LEGAL / PRIVACY

YOUR DATA.
CLEAR BOUNDARIES.

This policy explains what Misconfig Cloud LLC processes, why we process it, and the choices available to you.

Effective: 21 August 2026 · Controller: Misconfig Cloud LLC · Contact: contact@misconfig.cloud

1. What this policy covers

This policy covers the Misconfig Cloud website, customer console, local-runtime enrollment, governed agent sessions, and supported developer and provider integrations. It does not cover third-party services under their own policies.

2. Information we process

Identity and workspace data

When you sign in with Google or GitHub, we receive provider identifiers, verified email address, display name, and the authorization information needed to create or link your workspace membership. We do not receive or store your Google or GitHub password.

Device, profile, session, and receipt data

Misconfig processes enrolled-device identity, immutable session-profile and policy releases, agent and adapter versions, declared infrastructure scope, credential-mode labels, policy decisions, approval and stop records, redacted tool-action metadata, completion observations, independent provider-verification records when configured, and aggregate usage statistics exposed by the supported adapter. Hidden model reasoning is not collected. Unknown usage remains unknown rather than being inferred.

Local credentials and configuration

The current attach-mode runtime uses provider profiles already present on your machine. Misconfig does not upload or store the underlying long-lived provider credentials. Attach mode may be bypassed by using the original provider tooling outside the governed launcher. Any future brokered-identity feature will be documented separately before use.

Integration data

If you connect a developer or provider integration, we process installation identifiers, authorized scopes, requests directed to the service, and delivery metadata within the permissions you grant.

Website analytics

Google Analytics is loaded only after you accept analytics cookies. We configure it with IP anonymization, advertising personalization disabled, and Google signals disabled. If you decline, no Google Analytics script is loaded. Your choice is stored locally in your browser.

3. Why we process it

We process data to authenticate users, isolate tenant workspaces, enroll devices, distribute signed policy, present governed session state, retain action and approval proof, perform requested remote stops, support integrations, secure and troubleshoot the service, and meet legal obligations. Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the service, consent for optional analytics, and compliance with law.

4. Sharing and processors

We share data only with service providers required to operate Misconfig, such as hosting, identity, messaging, model-routing, logging, and analytics providers; when you direct an integration; or when law requires it. Providers receive only the data needed for their role and are subject to contractual or platform terms. We do not sell personal data.

5. International processing

Cloud and integration providers may process data outside your country. Where required, we use appropriate transfer mechanisms and contractual safeguards.

6. Retention and deletion

We retain identity, workspace, device, signed-profile, session, receipt, approval, stop, and audit data for the period applicable to your account or order and as otherwise needed to provide the service, preserve required audit history, resolve disputes, and meet legal obligations. Revoking a device or profile stops future eligibility but may retain prior session evidence. Contact us to request workspace deletion; we will explain any records that must be retained.

7. Security

We use tenant authorization checks, server-side sessions, encrypted transport, signed policy, local deterministic evaluation, redaction, expiring cached policy, remote stop, immutable release identity, and retained audit records. No system is perfectly secure, so report concerns to contact@misconfig.cloud.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or export personal data, and to withdraw consent. You may also complain to your local supervisory authority. Email contact@misconfig.cloud to exercise a right.

9. Changes

We may update this policy as the product and legal requirements evolve. We will publish the revised date here and provide additional notice for material changes where appropriate.