Privacy Policy
Sherlock Protocol, Inc. (“Sherlock,” “We,” “Us,” or “Our”) is committed to protecting your privacy. This Privacy Policy explains how Sherlock collects, uses, discloses, and safeguards your information when you use our website, our services including collaborative audits, audit contests, bug bounties, and our AI-powered code analysis products and features (“AI Analysis Services,” which include Sherlock AI and related or successor offerings), or otherwise interact with us. By accessing or using our Services, you agree to this Privacy Policy.
If you are a resident of the European Economic Area (EEA), United Kingdom (UK), or California, you may have additional rights under applicable data protection laws such as the GDPR, UK GDPR, or CCPA. We act as a data processor for certain data related to our Services, particularly code and repository data accessed via our AI Analysis Services.
- We prioritize data security: code and personal information are handled with enterprise-grade protections, including encryption in transit and at rest and role-based access controls. We do not use your proprietary code to train AI models without explicit consent.
- Limited data collection: we collect only what is necessary to provide the Services — account details, usage data, and the code and repository data you authorize us to analyze.
- Defined retention: repository and code data processed by our AI Analysis Services is retained for a default of 30 days after analysis, then deleted. Code excerpts in vulnerability reports persist as part of those reports.
- No unnecessary sharing: data is shared only with authorized service providers listed in this Policy or as required by law; we do not sell your data.
- Enterprise considerations: for organizations with heightened requirements, we offer data processing agreements (DPAs), support for GDPR/CCPA obligations, and configurable retention terms.
- User rights: you can request access to, correction of, or deletion of your data, and opt out of certain processing, as described in Section 8.
What information we collect
We collect personal data (e.g., name, email, IP address) when you create an account or contact us, and non-personal data such as code, vulnerability findings, and related metadata during audits and AI analysis. For our AI Analysis Services, we access GitHub repositories with your permission to analyze commits, pull requests, and repository contents for vulnerabilities. Repository contents are retained only for the limited, defined period described in Section 5, after which they are deleted.
How we use your information
Data is used to deliver the Services, improve security insights, and comply with legal obligations. For AI analysis, your codebase is processed for security analysis and retained only for the limited period described in Section 5.
Your privacy choices
Request access or deletion via support@sherlock.xyz. CCPA residents: We do not sell personal information.
This Privacy Policy (“Policy”) describes our practices regarding the collection, use, disclosure, and protection of information when you use our Services. Please read it carefully. If you do not agree, do not use our Services.
1. Interpretation and Definitions
Interpretation
Capitalized terms have the meanings defined below, applicable in singular or plural.
Definitions
- Account: A unique profile for accessing our Services.
- AI Analysis Services: Our AI-powered code analysis products and features, including Sherlock AI and related or successor offerings.
- Company: Sherlock Protocol, Inc., located at Dresdner Tower, 11th Floor 50th St. and 55th East Street, Panama City, Panama 00000.
- Cookies: Small files tracking browsing activity.
- Device: Any tool accessing our Services (e.g., computer, mobile).
- Personal Data: Information identifying an individual (e.g., name, email).
- Services: Our website, audits, contests, bounties, and AI Analysis Services.
- Usage Data: Automatically collected data (e.g., IP address, visit duration).
- You: The individual or entity using our Services.
2. Collecting and Using Your Personal Data
Personal Data
We may collect:
- Email, name, and contact details for account creation and communication.
- Payment and payout information, such as billing details and blockchain wallet addresses used for on-chain payouts and potential third-party providers such as Stripe.
- GitHub authentication data when integrating our AI Analysis Services.
Usage Data
Automatically collected:
- IP address, browser type, pages visited, time spent.
- For mobile access: Device ID, OS, browser.
Code and Repository Data (Non-Personal but Sensitive)
For our AI Analysis Services and audits:
- Repository contents authorized by you for analysis, including commits and pull requests.
- Code excerpts included in vulnerability reports.
- Vulnerability findings and metadata.
This data is treated as confidential, is processed only for security analysis and reporting, and is retained only as described in Section 5. We do not access repositories beyond the scope you authorize.
Data from Third-Party Services
- GitHub integration: We receive repository access tokens, usernames, and metadata per your permissions.
- Social logins (e.g., Google): Name, email.
3. Use of Your Personal Data
We use data for:
- Providing Services: Conducting audits, running AI analyses, reporting vulnerabilities.
- Account management: Registration, support.
- Performance of contracts: Fulfilling audit or bounty agreements.
- Communications: Updates, security alerts (opt-out available).
- Compliance: Legal obligations, dispute resolution.
- For AI Analysis Services: Analysis of repositories, commits, and pull requests to detect vulnerabilities, with code retained only for the limited period described in Section 5.
We do not use your proprietary code to train AI models, whether our own or those of our AI providers, unless you explicitly opt in via enterprise agreements. Where code is processed by third-party AI model providers as described in Section 4, it is processed under enterprise agreements that prohibit the use of your data to train their models and that limit their retention of your data.
4. Sharing of Your Personal Data
We share data:
- With Service Providers (Subprocessors): For hosting, infrastructure, authentication, communications, and AI model inference, under strict confidentiality and data protection obligations.
- Affiliates: For internal operations, bound by this Policy.
- Business Partners: For joint services, with your consent.
- In Business Transfers: During mergers/acquisitions.
- With Your Consent: For other purposes.
- For Legal Reasons: To comply with laws, protect rights, or respond to authorities.
We do not sell Personal Data. For enterprises, we offer DPAs outlining processor responsibilities.
| Subprocessor | Purpose |
|---|---|
| Google Cloud Platform | Cloud infrastructure, application hosting, data storage |
| Vercel | Web application hosting / frontend |
| Cloudflare | DNS, content delivery, and edge security |
| GitHub | Source code integration and CI/CD |
| Clerk | Customer authentication and identity |
| Anthropic | AI model inference for code analysis |
| OpenAI | AI model inference for code analysis |
| Twilio SendGrid | Transactional email |
| Google (OAuth) | Social login |
| Google Workspace | Business operations, email, and documents |
| Sumsub | Identity verification / KYC |
| Slack | Customer support channel and operational notifications |
| Telegram | Customer support channel and operational notifications |
| Discord | Community channel, infrastructure alerting, and operational notifications |
| DocuSign | eSignature / legal agreement signing |
| Alchemy | Polygon RPC provider for on-chain reads and writes for USDC payouts |
Google Cloud Platform
Cloud infrastructure, application hosting, data storage
Vercel
Web application hosting / frontend
Cloudflare
DNS, content delivery, and edge security
GitHub
Source code integration and CI/CD
Clerk
Customer authentication and identity
Anthropic
AI model inference for code analysis
OpenAI
AI model inference for code analysis
Twilio SendGrid
Transactional email
Google (OAuth)
Social login
Google Workspace
Business operations, email, and documents
Sumsub
Identity verification / KYC
Slack
Customer support channel and operational notifications
Telegram
Customer support channel and operational notifications
Discord
Community channel, infrastructure alerting, and operational notifications
DocuSign
eSignature / legal agreement signing
Alchemy
Polygon RPC provider for on-chain reads and writes for USDC payouts
5. Retention of Your Personal Data
- Personal Data: Retained as needed for the Services and legal compliance (e.g., 7 years for financial records).
- Code and Repository Data: Retained for a default period of 30 days following completion of analysis, after which it is deleted from our production systems. This retention period is configurable under enterprise agreements. Code excerpts contained in vulnerability reports delivered to you persist as part of those reports.
- Operational and Audit Logs (including records of analysis runs and prompt activity): Retained for 60 days.
- Usage Data: Retained for 12 months for analytics.
- Deletion Requests: Upon a verified request, we delete the requester's data from our production systems within 30 days, except where retention is required by law.
- Third-Party AI Providers: Copies of code processed by our AI model providers are deleted in accordance with their enterprise retention commitments, or are not retained where zero data retention arrangements apply.
6. Transfer of Your Personal Data
Data may be processed outside your jurisdiction (e.g., on US-based cloud infrastructure). We use Standard Contractual Clauses (SCCs) for EEA/UK transfers and ensure equivalent protections.
7. Security of Your Personal Data
We employ encryption in transit (TLS 1.2 or higher) and at rest (AES-256), role-based access controls, and least-privilege access limited to a small number of authorized personnel. However, no system is 100% secure.
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to your data, we will notify affected customers without undue delay, and in any event within 72 hours where required by agreement or applicable law, and will provide information reasonably available to us about the nature of the incident and the measures taken.
8. Your Privacy Rights
- Access, correct, or delete your data.
- Opt out of marketing or certain processing.
- GDPR/CCPA Rights: Object to processing, request portability, non-discrimination. We respond within 30 days (45 for CCPA).
For California Residents:
- Categories Collected: Identifiers, commercial info, internet activity.
- Sources: Directly from you, GitHub.
- Disclosures: To providers for business purposes.
- No sales in past 12 months.
9. Children's Privacy
Services not for under 18; we do not knowingly collect data from children.
10. Links to Other Websites
We are not responsible for third-party privacy practices (e.g., GitHub).
11. Changes to This Privacy Policy
Updates posted here with “Last Updated” date. Significant changes notified via email.