Effective: 21 August 2026 · Controller: Misconfig Cloud LLC · Contact: contact@misconfig.cloud
1. What this policy covers
This policy covers the Misconfig Cloud website, customer console, local-runtime enrollment, governed agent sessions, and supported developer and provider integrations. It does not cover third-party services under their own policies.
2. Information we process
Identity and workspace data
When you sign in with Google or GitHub, we receive provider identifiers, verified email address, display name, and the authorization information needed to create or link your workspace membership. We do not receive or store your Google or GitHub password.
Device, profile, session, and receipt data
Misconfig processes enrolled-device identity, immutable session-profile and policy releases, agent and adapter versions, declared infrastructure scope, credential-mode labels, policy decisions, approval and stop records, redacted tool-action metadata, completion observations, independent provider-verification records when configured, and aggregate usage statistics exposed by the supported adapter. Hidden model reasoning is not collected. Unknown usage remains unknown rather than being inferred.
Local credentials and configuration
The current attach-mode runtime uses provider profiles already present on your machine. Misconfig does not upload or store the underlying long-lived provider credentials. Attach mode may be bypassed by using the original provider tooling outside the governed launcher. Any future brokered-identity feature will be documented separately before use.
Integration data
If you connect a developer or provider integration, we process installation identifiers, authorized scopes, requests directed to the service, and delivery metadata within the permissions you grant.
Website analytics
Google Analytics is loaded only after you accept analytics cookies. We configure it with IP anonymization, advertising personalization disabled, and Google signals disabled. If you decline, no Google Analytics script is loaded. Your choice is stored locally in your browser.
3. Why we process it
We process data to authenticate users, isolate tenant workspaces, enroll devices, distribute signed policy, present governed session state, retain action and approval proof, perform requested remote stops, support integrations, secure and troubleshoot the service, and meet legal obligations. Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the service, consent for optional analytics, and compliance with law.
4. Sharing and processors
We share data only with service providers required to operate Misconfig, such as hosting, identity, messaging, model-routing, logging, and analytics providers; when you direct an integration; or when law requires it. Providers receive only the data needed for their role and are subject to contractual or platform terms. We do not sell personal data.
5. International processing
Cloud and integration providers may process data outside your country. Where required, we use appropriate transfer mechanisms and contractual safeguards.
6. Retention and deletion
We retain identity, workspace, device, signed-profile, session, receipt, approval, stop, and audit data for the period applicable to your account or order and as otherwise needed to provide the service, preserve required audit history, resolve disputes, and meet legal obligations. Revoking a device or profile stops future eligibility but may retain prior session evidence. Contact us to request workspace deletion; we will explain any records that must be retained.
7. Security
We use tenant authorization checks, server-side sessions, encrypted transport, signed policy, local deterministic evaluation, redaction, expiring cached policy, remote stop, immutable release identity, and retained audit records. No system is perfectly secure, so report concerns to contact@misconfig.cloud.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or export personal data, and to withdraw consent. You may also complain to your local supervisory authority. Email contact@misconfig.cloud to exercise a right.
9. Changes
We may update this policy as the product and legal requirements evolve. We will publish the revised date here and provide additional notice for material changes where appropriate.