VirusTotalFile-hash reputation serviceSHA-256 file hashes (never contents)Only if file-hash reputation enabled (your own API key)https://docs.virustotal.com/docs/privacy-policy
Google PageSpeed InsightsWeb-performance dataThe audited URLOnly if Core Web Vitals enabledhttps://policies.google.com/privacy
Your chosen AI vendor (e.g., Anthropic)AI Co-PilotYour code, via your AI assistant (secrets redacted by IOnclad)Only if AI Co-Pilot enabledThe vendor's own policy
GitHub, Inc.Distribution of downloads / public sourceStandard request data when you download or view (governed by GitHub)When you download/visithttps://docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
Google Analytics 4Website onlyWebsite usage data + identifiersOn website visits (with consent)https://policies.google.com/privacy

6. International Data Transfers

We are based in the United States. Where you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction outside the US, the limited personal data described in this policy (for example, your machine fingerprint on activation, or support correspondence) may be transferred to and processed in the United States.

Where such transfers occur, they are protected by appropriate safeguards under GDPR Chapter V — principally the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum), together with supplementary technical and organizational measures (such as encryption in transit). For purchase and payment data, the relevant transfer safeguards are implemented by Polar and Stripe as the controllers/processors of that data, under their respective privacy frameworks and contractual clauses. You may request more information about the safeguards that apply by contacting [email protected].


7. Data Retention

Local data (on your device)

The local SQLite database (scan history, projects, targets, live-audit reports, suppressions, settings, LaunchGuard intake answers) and config files under ~/.ionclad/ (online-consent and AI Co-Pilot consent flags, your signed license file, custom rule packs, the cached AI-guidance pack, and optional per-project AI "fix plan" markdown files) live in your OS app-data directory (e.g., %APPDATA%\com.ionproject.ionclad\ on Windows). This data is retained on your machine until you delete it. You can remove all of it at any time via Settings → Data Management → "Erase all IOnclad data on this machine" — a single click; this action is irreversible.

Activation / license records

We retain activation and license records (including the machine fingerprint and associated license key) for as long as the license is active / for its term, and thereafter only as needed to meet legal, tax, accounting, and dispute-resolution obligations, after which they are deleted or anonymized.

Purchase records

Purchase records are held primarily by Polar (and Stripe) as merchant of record, under their retention policies and applicable tax/financial-record laws. We retain the limited order/license data we receive for the same legal and support purposes described above.

To request deletion of data we hold, see Section 8.


8. Your Rights and How to Exercise Them (DSAR Process)

You have rights over your personal data. The specific rights depend on where you live, but we honor the core rights below for all users wherever practicable.

8.1 Your rights under the GDPR / UK GDPR (EEA, UK, and similar regimes)

8.2 Your rights under US state privacy laws (CCPA/CPRA and others)

If you are a resident of California or another US state with a comprehensive privacy law, you have the right to:

We do not "sell" or "share" personal information, and we do not use personal information for cross-context behavioral/targeted advertising — so there is nothing to opt out of in that respect. You also have the right to be free from discrimination for exercising your rights.

8.3 The fastest path for your local data

For the data stored on your own machine, the quickest way to exercise your erasure right is the built-in, self-service control: Settings → Data Management → "Erase all IOnclad data on this machine." This deletes your local database and config files instantly and does not require contacting us.

8.4 How to submit a request (DSAR)

To exercise any right relating to data we hold, email [email protected] with:

Identity verification. To protect your data, we will take reasonable steps to verify your identity before acting — typically by confirming you control the email address associated with your purchase/license, and (for sensitive requests) by asking for additional matching details. We will not ask for more information than necessary. You may use an authorized agent where the law allows.

Timeline.

Cost. Requests are free of charge. We may charge a reasonable fee or refuse to act only where a request is manifestly unfounded, excessive, or repetitive, as permitted by law, and we will explain any such decision.

No discrimination. We will not discriminate against you for exercising your rights.

8.5 Purchase data — you may also contact Polar

Because Polar is the independent controller and merchant of record for your purchase and billing data, requests concerning that data may need to be directed to Polar ([email protected]; https://polar.sh/legal/privacy). We will help route or coordinate your request where we can.


9. Children's Privacy

IOnclad is a developer/security tool and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or under 13 where US law sets that threshold). If you believe a child has provided us personal data, contact [email protected] and we will delete it.


10. Security

IOnclad's local-first architecture is itself a privacy and security measure: because your code, scans, and results stay on your machine, the exposure surface is minimal. In addition:

No method of transmission or storage is perfectly secure, but we design IOnclad to keep the amount of data leaving your device as close to zero as possible.


11. EU/UK Representative (GDPR/UK GDPR Article 27)

We are established in the United States and currently process EEA/UK personal data only occasionally and at low risk (principally the one-time activation fingerprint and any voluntary correspondence). On that basis we presently rely on the Article 27(2) exemption from the requirement to appoint an EU/UK representative. If our EU/UK sales or processing become substantial or regular, we will appoint an Article 27 representative and update this policy with their details.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you (for example, via the website or in-app). The version in force is the one published at the time of processing.

Questions or requests? Email [email protected] (data/privacy) or [email protected] (general/legal).