Privacy Policy

Sherlock Protocol, Inc. (“Sherlock,” “We,” “Us,” or “Our”) is committed to protecting your privacy. This Privacy Policy explains how Sherlock collects, uses, discloses, and safeguards your information when you use our website, our services including collaborative audits, audit contests, bug bounties, and our AI-powered code analysis products and features (“AI Analysis Services,” which include Sherlock AI and related or successor offerings), or otherwise interact with us. By accessing or using our Services, you agree to this Privacy Policy.

If you are a resident of the European Economic Area (EEA), United Kingdom (UK), or California, you may have additional rights under applicable data protection laws such as the GDPR, UK GDPR, or CCPA. We act as a data processor for certain data related to our Services, particularly code and repository data accessed via our AI Analysis Services.

  • We prioritize data security: code and personal information are handled with enterprise-grade protections, including encryption in transit and at rest and role-based access controls. We do not use your proprietary code to train AI models without explicit consent.
  • Limited data collection: we collect only what is necessary to provide the Services — account details, usage data, and the code and repository data you authorize us to analyze.
  • Defined retention: repository and code data processed by our AI Analysis Services is retained for a default of 30 days after analysis, then deleted. Code excerpts in vulnerability reports persist as part of those reports.
  • No unnecessary sharing: data is shared only with authorized service providers listed in this Policy or as required by law; we do not sell your data.
  • Enterprise considerations: for organizations with heightened requirements, we offer data processing agreements (DPAs), support for GDPR/CCPA obligations, and configurable retention terms.
  • User rights: you can request access to, correction of, or deletion of your data, and opt out of certain processing, as described in Section 8.

What information we collect

We collect personal data (e.g., name, email, IP address) when you create an account or contact us, and non-personal data such as code, vulnerability findings, and related metadata during audits and AI analysis. For our AI Analysis Services, we access GitHub repositories with your permission to analyze commits, pull requests, and repository contents for vulnerabilities. Repository contents are retained only for the limited, defined period described in Section 5, after which they are deleted.

How we use your information

Data is used to deliver the Services, improve security insights, and comply with legal obligations. For AI analysis, your codebase is processed for security analysis and retained only for the limited period described in Section 5.

Your privacy choices

Request access or deletion via support@sherlock.xyz. CCPA residents: We do not sell personal information.

This Privacy Policy (“Policy”) describes our practices regarding the collection, use, disclosure, and protection of information when you use our Services. Please read it carefully. If you do not agree, do not use our Services.


1. Interpretation and Definitions

Interpretation

Capitalized terms have the meanings defined below, applicable in singular or plural.

Definitions

  • Account: A unique profile for accessing our Services.
  • AI Analysis Services: Our AI-powered code analysis products and features, including Sherlock AI and related or successor offerings.
  • Company: Sherlock Protocol, Inc., located at Dresdner Tower, 11th Floor 50th St. and 55th East Street, Panama City, Panama 00000.
  • Cookies: Small files tracking browsing activity.
  • Device: Any tool accessing our Services (e.g., computer, mobile).
  • Personal Data: Information identifying an individual (e.g., name, email).
  • Services: Our website, audits, contests, bounties, and AI Analysis Services.
  • Usage Data: Automatically collected data (e.g., IP address, visit duration).
  • You: The individual or entity using our Services.

2. Collecting and Using Your Personal Data

Personal Data

We may collect:

  • Email, name, and contact details for account creation and communication.
  • Payment and payout information, such as billing details and blockchain wallet addresses used for on-chain payouts and potential third-party providers such as Stripe.
  • GitHub authentication data when integrating our AI Analysis Services.

Usage Data

Automatically collected:

  • IP address, browser type, pages visited, time spent.
  • For mobile access: Device ID, OS, browser.

Code and Repository Data (Non-Personal but Sensitive)

For our AI Analysis Services and audits:

  • Repository contents authorized by you for analysis, including commits and pull requests.
  • Code excerpts included in vulnerability reports.
  • Vulnerability findings and metadata.

This data is treated as confidential, is processed only for security analysis and reporting, and is retained only as described in Section 5. We do not access repositories beyond the scope you authorize.

Data from Third-Party Services

  • GitHub integration: We receive repository access tokens, usernames, and metadata per your permissions.
  • Social logins (e.g., Google): Name, email.

3. Use of Your Personal Data

We use data for:

  • Providing Services: Conducting audits, running AI analyses, reporting vulnerabilities.
  • Account management: Registration, support.
  • Performance of contracts: Fulfilling audit or bounty agreements.
  • Communications: Updates, security alerts (opt-out available).
  • Compliance: Legal obligations, dispute resolution.
  • For AI Analysis Services: Analysis of repositories, commits, and pull requests to detect vulnerabilities, with code retained only for the limited period described in Section 5.

We do not use your proprietary code to train AI models, whether our own or those of our AI providers, unless you explicitly opt in via enterprise agreements. Where code is processed by third-party AI model providers as described in Section 4, it is processed under enterprise agreements that prohibit the use of your data to train their models and that limit their retention of your data.


4. Sharing of Your Personal Data

We share data:

  • With Service Providers (Subprocessors): For hosting, infrastructure, authentication, communications, and AI model inference, under strict confidentiality and data protection obligations.
  • Affiliates: For internal operations, bound by this Policy.
  • Business Partners: For joint services, with your consent.
  • In Business Transfers: During mergers/acquisitions.
  • With Your Consent: For other purposes.
  • For Legal Reasons: To comply with laws, protect rights, or respond to authorities.

We do not sell Personal Data. For enterprises, we offer DPAs outlining processor responsibilities.

Subprocessor Purpose
Google Cloud PlatformCloud infrastructure, application hosting, data storage
VercelWeb application hosting / frontend
CloudflareDNS, content delivery, and edge security
GitHubSource code integration and CI/CD
ClerkCustomer authentication and identity
AnthropicAI model inference for code analysis
OpenAIAI model inference for code analysis
Twilio SendGridTransactional email
Google (OAuth)Social login
Google WorkspaceBusiness operations, email, and documents
SumsubIdentity verification / KYC
SlackCustomer support channel and operational notifications
TelegramCustomer support channel and operational notifications
DiscordCommunity channel, infrastructure alerting, and operational notifications
DocuSigneSignature / legal agreement signing
AlchemyPolygon RPC provider for on-chain reads and writes for USDC payouts
Subprocesadores
  • Google Cloud Platform

    Cloud infrastructure, application hosting, data storage

  • Vercel

    Web application hosting / frontend

  • Cloudflare

    DNS, content delivery, and edge security

  • GitHub

    Source code integration and CI/CD

  • Clerk

    Customer authentication and identity

  • Anthropic

    AI model inference for code analysis

  • OpenAI

    AI model inference for code analysis

  • Twilio SendGrid

    Transactional email

  • Google (OAuth)

    Social login

  • Google Workspace

    Business operations, email, and documents

  • Sumsub

    Identity verification / KYC

  • Slack

    Customer support channel and operational notifications

  • Telegram

    Customer support channel and operational notifications

  • Discord

    Community channel, infrastructure alerting, and operational notifications

  • DocuSign

    eSignature / legal agreement signing

  • Alchemy

    Polygon RPC provider for on-chain reads and writes for USDC payouts


5. Retention of Your Personal Data

  • Personal Data: Retained as needed for the Services and legal compliance (e.g., 7 years for financial records).
  • Code and Repository Data: Retained for a default period of 30 days following completion of analysis, after which it is deleted from our production systems. This retention period is configurable under enterprise agreements. Code excerpts contained in vulnerability reports delivered to you persist as part of those reports.
  • Operational and Audit Logs (including records of analysis runs and prompt activity): Retained for 60 days.
  • Usage Data: Retained for 12 months for analytics.
  • Deletion Requests: Upon a verified request, we delete the requester's data from our production systems within 30 days, except where retention is required by law.
  • Third-Party AI Providers: Copies of code processed by our AI model providers are deleted in accordance with their enterprise retention commitments, or are not retained where zero data retention arrangements apply.

6. Transfer of Your Personal Data

Data may be processed outside your jurisdiction (e.g., on US-based cloud infrastructure). We use Standard Contractual Clauses (SCCs) for EEA/UK transfers and ensure equivalent protections.


7. Security of Your Personal Data

We employ encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, and least-privilege access limited to a small number of authorized personnel. However, no system is 100% secure.

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to your data, we will notify affected customers without undue delay, and in any event within 72 hours where required by agreement or applicable law, and will provide information reasonably available to us about the nature of the incident and the measures taken.


8. Your Privacy Rights

  • Access, correct, or delete your data.
  • Opt out of marketing or certain processing.
  • GDPR/CCPA Rights: Object to processing, request portability, non-discrimination. We respond within 30 days (45 for CCPA).

For California Residents:

  • Categories Collected: Identifiers, commercial info, internet activity.
  • Sources: Directly from you, GitHub.
  • Disclosures: To providers for business purposes.
  • No sales in past 12 months.

9. Children's Privacy

Services not for under 18; we do not knowingly collect data from children.


10. Links to Other Websites

We are not responsible for third-party privacy practices (e.g., GitHub).


11. Changes to This Privacy Policy

Updates posted here with “Last Updated” date. Significant changes notified via email.


12. Contact Us

privacy@sherlock.xyz